This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Google Redirect, Programs won't open, Nothing is working

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry, I wasn't able to get back to you because my battery power cord broke and I had to order a new one. I got a new cord. I had downloaded OTL.exe and ran it.

Below are the results of the scan.

OTL logfile created on: 5/19/2010 10:55:12 AM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Audra Drish\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.00 Mb Total Physical Memory | 123.00 Mb Available Physical Memory | 24.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 2.18 Gb Free Space | 5.84% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: AUDRA
Current User Name: Audra Drish
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Audra Drish\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe (America Online Inc)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Audra Drish\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton 360\Engine\4.1.0.32\asOEHook.dll (Symantec Corporation)
MOD - C:\Program Files\Norton 360\Engine\4.1.0.32\Microsoft.VC90.CRT\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton 360\Engine\4.1.0.32\Microsoft.VC90.CRT\msvcp90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (N360) – C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe (Symantec Corporation)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (Swupdtmr) – c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()
SRV - (CFSvcs) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (AOL TopSpeedMonitor) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100522.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\VirusDefs\20100522.003\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20100429.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0401000.020\Ironx86.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0401000.020\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0401000.020\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\N360\0401000.020\ccHPx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0401000.020\SYMTDI.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0401000.020\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0401000.020\SYMDS.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20100513.002\IDSXpx86.sys (Symantec Corporation)
DRV - (SAMFILT) – C:\WINDOWS\system32\drivers\samfilt.sys (Dolphin, Inc.)
DRV - (tbiosdrv) – C:\WINDOWS\system32\drivers\tbiosdrv.sys ()
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (TVALZ) – C:\WINDOWS\system32\DRIVERS\TVALZ.SYS (TOSHIBA Corporation)
DRV - (STAC97) – C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.iastate.edu/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: [removed]:1.03.01
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\IPSFFPlgn\ [2010/04/26 20:49:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\coFFPlgn\ [2010/04/21 00:51:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/31 21:16:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/31 15:46:21 | 000,000,000 | —D | M]

[2008/11/11 17:03:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Extensions
[2010/05/18 08:49:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions
[2009/08/10 16:51:03 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/28 15:50:55 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/05/07 23:01:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\[removed]
[2009/08/15 21:29:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Mozilla\Firefox\Profiles\xh2qqzhk.default\extensions\[removed]
[2010/04/20 19:38:39 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.1.0.32\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.1.0.32\IPSBHO.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.1.0.32\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.1.0.32\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [000StTHK] C:\WINDOWS\System32\000StTHK.exe ()
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe File not found
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [CFSServ.exe] File not found
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe File not found
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [TFNF5] C:\WINDOWS\System32\TFNF5.exe (TOSHIBA Corp.)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPSODDCtl] C:\WINDOWS\System32\TPSODDCtl.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Norton Download Manager{N360S_prod_1.19_4.1.0.32}] C:\Documents and Settings\All Users\Documents\Norton\{N360S_prod_1.19_4.1.0.32}\N360Downloader.exe (Symantec Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk = C:\Program Files\SanDisk\SanDisk TransferMate\SD Monitor.exe (SanDisk)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - Startup: C:\Documents and Settings\Audra Drish\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\NPJPI150_04.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab (Reg Error: Key error.)
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab (TTestGenXInstallObject)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} http://www.slide.com/uploader/SlideImageUploader.cab (Slide Image Uploader Control)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1} http://www.parallelgraphics.com/l2/bin/cortvrml.cab (ParallelGraphics Cortona Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab (Pearson Installation Assistant 2)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (Reg Error: Key error.)
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} https://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab (Reg Error: Key error.)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {DBA8E419-0D5F-439B-A3CC-D01C768D9B51} http://aolsvc.aol.com/onlinegames/sonydavi…aderControl.cab (DVCDownloaderControl Object)
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} http://asp.mathxl.com/books/_Players/MathPlayer.cab (Pearson MathXL Player)
O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} http://asp.mathxl.com/books/_Players/EconPlayer.cab (Pearson MyEconLab Player Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/AUDRAD~1/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Audra Drish\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Audra Drish\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/14 18:12:54 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = secfile] – "C:\Documents and Settings\Audra Drish\Local Settings\Application Data\av.exe" /START "%1" %* File not found

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/11/14 18:12:17 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/05/19 10:52:11 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Audra Drish\Desktop\OTL.exe
[2010/04/23 20:23:23 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Audra Drish\Desktop\HJTInstall(2)(2).exe
[2010/04/22 23:09:49 | 002,260,992 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoCompress.dll
[2010/04/22 23:09:49 | 000,282,624 | —- | C] (Online Media Technologies Company Ltd.) – C:\WINDOWS\System32\NCTQuickTimeFile.dll
[2010/04/22 23:09:49 | 000,261,632 | —- | C] (MainConcept) – C:\WINDOWS\System32\mcdvd_32.dll
[2010/04/22 23:09:49 | 000,139,264 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoFile.dll
[2010/04/22 23:09:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\RMBin
[2010/04/22 23:09:48 | 001,986,560 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioFile2.dll
[2010/04/22 23:09:48 | 001,245,184 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTRMFile.dll
[2010/04/22 23:09:48 | 000,991,232 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoCoreM.dll
[2010/04/22 23:09:48 | 000,294,912 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAVIFile.dll
[2010/04/22 23:09:48 | 000,196,608 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTWMVFile.dll
[2010/04/22 23:09:48 | 000,106,496 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTVideoCoreU.dll
[2010/04/22 23:09:47 | 002,564,096 | —- | C] (Online Media Technologies Ltd.) – C:\WINDOWS\System32\NCTAudioCompress3.dll
[2010/04/22 23:09:47 | 001,810,432 | —- | C] (Online Media Technologies Ltd.) – C:\WINDOWS\System32\NCTAudioCompress2.dll
[2010/04/22 23:09:44 | 000,000,000 | —D | C] – C:\Program Files\4U Computing
[2010/04/22 23:06:40 | 011,610,677 | —- | C] (4U Computing, Inc. ) – C:\Documents and Settings\Audra Drish\Desktop\4UAVIMPEGConverter.exe
[2010/04/20 21:47:17 | 097,525,032 | —- | C] (Apple Inc.) – C:\Documents and Settings\Audra Drish\Desktop\iTunesSetup.exe
[2010/04/20 19:43:34 | 000,124,976 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/04/20 19:43:34 | 000,060,808 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/04/20 19:42:34 | 000,362,032 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\symtdi.sys
[2010/04/20 19:42:34 | 000,340,016 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\symtdiv.sys
[2010/04/20 19:42:34 | 000,328,752 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\SymDS.sys
[2010/04/20 19:42:34 | 000,325,680 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.sys
[2010/04/20 19:42:34 | 000,172,592 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\SymEFA.sys
[2010/04/20 19:42:34 | 000,116,784 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\Ironx86.sys
[2010/04/20 19:42:34 | 000,043,696 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.sys
[2010/04/20 19:42:30 | 000,501,888 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0401000.020\cchpx86.sys
[2010/04/20 19:40:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360
[2010/04/20 19:40:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360\0401000.020
[2010/04/20 19:40:48 | 000,000,000 | —D | C] – C:\Program Files\Norton 360
[2010/04/20 19:40:47 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2010/04/20 19:17:58 | 110,083,680 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360-ESD-17-6-0-32-EN.exe
[2010/04/20 19:13:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Norton
[2010/04/20 19:06:18 | 000,408,024 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader(2).exe
[2010/04/20 19:05:04 | 000,408,024 | —- | C] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader.exe
[2 C:\Documents and Settings\Audra Drish\My Documents\*.tmp files -> C:\Documents and Settings\Audra Drish\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/19 10:52:15 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Audra Drish\Desktop\OTL.exe
[2010/05/18 12:07:31 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/05/17 17:08:51 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/05/17 16:42:23 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/17 16:41:25 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/17 16:41:15 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/17 16:41:01 | 000,361,728 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/17 16:41:00 | 527,749,120 | -HS- | M] () – C:\hiberfil.sys
[2010/05/17 16:39:02 | 004,980,736 | -H– | M] () – C:\Documents and Settings\Audra Drish\NTUSER.DAT
[2010/05/17 16:39:02 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Audra Drish\ntuser.ini
[2010/05/17 08:41:08 | 000,005,746 | —- | M] () – C:\Documents and Settings\Audra Drish\Application Data\wklnhst.dat
[2010/05/17 04:47:58 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Audra Drish\Desktop\~$ta Analysis Form.docx
[2010/05/17 04:40:54 | 000,011,019 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\Data%20Analysis%20Form.docx
[2010/04/26 20:00:17 | 000,000,692 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Audra Drish.job
[2010/04/23 23:24:00 | 000,002,137 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\iTunes.lnk
[2010/04/23 22:44:33 | 000,032,256 | —- | M] () – C:\Documents and Settings\Audra Drish\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/23 20:27:26 | 000,002,459 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.lnk
[2010/04/23 20:23:24 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Audra Drish\Desktop\HJTInstall(2)(2).exe
[2010/04/23 20:16:43 | 001,402,880 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.msi
[2010/04/22 23:10:08 | 000,000,839 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\4U AVI MPEG Converter.lnk
[2010/04/22 23:08:15 | 011,610,677 | —- | M] (4U Computing, Inc. ) – C:\Documents and Settings\Audra Drish\Desktop\4UAVIMPEGConverter.exe
[2010/04/22 13:13:39 | 000,000,349 | —- | M] () – C:\Documents and Settings\All Users\Documents\PCLECHAL.INI
[2010/04/21 21:02:35 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/04/21 00:55:11 | 000,677,310 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0401000.020\Cat.DB
[2010/04/20 21:58:27 | 097,525,032 | —- | M] (Apple Inc.) – C:\Documents and Settings\Audra Drish\Desktop\iTunesSetup.exe
[2010/04/20 20:48:06 | 000,002,421 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\VideoSpin.lnk
[2010/04/20 19:43:33 | 000,124,976 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/04/20 19:43:33 | 000,060,808 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/04/20 19:43:33 | 000,007,443 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/04/20 19:43:33 | 000,000,805 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/04/20 19:42:53 | 000,001,908 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/04/20 19:39:58 | 000,000,897 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Download Manager.lnk
[2010/04/20 19:39:58 | 000,000,768 | —- | M] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Installation Files.lnk
[2010/04/20 19:25:11 | 110,083,680 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360-ESD-17-6-0-32-EN.exe
[2010/04/20 19:06:18 | 000,408,024 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader(2).exe
[2010/04/20 19:05:11 | 000,408,024 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Audra Drish\Desktop\N360Downloader.exe
[2 C:\Documents and Settings\Audra Drish\My Documents\*.tmp files -> C:\Documents and Settings\Audra Drish\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/17 04:47:58 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Audra Drish\Desktop\~$ta Analysis Form.docx
[2010/05/17 04:40:42 | 000,011,019 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\Data%20Analysis%20Form.docx
[2010/04/23 20:18:00 | 000,002,459 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.lnk
[2010/04/23 20:16:32 | 001,402,880 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.msi
[2010/04/22 23:10:07 | 000,000,839 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\4U AVI MPEG Converter.lnk
[2010/04/22 23:09:47 | 000,126,464 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2010/04/21 21:02:34 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/04/21 21:02:34 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/04/21 00:59:36 | 527,749,120 | -HS- | C] () – C:\hiberfil.sys
[2010/04/20 21:06:36 | 000,002,137 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\iTunes.lnk
[2010/04/20 19:46:09 | 000,677,310 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\Cat.DB
[2010/04/20 19:43:34 | 000,007,443 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/04/20 19:43:34 | 000,000,805 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/04/20 19:42:52 | 000,001,908 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton 360.LNK
[2010/04/20 19:41:44 | 000,003,374 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymEFA.inf
[2010/04/20 19:41:44 | 000,002,793 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymDS.inf
[2010/04/20 19:41:44 | 000,001,473 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymNetV.inf
[2010/04/20 19:41:44 | 000,001,445 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymNet.inf
[2010/04/20 19:41:44 | 000,001,388 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.inf
[2010/04/20 19:41:44 | 000,001,382 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.inf
[2010/04/20 19:41:44 | 000,000,741 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\Iron.inf
[2010/04/20 19:41:43 | 000,001,754 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\ccHPx86.inf
[2010/04/20 19:40:54 | 000,007,787 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\symnetv.cat
[2010/04/20 19:40:54 | 000,007,444 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymEFA.cat
[2010/04/20 19:40:54 | 000,007,442 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtspx.cat
[2010/04/20 19:40:54 | 000,007,438 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\srtsp.cat
[2010/04/20 19:40:54 | 000,007,438 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\iron.cat
[2010/04/20 19:40:54 | 000,007,425 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymDS.cat
[2010/04/20 19:40:54 | 000,007,396 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\cchpx86.cat
[2010/04/20 19:40:54 | 000,007,368 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\SymNet.cat
[2010/04/20 19:40:53 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0401000.020\isolate.ini
[2010/04/20 19:13:03 | 000,000,897 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Download Manager.lnk
[2010/04/20 19:13:03 | 000,000,768 | —- | C] () – C:\Documents and Settings\Audra Drish\Desktop\Norton Installation Files.lnk
[2010/03/12 23:01:43 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/02/04 21:36:45 | 000,000,142 | —- | C] () – C:\WINDOWS\wpd99.drv
[2008/02/04 21:36:44 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2007/05/02 12:28:54 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/01/26 03:04:12 | 000,138,752 | —- | C] () – C:\WINDOWS\System32\mase32.dll
[2007/01/26 03:04:12 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\ma32.dll
[2006/04/27 00:25:15 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/03/22 19:39:10 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS38.DLL
[2006/03/20 17:12:27 | 000,000,012 | —- | C] () – C:\WINDOWS\dirsaver.ini
[2006/03/19 23:50:04 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2005/11/15 13:11:52 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/14 19:51:26 | 000,000,228 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/14 19:44:44 | 000,000,166 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2005/11/14 19:35:03 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/11/14 19:35:03 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/11/14 19:35:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/11/14 19:35:03 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/11/14 19:35:03 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/11/14 19:35:03 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/11/14 19:32:21 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2005/11/14 19:07:08 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2005/11/14 19:07:08 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2005/11/14 19:07:08 | 000,010,165 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2005/11/14 19:07:08 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2005/11/14 18:57:24 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\stac97co.dll
[2005/11/14 18:17:56 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/11/14 18:09:30 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/11/14 16:46:58 | 000,000,341 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/24 18:20:28 | 000,009,472 | —- | C] () – C:\WINDOWS\System32\drivers\tbiosdrv.sys
[2005/08/10 22:02:04 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/06/21 17:22:08 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2003/01/07 18:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/21 14:04:23 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\atsdrve.dll

========== LOP Check ==========

[2009/05/03 13:36:59 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/04/05 20:37:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2010/01/19 21:51:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fugazo
[2007/12/16 20:51:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/11/11 18:24:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2009/06/04 10:58:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2008/02/04 21:36:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2008/11/12 00:53:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2008/11/13 20:45:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle VideoSpin
[2006/12/14 15:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SonyPicturesGames
[2008/02/04 21:31:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2008/11/11 23:22:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/11/13 20:37:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VideoSpin
[2008/02/22 16:39:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/08/03 14:10:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo
[2010/02/21 19:27:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Canon
[2006/08/26 12:09:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\FUJIFILM
[2008/12/04 19:34:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\GetRightToGo
[2005/11/14 20:51:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\InterVideo
[2007/10/24 15:19:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Leadertech
[2008/11/11 18:24:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\muvee Technologies
[2007/03/08 13:37:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Snapfish
[2008/02/04 21:36:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\TaxCut
[2006/03/19 18:22:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Template
[2009/04/28 22:21:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\toshiba
[2007/01/15 16:00:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Audra Drish\Application Data\Viewpoint
[2010/05/17 17:08:51 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/12/03 14:56:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 01:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 07:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/11/14 10:04:20 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/11/14 10:04:20 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/11/14 10:04:20 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/20 19:43:33 | 000,124,976 | —- | M] (Symantec Corporation) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS

========== Alternate Data Streams ==========

@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7F4E393D
< End of report >
OTL Extras logfile created on: 5/19/2010 10:55:12 AM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Audra Drish\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.00 Mb Total Physical Memory | 123.00 Mb Available Physical Memory | 24.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 2.18 Gb Free Space | 5.84% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: AUDRA
Current User Name: Audra Drish
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = secfile] – C:\Documents and Settings\Audra Drish\Local Settings\Application Data\av.exe File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] – "C:\Program Files\FinePixViewer\FinePixViewer.exe" "%1" (FUJI PHOTO FILM CO.,LTD.)
Directory [FinePixPrint] – "C:\Program Files\FinePixViewer\FinePixViewer.exe" /p "%1" (FUJI PHOTO FILM CO.,LTD.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\TOSHIBA\ivp\NetInt\Netint.exe" = C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrade Engine – (TOSHIBA Corporation)
"C:\TOSHIBA\Ivp\ISM\pinger.exe" = C:\TOSHIBA\IVP\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger – File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon – (America Online, Inc)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed – (America Online Inc)
"C:\Program Files\Common Files\AOL\1132016392\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1132016392\EE\AOLServiceHost.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL – (America Online Inc.)
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL – ()
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL – (AOL Spyware Protection)
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL – File not found
"C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" = C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Engine – File not found
"C:\Program Files\Common Files\AOL\1132016392\EE\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1132016392\EE\aolsoftware.exe:*:Enabled:AOL Services – File not found
"C:\Program Files\Common Files\AOL\1132016392\EE\aim6.exe" = C:\Program Files\Common Files\AOL\1132016392\EE\aim6.exe:*:Enabled:AIM – (America Online, Inc.)
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – File not found
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe" = C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems)
"C:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe" = C:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile – ( )
"C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe" = C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe:*:Enabled:umi – (Pinnacle Systems)
"C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe" = C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin – (Pinnacle Systems)
"C:\Program Files\Toshiba\ConfigFree\CFXFER.exe" = C:\Program Files\Toshiba\ConfigFree\CFXFER.exe:*:Disabled:ConfigFree SUMMIT Engine – (TOSHIBA CORPORATION)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05832D65-6EDB-4D32-BA78-BCD0E2B91C02}" = Atheros Wireless LAN MiniPCI card Driver
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series" = Canon iP2600 series
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{24300A63-DD78-4AA5-A914-4D582C41D33A}" = TOSHIBA TouchPad On/Off Utility V2.05.01
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.4.3
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{425A2BC2-AA64-4107-9C29-484245BBEA05}" = TOSHIBA Software Upgrades
"{44734179-8A79-4DEE-BB08-73037F065543}" = Apple Mobile Device Support
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{49FC50FC-F965-40D9-89B4-CBFF80941033}" = Windows Movie Maker 2.0
"{4EDB1CA5-983F-4FC3-A8E3-E34981E05A60}" = Pinnacle VideoSpin
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{56190F69-01D3-46CA-9861-43377C5E9B87}" = TOSHIBA Utilities
"{601C6E14-DF1E-4113-A8C8-F9DB90CB0D88}" = SanDisk TransferMate
"{64212898-097F-4F3F-AECA-6D34A7EF82DF}" = TOSHIBA Zooming Utility
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{71D658CF-4E0D-4DA8-AA67-8C0B6F1C01FE}" = Atheros Client Utility
"{80FD852F-5AAC-4129-B931-06AAFFA43138}" = iTunes
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90AB0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint 2003 Template Pack 1
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for TOSHIBA
"{91A10409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office OneNote 2003
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}" = TOSHIBA Controls
"{AC4732F4-665D-4E6B-8E50-74D6B6FBE5A9}" = PassAlong Software
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{BA561482-C49D-4687-A61C-96236C1688F0}" = ArcSoft Software Suite
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0FC3B56-E345-40CD-A5CB-7EB791CE3E74}" = TOSHIBA Password Utility
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"4U AVI MPEG Converter_is1" = 4U AVI MPEG Converter (version 5.6.9)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"am-kitchenbrigade" = Kitchen Brigade
"AOL Spyware Protection" = AOL Spyware Protection
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"CAM-IN SUITE III" = CAM-IN SUITE III
"Canon iP2600 series User Registration" = Canon iP2600 series User Registration
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Free Video Flip and Rotate_is1" = Free Video Flip and Rotate version 1.4
"Free YouTube to iPod Converter_is1" = Free YouTube to iPod Converter version 3.1
"Free YouTube Uploader_is1" = Free YouTube Uploader version 2.2
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{56190F69-01D3-46CA-9861-43377C5E9B87}" = TOSHIBA Utilities
"InstallShield_{C0FC3B56-E345-40CD-A5CB-7EB791CE3E74}" = TOSHIBA Password Utility
"IrfanView" = IrfanView (remove only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"N360" = Norton 360
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PC Diagnostic Tool" = TOSHIBA PC Diagnostic Tool
"Picasa 3" = Picasa 3
"Port Magic" = Pure Networks Port Magic
"Power Saver" = TOSHIBA Power Saver
"PROR" = Microsoft Office Professional 2007 Trial
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"TDspBtn" = TOSHIBA Display Devices Change Utility
"TFNF5" = TOSHIBA Hotkey Utility for Display Devices
"Toshiba Q4 Retail Demo.scr" = Toshiba Q4 Retail Demo ScreenSaver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Uninstall_is1" = Uninstall 1.0.0.1
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/17/2010 6:48:58 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/17/2010 6:48:58 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/17/2010 6:49:00 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/17/2010 6:49:00 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/18/2010 11:01:18 AM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/18/2010 11:01:18 AM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/18/2010 5:36:14 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/18/2010 5:36:14 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/18/2010 7:38:49 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/18/2010 7:38:50 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

[ System Events ]
Error - 4/29/2010 8:01:30 PM | Computer Name = AUDRA | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 5/4/2010 4:12:35 PM | Computer Name = AUDRA | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{FBA93F0B-98D1-4138-A058-9595699109B9}
because another computer on the network has the same name. The server could not
start.

Error - 5/4/2010 4:12:56 PM | Computer Name = AUDRA | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 5/13/2010 4:59:50 PM | Computer Name = AUDRA | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 5/13/2010 4:59:50 PM | Computer Name = AUDRA | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 5/13/2010 5:00:14 PM | Computer Name = AUDRA | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 5/17/2010 12:33:04 AM | Computer Name = AUDRA | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.106 on
the Network Card with network address 0011F5EBF787.

Error - 5/13/2010 5:04:20 PM | Computer Name = AUDRA | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the W32Time service.

Error - 5/17/2010 5:35:33 AM | Computer Name = AUDRA | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 5/19/2010 6:17:19 AM | Computer Name = AUDRA | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.


< End of report >
OTL Extras logfile created on: 5/19/2010 10:55:12 AM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Audra Drish\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.00 Mb Total Physical Memory | 123.00 Mb Available Physical Memory | 24.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 2.18 Gb Free Space | 5.84% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: AUDRA
Current User Name: Audra Drish
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = secfile] – C:\Documents and Settings\Audra Drish\Local Settings\Application Data\av.exe File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] – "C:\Program Files\FinePixViewer\FinePixViewer.exe" "%1" (FUJI PHOTO FILM CO.,LTD.)
Directory [FinePixPrint] – "C:\Program Files\FinePixViewer\FinePixViewer.exe" /p "%1" (FUJI PHOTO FILM CO.,LTD.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\TOSHIBA\ivp\NetInt\Netint.exe" = C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrade Engine – (TOSHIBA Corporation)
"C:\TOSHIBA\Ivp\ISM\pinger.exe" = C:\TOSHIBA\IVP\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger – File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon – (America Online, Inc)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed – (America Online Inc)
"C:\Program Files\Common Files\AOL\1132016392\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1132016392\EE\AOLServiceHost.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL – (America Online Inc.)
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL – ()
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL – (AOL Spyware Protection)
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL – File not found
"C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" = C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Engine – File not found
"C:\Program Files\Common Files\AOL\1132016392\EE\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1132016392\EE\aolsoftware.exe:*:Enabled:AOL Services – File not found
"C:\Program Files\Common Files\AOL\1132016392\EE\aim6.exe" = C:\Program Files\Common Files\AOL\1132016392\EE\aim6.exe:*:Enabled:AIM – (America Online, Inc.)
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – File not found
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe" = C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems)
"C:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe" = C:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile – ( )
"C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe" = C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe:*:Enabled:umi – (Pinnacle Systems)
"C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe" = C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin – (Pinnacle Systems)
"C:\Program Files\Toshiba\ConfigFree\CFXFER.exe" = C:\Program Files\Toshiba\ConfigFree\CFXFER.exe:*:Disabled:ConfigFree SUMMIT Engine – (TOSHIBA CORPORATION)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05832D65-6EDB-4D32-BA78-BCD0E2B91C02}" = Atheros Wireless LAN MiniPCI card Driver
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series" = Canon iP2600 series
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{24300A63-DD78-4AA5-A914-4D582C41D33A}" = TOSHIBA TouchPad On/Off Utility V2.05.01
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.4.3
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{425A2BC2-AA64-4107-9C29-484245BBEA05}" = TOSHIBA Software Upgrades
"{44734179-8A79-4DEE-BB08-73037F065543}" = Apple Mobile Device Support
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{49FC50FC-F965-40D9-89B4-CBFF80941033}" = Windows Movie Maker 2.0
"{4EDB1CA5-983F-4FC3-A8E3-E34981E05A60}" = Pinnacle VideoSpin
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{56190F69-01D3-46CA-9861-43377C5E9B87}" = TOSHIBA Utilities
"{601C6E14-DF1E-4113-A8C8-F9DB90CB0D88}" = SanDisk TransferMate
"{64212898-097F-4F3F-AECA-6D34A7EF82DF}" = TOSHIBA Zooming Utility
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{71D658CF-4E0D-4DA8-AA67-8C0B6F1C01FE}" = Atheros Client Utility
"{80FD852F-5AAC-4129-B931-06AAFFA43138}" = iTunes
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90AB0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint 2003 Template Pack 1
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for TOSHIBA
"{91A10409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office OneNote 2003
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}" = TOSHIBA Controls
"{AC4732F4-665D-4E6B-8E50-74D6B6FBE5A9}" = PassAlong Software
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{BA561482-C49D-4687-A61C-96236C1688F0}" = ArcSoft Software Suite
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0FC3B56-E345-40CD-A5CB-7EB791CE3E74}" = TOSHIBA Password Utility
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"4U AVI MPEG Converter_is1" = 4U AVI MPEG Converter (version 5.6.9)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"am-kitchenbrigade" = Kitchen Brigade
"AOL Spyware Protection" = AOL Spyware Protection
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"CAM-IN SUITE III" = CAM-IN SUITE III
"Canon iP2600 series User Registration" = Canon iP2600 series User Registration
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Free Video Flip and Rotate_is1" = Free Video Flip and Rotate version 1.4
"Free YouTube to iPod Converter_is1" = Free YouTube to iPod Converter version 3.1
"Free YouTube Uploader_is1" = Free YouTube Uploader version 2.2
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{56190F69-01D3-46CA-9861-43377C5E9B87}" = TOSHIBA Utilities
"InstallShield_{C0FC3B56-E345-40CD-A5CB-7EB791CE3E74}" = TOSHIBA Password Utility
"IrfanView" = IrfanView (remove only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"N360" = Norton 360
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PC Diagnostic Tool" = TOSHIBA PC Diagnostic Tool
"Picasa 3" = Picasa 3
"Port Magic" = Pure Networks Port Magic
"Power Saver" = TOSHIBA Power Saver
"PROR" = Microsoft Office Professional 2007 Trial
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"TDspBtn" = TOSHIBA Display Devices Change Utility
"TFNF5" = TOSHIBA Hotkey Utility for Display Devices
"Toshiba Q4 Retail Demo.scr" = Toshiba Q4 Retail Demo ScreenSaver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Uninstall_is1" = Uninstall 1.0.0.1
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/17/2010 6:48:58 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/17/2010 6:48:58 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/17/2010 6:49:00 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/17/2010 6:49:00 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/18/2010 11:01:18 AM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/18/2010 11:01:18 AM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/18/2010 5:36:14 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/18/2010 5:36:14 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 5/18/2010 7:38:49 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 5/18/2010 7:38:50 PM | Computer Name = AUDRA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

[ System Events ]
Error - 4/29/2010 8:01:30 PM | Computer Name = AUDRA | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 5/4/2010 4:12:35 PM | Computer Name = AUDRA | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{FBA93F0B-98D1-4138-A058-9595699109B9}
because another computer on the network has the same name. The server could not
start.

Error - 5/4/2010 4:12:56 PM | Computer Name = AUDRA | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 5/13/2010 4:59:50 PM | Computer Name = AUDRA | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 5/13/2010 4:59:50 PM | Computer Name = AUDRA | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 5/13/2010 5:00:14 PM | Computer Name = AUDRA | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 5/17/2010 12:33:04 AM | Computer Name = AUDRA | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.106 on
the Network Card with network address 0011F5EBF787.

Error - 5/13/2010 5:04:20 PM | Computer Name = AUDRA | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the W32Time service.

Error - 5/17/2010 5:35:33 AM | Computer Name = AUDRA | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 5/19/2010 6:17:19 AM | Computer Name = AUDRA | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.


< End of report >
GGMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-19 12:15:12
Windows 5.1.2600 Service Pack 3
Running: phqie1tr.exe; Driver: C:\DOCUME~1\AUDRAD~1\LOCALS~1\Temp\ugldrpog.sys


—- System - GMER 1.0.15 —-

SSDT 82CFC680 ZwAlertResumeThread
SSDT 82C82050 ZwAlertThread
SSDT 82D218E8 ZwAllocateVirtualMemory
SSDT 82CFF968 ZwAssignProcessToJobObject
SSDT 82FCE7D0 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xAADCB210]
SSDT 82D0C5F8 ZwCreateMutant
SSDT 82D1E490 ZwCreateSymbolicLinkObject
SSDT 82F6CB08 ZwCreateThread
SSDT 82BF3050 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xAADCB490]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAADCB9F0]
SSDT 82D219C0 ZwDuplicateObject
SSDT 82D217C8 ZwFreeVirtualMemory
SSDT 82CFFD38 ZwImpersonateAnonymousToken
SSDT 82D01168 ZwImpersonateThread
SSDT 82E88078 ZwLoadDriver
SSDT 82D21728 ZwMapViewOfSection
SSDT 82B28050 ZwOpenEvent
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwOpenKey [0xAADCB7A0]
SSDT 82F6CA30 ZwOpenProcess
SSDT 82BA0288 ZwOpenProcessToken
SSDT 82F559E0 ZwOpenSection
SSDT 82D21A50 ZwOpenThread
SSDT 82D1E560 ZwProtectVirtualMemory
SSDT 82CEDB10 ZwResumeThread
SSDT 82F7B050 ZwSetContextThread
SSDT 82D0C8C8 ZwSetInformationProcess
SSDT 82C96050 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAADCBC40]
SSDT 82CA1050 ZwSuspendProcess
SSDT 82BAD2A0 ZwSuspendThread
SSDT 82B2A108 ZwTerminateProcess
SSDT 82CEE8B0 ZwTerminateThread
SSDT 82EEE0D8 ZwUnmapViewOfSection
SSDT 82D21858 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!_abnormal_termination + 90 804E26FC 4 Bytes CALL E7D0F919
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
init C:\WINDOWS\SYSTEM32\drivers\samfilt.sys entry point in "init" section [0xF8738D00]
? System32\Drivers\hiber_WMILIB.SYS The system cannot find the path specified. !

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Udfs \UdfsCdRom tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\meiudf \MeiUDF_Disk tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\meiudf \MeiUDF_CdRom tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Udfs \UdfsDisk tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF …
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x46 0x47 0x15 0xB0 …
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 …
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 …
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xE9 0x02 0x6C 0xFA …
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 …
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA …
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0xAA 0x52 0xC6 0x00 …
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xB2 0x46 0x9A 0xE2 …
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 …
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xF8 0x31 0x0F 0xA9 …
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F …

—- EOF - GMER 1.0.15 —-
I also attached the new hijackthis log.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:46:49 PM, on 5/19/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Audra Drish\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iastate.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.toshibadirect.com/dpdstart
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\4.1.0.32\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\4.1.0.32\IPSBHO.DLL
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\4.1.0.32\coIEPlg.dll
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPSODDCtl] TPSODDCtl.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [MRT] "C:\WINDOWS\system32\MRT.exe" /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Norton Download Manager{N360S_prod_1.19_4.1.0.32}] C:\Documents and Settings\All Users\Documents\Norton\{N360S_prod_1.19_4.1.0.32}\N360Downloader.exe /m
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Monitor.lnk = C:\Program Files\SanDisk\SanDisk TransferMate\SD Monitor.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZUxdm265YYUS
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1} (ParallelGraphics Cortona Control) - http://www.parallelgraphics.com/l2/bin/cortvrml.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - https://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O16 - DPF: {DBA8E419-0D5F-439B-A3CC-D01C768D9B51} (DVCDownloaderControl Object) - http://aolsvc.aol.com/onlinegames/sonydavi…aderControl.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} (Pearson MyEconLab Player Control) - http://asp.mathxl.com/books/_Players/EconPlayer.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\4.1.0.32\ccSvcHst.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/AUDRAD~1/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

–
End of file - 10391 bytes
Hi drishi8,

Welcome back.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O37 - HKCU\…exe [@ = secfile] – "C:\Documents and Settings\Audra Drish\Local Settings\Application Data\av.exe" /START "%1" %* File not found

:Commands
[CREATERESTOREPOINT]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

Next

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please post back with
  • OTL fix log
  • MBAM log
How is the computer now?

Thanks
Ok I'm not sure if I did something wrong. I accidentally hit Run Scan instead of Run Fix and I tried to close the program out and redo but I'm not sure if it worked. But after my computer restarted and I opened up my internet browser, it didn't ask to "open with" it just opened so I think it worked! Here's the OTL log All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry key HKEY_CURRENT_USER\Software\Classes\.exe\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Classes\secfile\ deleted successfully. HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully! ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: All Users User: Audra Drish ->Temp folder emptied: 81414022 bytes ->Temporary Internet Files folder emptied: 10308528 bytes ->Java cache emptied: 44329082 bytes ->FireFox cache emptied: 40298578 bytes ->Google Chrome cache emptied: 6229325 bytes ->Flash cache emptied: 206795 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 41 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 7730287 bytes User: NetworkService ->Temp folder emptied: 36882 bytes ->Temporary Internet Files folder emptied: 69867985 bytes User: Owner %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 31047705 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23947404 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 3798918208 bytes Total Files Cleaned = 3,924.00 mb OTL by OldTimer - Version 3.2.5.0 log created on 05202010_052437 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Audra Drish\Local Settings\Temp\WER34e6.dir00\appcompat.txt not found! C:\WINDOWS\temp\Perflib_Perfdata_6c4.dat moved successfully. Registry entries deleted on Reboot… I'll put the next log onto the next reply.
Here's the other log. It said I needed to purchase a registration key to fix the problems and I don't have the money right now to buy it. Hopefully next week I will. Operating System: Windows XP Service Pack 3 Num of Processors: Number of CPU(s): 1 Computer Name: AUDRA Memory Status: Installed RAM: 504MB Memory Available: 67200KB Precent of used RAM: %86 Hard Disk Information: Number of Hard Disk Drives: 1 — Hard Disk No. 1 — Cylinders: 4864 Tracks per cylinder: 255 Sectors per track: 63 Bytes per sector: 512 Total size: 40007761920 (Bytes) -> 38154 (MB) -> 37 (GB) Running Processes c:\windows\explorer.exe, 1033728, 239a79340ca6c0c4edac57cdbfedaa34 c:\program files\norton 360\engine\4.1.0.32\ccsvchst.exe, 126392, 9f7540e60490bab3feb38379b2fa5aa0 c:\windows\notepad.exe, 69120, 6f393950ac60a1a8751e69b84e49be5d c:\windows\agrsmmsg.exe, 88358, c3fe5131ff3ba55775adf7c1ba29da2d c:\windows\system32\tpsmain.exe, 315392, 688eba65c73fdec8bbdcf0a7c31d6a14 c:\windows\system32\tfnf5.exe, 73728, bb070d9e9c45aa0fe8112743852154b2 c:\program files\toshiba\toshiba controls\tfncky.exe, 188416, ef8becba83a8bc92d7f22763b000e785 c:\program files\toshiba\configfree\ndstray.exe, 978944, a58736546d653b73c3814b720a776c96 c:\program files\toshiba\configfree\cfsserv.exe, 798720, 5aa87165083591f8ce8ee804b1562fe6 c:\program files\itunes\ituneshelper.exe, 267048, 7075a4ba3acdac6873146a51f936c951 c:\program files\canon\myprinter\bjmyprt.exe, 1603152, 30101f7bb706985f24f8a3aa7188249c c:\program files\windows defender\msascui.exe, 866584, 88d14c034bf67c1b42bf5e6cc5c4e1bd c:\windows\system32\ctfmon.exe, 15360, 602e6099414e5b5ecd9f60a8cba78dd4 c:\progra~1\yahoo!\messenger\yahoomessenger.exe, 5244216, 2c18fba3d695936af3f023904a33432a c:\program files\sandisk\sandisk transfermate\sd monitor.exe, 114688, 7bf7faa1e93a6cc35e47243116a091ce c:\windows\system32\ramasst.exe, 155648, 6759263be3ddbc1376fbca8228660595 c:\program files\toshiba\configfree\cfxfer.exe, 901120, 75a1150215419b1e38912bf01282be84 c:\program files\mozilla firefox\firefox.exe, 307672, c91c5a444003588167a20f3d23e0e24a c:\windows\system32\tpsbattm.exe, 45056, 7fc55fa5638b3e34eae7e9afe5a371cd c:\program files\antimalware pro\antimalwarepro.exe, 16080016, f50d1f04fca301696b98aee95b290328 Startup registry items (LOCAL MACHINE) [LtMoh], C:\Program Files\ltmoh\Ltmoh.exe [AGRSMMSG], AGRSMMSG.exe [Apoint], C:\Program Files\Apoint2K\Apoint.exe [000StTHK], 000StTHK.exe [TPSMain], TPSMain.exe [TPSODDCtl], TPSODDCtl.exe [TFNF5], TFNF5.exe [TFncKy], TFncKy.exe [NDSTray.exe], NDSTray.exe [], [CFSServ.exe], CFSServ.exe -NoClient [QuickTime Task], "C:\Program Files\QuickTime\qttask.exe" -atboottime [iTunesHelper], "C:\Program Files\iTunes\iTunesHelper.exe" [CanonSolutionMenu], C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon [CanonMyPrinter], C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon [Windows Defender], "C:\Program Files\Windows Defender\MSASCui.exe" -hide Startup registry items (CURRENT USER) [ctfmon.exe], C:\WINDOWS\system32\ctfmon.exe [Messenger (Yahoo!)], "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet [PrMa_An_T], C:\Program Files\AntiMalware Pro\AntiMalwarePro.exe BHO Items {02478D38-C3F9-4efb-9B51-7695ECA05670} {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} {5CA3D70E-1895-11CF-8E15-001234567890} {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} {6D53EC84-6AAE-4787-AEEE-F4628F01010C} Executable files that were created in last 30 days: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\clt\cltlmsx.dll, 892784, 67cfef3edbcb2c4a171067c8132a054b c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\coffplgn\components\coffplgn.dll, 786800, a59c61e1a82846d03ae4631f9b5bb0c0 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20100429.001\bbrgen.dll, 611216, 229d00516095aeb324e1b52e9c82123c c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20100429.001\bhengine.dll, 1407888, 615f4adf07b99bde50cbeb01f47f2de7 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\bashdefs\20100429.001\bhrules.dll, 201616, 05908391fe5e723cd05e3a21a5190347 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20100422.002\idsxpx86.dll, 488312, 9a3fc9a7f1d7d4f265c105a59c43a0a8 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20100422.002\scxpx86.dll, 811896, c6dbcbd9e7ad50d3ab2c0a89881da42e c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20100429.001\idsxpx86.dll, 488312, 9a3fc9a7f1d7d4f265c105a59c43a0a8 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20100429.001\scxpx86.dll, 811896, c6dbcbd9e7ad50d3ab2c0a89881da42e c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20100505.001\idsxpx86.dll, 488312, 9a3fc9a7f1d7d4f265c105a59c43a0a8 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20100505.001\scxpx86.dll, 811896, c6dbcbd9e7ad50d3ab2c0a89881da42e c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20100513.002\idsxpx86.dll, 488312, 9a3fc9a7f1d7d4f265c105a59c43a0a8 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\20100513.002\scxpx86.dll, 811896, c6dbcbd9e7ad50d3ab2c0a89881da42e c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\binhub\idsxpx86.dll, 488312, 9a3fc9a7f1d7d4f265c105a59c43a0a8 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\ipsdefs\binhub\scxpx86.dll, 811896, c6dbcbd9e7ad50d3ab2c0a89881da42e c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20100523.004\cceraser.dll, 2747440, d72679ff2e9f95280063437014011a08 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20100523.004\ecmsvr32.dll, 275824, 650e038aaef2f0c5fa8db2be40dcb271 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20100523.004\naveng32.dll, 177520, c514fd53e026b186c963be9714574ca9 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\definitions\virusdefs\20100523.004\navex32a.dll, 1697136, 545bc62cbe89103231b1d6cce4b74aba c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\ipsffplgn\components\ipsffpl.dll, 164216, 89e65a0d01b6422c89fc02e6f2ef0ad1 c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\ocs\hsplayer.dll, 1122672, 783e7142540a0271e7483ae2ab7308c5 c:\documents and settings\all users\documents\norton\{n360s_prod_1.19_4.1.0.32}\n360downloader.exe, 408024, bb37abc313972645f2beda28bcd8338b c:\documents and settings\audra drish\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\hijackthis.exe, 388096, 3ad9298644308195432d4b93bab8c0a0 c:\documents and settings\audra drish\desktop\4uavimpegconverter.exe, 11610677, 684eeb1d2656984d2b2cfc11ec44959d c:\documents and settings\audra drish\desktop\anti-malware-pro-v04.exe, 2813760, 7b68f81e1c62a19304b8534b32731886 c:\documents and settings\audra drish\desktop\hijackthis.exe, 388608, ab3458a14e7fec95d210399cd1689d2d c:\documents and settings\audra drish\desktop\itunessetup.exe, 97525032, 08d2ff39b6d0b6cbf469a46447de3c8b c:\documents and settings\audra drish\desktop\n360-esd-17-6-0-32-en.exe, 110083680, 84ce7e94a33737a6e6356f8145c4376a c:\documents and settings\audra drish\desktop\n360downloader(2).exe, 408024, bb37abc313972645f2beda28bcd8338b c:\documents and settings\audra drish\desktop\n360downloader.exe, 408024, bb37abc313972645f2beda28bcd8338b c:\documents and settings\audra drish\desktop\otl.exe, 571904, a1e67ca06ac6875d2ada2b27995eab87 c:\documents and settings\audra drish\desktop\phqie1tr.exe, 293376, 09107f1af805cb0f589db1eb7248f2f3 c:\program files\4u computing\avi mpeg converter\avimpegconverter.exe, 998912, 61c5f73cfb1242fe20bcbbec49e51c22 c:\program files\4u computing\avi mpeg converter\contextmenuhandle.dll, 188928, f78c3082703d4a83dace0fa0b3d257b5 c:\program files\4u computing\avi mpeg converter\tutorial.exe, 921600, 91569a325378bbf0834de09b8de1b07d c:\program files\4u computing\avi mpeg converter\unins000.exe, 639933, 1c473e0378ac2737ef3757b7bbf7629b c:\program files\antimalware pro\antimalwarepro.exe, 16080016, f50d1f04fca301696b98aee95b290328 c:\program files\antimalware pro\cl.exe, 221184, 8f1f141ff1d57f6e9da30d190564030a c:\program files\antimalware pro\engineap.dll, 851968, 3684d26aa00ccccd98e9d3b1f0a9093e c:\program files\antimalware pro\unins000.exe, 691481, 185b0a4b8f39fc0ecbd4455966ec7c48 c:\program files\common files\symantec shared\sevinst.exe, 832904, d758427d7317376e6da8672f521637cb c:\program files\norton 360\branding\muis.dll, 8560, 32ca93be0cef50721e481af8f4719781 c:\program files\norton 360\engine\4.1.0.32\acctmgr.dll, 1131888, c99b7f1e4aece4db599f8a4923a85cd9 c:\program files\norton 360\engine\4.1.0.32\appmgr32.dll, 268656, b5686758a61727334444ecb5be28ef08 c:\program files\norton 360\engine\4.1.0.32\arestore.exe, 3846512, 7be08514a2aa3032988685a06504ebce c:\program files\norton 360\engine\4.1.0.32\asdcacl.dll, 134512, c01a2e949203addc7aa616982367e561 c:\program files\norton 360\engine\4.1.0.32\asengine.dll, 3637104, 1b9b6e8db1f4f9ed885ef6360943c184 c:\program files\norton 360\engine\4.1.0.32\ashelper.dll, 383856, 17ecd8fa0ed6206c251c9499f3122cd6 c:\program files\norton 360\engine\4.1.0.32\asoehook.dll, 415088, 7f138a74eb6a4df8b3a1915453437b30 c:\program files\norton 360\engine\4.1.0.32\asoelnch.exe, 48496, 68850fe9c22c1fa4ab789147e04e7054 c:\program files\norton 360\engine\4.1.0.32\avexclu.dll, 131952, c27cd321d9f50f6eeaa1cf301efd04a5 c:\program files\norton 360\engine\4.1.0.32\avifc.dll, 462704, 230a7266b895c81e8cb14b6aaf013a88 c:\program files\norton 360\engine\4.1.0.32\avmail.dll, 97648, e38c40cbd6bc598f9a2cd77168195b08 c:\program files\norton 360\engine\4.1.0.32\avmodule.dll, 1446256, 2dbe33b0fe61389b5317da13cda72b02 c:\program files\norton 360\engine\4.1.0.32\avpapp32.dll, 288624, bf7c714e9694bafbe0e6eea7e36ed0ca c:\program files\norton 360\engine\4.1.0.32\avpsvc32.dll, 261488, 5d1c27a70604ba79a0a8b3eb5742e1cc c:\program files\norton 360\engine\4.1.0.32\avscanui.dll, 458096, 2cb2f65b485ce48c28ff14d1bcdc45e8 c:\program files\norton 360\engine\4.1.0.32\avscntsk.dll, 185712, 6bbdab33c38b2f8692a164f454255235 c:\program files\norton 360\engine\4.1.0.32\bhca.exe, 356712, ffed5ac63838bc74cb2dd765deaf2c9b c:\program files\norton 360\engine\4.1.0.32\bhclient.dll, 143760, c4a2fd07bf4f0d9ed267b3026fbbba36 c:\program files\norton 360\engine\4.1.0.32\bhsvcplg.dll, 107408, 19f8be903d65fcc2fe146d9dad0e14e5 c:\program files\norton 360\engine\4.1.0.32\bucomm.dll, 279408, 69ec661163b8e625f3da9cd6c7f79ed0 c:\program files\norton 360\engine\4.1.0.32\budatacl.dll, 106352, b453cc4d4292f2ac45ce053883ddc914 c:\program files\norton 360\engine\4.1.0.32\bueng.dll, 1447280, a08129cd4c9aec391cd4145e6426d65e c:\program files\norton 360\engine\4.1.0.32\buih.exe, 74096, ab807f9f51b83b87e5aebd0cfcefee8a c:\program files\norton 360\engine\4.1.0.32\buiopart.dll, 76656, 92e2e47638b1aeb252c971b66a3515d2 c:\program files\norton 360\engine\4.1.0.32\bumc.dll, 95600, 01c54e4223c80b65c633794b1694cb7b c:\program files\norton 360\engine\4.1.0.32\buprov.dll, 442736, bfed55e35c2032b7c0543a83eb634829 c:\program files\norton 360\engine\4.1.0.32\bushell.dll, 2389360, a439767dd7e2046d6d16254b14722299 c:\program files\norton 360\engine\4.1.0.32\busvc.dll, 421232, e99c058826ae6591541a4cf70a498378 c:\program files\norton 360\engine\4.1.0.32\buui.dll, 472944, e6c2a280b57a8cac1caa2ea29b567ed0 c:\program files\norton 360\engine\4.1.0.32\buuiplg.dll, 106864, 7b0a18b6b77ac250af3a20727672cbb8 c:\program files\norton 360\engine\4.1.0.32\buvss.exe, 145264, afd5ab5bb2bea99ea909f2ba80973ac3 c:\program files\norton 360\engine\4.1.0.32\buvssvst.dll, 28528, 6d4f77da7e3ed4f3f927d943fb979489 c:\program files\norton 360\engine\4.1.0.32\buvssxp.dll, 28528, ca792071584c2484c146cf6df8ada055 c:\program files\norton 360\engine\4.1.0.32\ccalert.dll, 219512, c1ee57ab9fa9eaa6e43d6aa7cda32104 c:\program files\norton 360\engine\4.1.0.32\ccemlpxy.dll, 221560, b8f166311104934b5f9e80150b390ab4 c:\program files\norton 360\engine\4.1.0.32\ccerrdsp.dll, 101752, 65664ae15d76b240797962605d318c77 c:\program files\norton 360\engine\4.1.0.32\ccgevt.dll, 284536, c342d3e0a29998916f286da18d55ea02 c:\program files\norton 360\engine\4.1.0.32\ccglog.dll, 199544, fac89179f3663ed5a28e98ee49ae077c c:\program files\norton 360\engine\4.1.0.32\ccipc.dll, 152952, 576d75077383ad1a6f783cbdae5adf81 c:\program files\norton 360\engine\4.1.0.32\ccjobmgr.dll, 380792, 15b4dd3a826730e73eef756c5a034f25 c:\program files\norton 360\engine\4.1.0.32\ccl90u.dll, 646008, 81c945d25ff22fb0402b658600051ac2 c:\program files\norton 360\engine\4.1.0.32\ccscanw.dll, 393592, bf0723bb99c2fa27def618ee9fb566a0 c:\program files\norton 360\engine\4.1.0.32\ccsebind.dll, 610168, 3a2691ffd109d245a8463145e00cdb2e c:\program files\norton 360\engine\4.1.0.32\ccset.dll, 268152, d9d3818063a1584731a42330b1178c41 c:\program files\norton 360\engine\4.1.0.32\ccseupdt.exe, 112504, be83bf0865256706349cae9b7e928208 c:\program files\norton 360\engine\4.1.0.32\ccsubeng.dll, 262008, dbcadebb728711ac2207645cf2ffe26c c:\program files\norton 360\engine\4.1.0.32\ccsvc.dll, 135032, c8620e8caf3fc5db5e1d79640621cde1 c:\program files\norton 360\engine\4.1.0.32\ccsvchst.exe, 126392, 9f7540e60490bab3feb38379b2fa5aa0 c:\program files\norton 360\engine\4.1.0.32\ccvrtrst.dll, 85880, 0334557d4cd32e74fa8e1ac6238fb31e c:\program files\norton 360\engine\4.1.0.32\cltaldis.dll, 698248, eec73f140f57a4c8106ce72b3bb6bac9 c:\program files\norton 360\engine\4.1.0.32\cltalert.dll, 518024, fab72d71293ba27282fd28080bbbb580 c:\program files\norton 360\engine\4.1.0.32\cltelprv.dll, 48008, 0d47eae2ab31bcea37bb7272b155b154 c:\program files\norton 360\engine\4.1.0.32\cltlmc.dll, 91528, 2a0c23c8f2a888a646af79b94d01263b c:\program files\norton 360\engine\4.1.0.32\cltlmh.exe, 482184, 3490248573a659abf0e38344befab0e9 c:\program files\norton 360\engine\4.1.0.32\cltlmj.dll, 992136, 24f01ff2370111c2e0dc4415d4999581 c:\program files\norton 360\engine\4.1.0.32\cltlms.dll, 533384, 3e728e260ca6b370ebb86564a619aa8f c:\program files\norton 360\engine\4.1.0.32\cltnahd.dll, 99208, 75b37581e3754d815e0fff0d357ed0b0 c:\program files\norton 360\engine\4.1.0.32\cltrdurl.dll, 44936, e6674d4836d59e83cb3242a8542eae00 c:\program files\norton 360\engine\4.1.0.32\cltui.dll, 318832, 6faff17949b1b7a025ea52e60624d73b c:\program files\norton 360\engine\4.1.0.32\cltwzhlp.dll, 25480, 2a13ff5e2f74edb02f14616acf9024f0 c:\program files\norton 360\engine\4.1.0.32\codatapr.dll, 322416, 11451a0ddd115207ba87081f3652187a c:\program files\norton 360\engine\4.1.0.32\coexport.exe, 485232, 8516d9641267817d766bd4cde584a03b c:\program files\norton 360\engine\4.1.0.32\coffplgn.dll, 786800, a59c61e1a82846d03ae4631f9b5bb0c0 c:\program files\norton 360\engine\4.1.0.32\coieplg.dll, 394608, bedb68efa4539038ff98e0b1588f7208 c:\program files\norton 360\engine\4.1.0.32\coinst.exe, 29040, 64f105629a12d08efb624745cd3deccc c:\program files\norton 360\engine\4.1.0.32\comcplug.dll, 76656, a2fa154b19a9b6958593bbf82f5b7512 c:\program files\norton 360\engine\4.1.0.32\coparse.dll, 193904, 83140f496f1516483e6625e3f0d336f2 c:\program files\norton 360\engine\4.1.0.32\cosvcplg.dll, 586096, 2f67c1cc928868d6c1a16c2bfa01d7a1 c:\program files\norton 360\engine\4.1.0.32\couictlr.dll, 750448, c2d6c1160318fe61fac39e7d632a3190 c:\program files\norton 360\engine\4.1.0.32\cowpplg.dll, 728432, ba318de72b4fd05ad3bf28b1bfc97f96 c:\program files\norton 360\engine\4.1.0.32\cueng.dll, 243056, 3fa34991b6da29dd5386e1074cea4702 c:\program files\norton 360\engine\4.1.0.32\cuieplg.dll, 106864, eee180f998e0cb9d140b0dc57318e9f1 c:\program files\norton 360\engine\4.1.0.32\cutfplg.dll, 86896, b2ce75e69b88e45e34b70c3ac8ca6f2e c:\program files\norton 360\engine\4.1.0.32\dec_abi.dll, 1844064, 892d4424725e7438221ab5e3e8042c5b c:\program files\norton 360\engine\4.1.0.32\defutdcd.dll, 224120, b4b98ac73194c444cf08b313bd22f2ee c:\program files\norton 360\engine\4.1.0.32\diagrpt.dll, 118128, 4095be05f235b23cb7bcfa74e35051f5 c:\program files\norton 360\engine\4.1.0.32\diarkive.dll, 245624, 551c9e744f57f3b2a67a80d430f7474f c:\program files\norton 360\engine\4.1.0.32\diluecbk.dll, 97144, 8700349eadf32cc997e17f7d005e0008 c:\program files\norton 360\engine\4.1.0.32\dimaster.dll, 135032, 11ecf9842a6ba03547358e65f9fbd7ac c:\program files\norton 360\engine\4.1.0.32\distrptr.dll, 284536, e8071aff4f3f0d7f4ae4527ece88f77b c:\program files\norton 360\engine\4.1.0.32\dnlp0808.exe, 308592, 48509fb792ff0f0449a900ac8bd6fe43 c:\program files\norton 360\engine\4.1.0.32\dscli.dll, 298336, 1ce6571f48cd0b809cd66a3fbf4f6974 c:\program files\norton 360\engine\4.1.0.32\ducclib.dll, 33144, 1bb7372329aba92980d0f0ed5fae2bf0 c:\program files\norton 360\engine\4.1.0.32\dulucbk.dll, 68960, c7445c7359efa49a74359b32458eb8f9 c:\program files\norton 360\engine\4.1.0.32\ecmldr32.dll, 54640, b5213ae9ef1e819edf728e27dfe604ae c:\program files\norton 360\engine\4.1.0.32\efacli.dll, 66408, f99a3435fbdeecb1211ca5e8fed7f39a c:\program files\norton 360\engine\4.1.0.32\efainst.exe, 61800, c8299af01f3799f03ff2e78ac7f5dda2 c:\program files\norton 360\engine\4.1.0.32\ffprefs.dll, 47472, 918b440565403f8cd46e53448e942c42 c:\program files\norton 360\engine\4.1.0.32\fwcore.dll, 153456, a2820881beba1b0f257663014be9f345 c:\program files\norton 360\engine\4.1.0.32\fwgenplg.dll, 90992, 86c9282b61047bac3c7246b43fb0fed4 c:\program files\norton 360\engine\4.1.0.32\fwhelper.dll, 107888, f25d4ffe9337b6b0c4cb3803719853a8 c:\program files\norton 360\engine\4.1.0.32\fwmcplug.dll, 259440, 8bb06e08f1431abdd73068e34b8e793e c:\program files\norton 360\engine\4.1.0.32\fwsesal.dll, 179056, f909844c273f225259b82f3b7cd11aae c:\program files\norton 360\engine\4.1.0.32\fwsetup.dll, 101744, a6fe4303457ac6d9561f607f022de0db c:\program files\norton 360\engine\4.1.0.32\gadgetca.exe, 31088, 02a8864d747a2183dad8305f776e365f c:\program files\norton 360\engine\4.1.0.32\gearaw32.dll, 3577192, 929c33af4697809b4873da1524306a20 c:\program files\norton 360\engine\4.1.0.32\geardifx.exe, 173416, d8d56d0639b09ae17abd497558d18526 c:\program files\norton 360\engine\4.1.0.32\gwlangen.dll, 238952, c22638c2e5938d0eab59dcb3f5b37b98 c:\program files\norton 360\engine\4.1.0.32\gwrks32.dll, 394600, bea79b5095377b563290afff24bdb7d7 c:\program files\norton 360\engine\4.1.0.32\hncfg.dll, 101744, 5a2cec2dcc78881cb29f2849522a06a6 c:\program files\norton 360\engine\4.1.0.32\hncore.dll, 474480, 3621fea86e2a127c26a02768ee0e5357 c:\program files\norton 360\engine\4.1.0.32\hndisco.dll, 142704, f1e9ce6e664f4d4c01f80212b5cc36a0 c:\program files\norton 360\engine\4.1.0.32\hsplayer.exe, 4362096, 66ab18c4a042578ae0c0c4982402868a c:\program files\norton 360\engine\4.1.0.32\hsui.dll, 108912, e0453934582b1b70db331dc2041edc4e c:\program files\norton 360\engine\4.1.0.32\idsaux.dll, 66424, bc66890242a6987ba0378764382c47ce c:\program files\norton 360\engine\4.1.0.32\imcfg.dll, 68464, a0762d1ffc0ca4a5574ae90212ddc75f c:\program files\norton 360\engine\4.1.0.32\instca.exe, 114032, cd28bd24087779068b76e22e5ebaae27 c:\program files\norton 360\engine\4.1.0.32\ipsbho.dll, 79224, f710667a3ef1e0504a4b3b29d80ca773 c:\program files\norton 360\engine\4.1.0.32\ipsffpl.dll, 164216, 89e65a0d01b6422c89fc02e6f2ef0ad1 c:\program files\norton 360\engine\4.1.0.32\ipsplug.dll, 78200, 30e238baa7d6075a4caa7cd114637519 c:\program files\norton 360\engine\4.1.0.32\iron.dll, 597336, 3f05d8885946004b32041685c27244ac c:\program files\norton 360\engine\4.1.0.32\isdatapr.dll, 534896, 8f463f92fe086b41d74b4196c02418d9 c:\program files\norton 360\engine\4.1.0.32\isdatasv.dll, 268144, a53ee1bce45f2401206936b56f47600f c:\program files\norton 360\engine\4.1.0.32\iserror.dll, 301936, 8fc2eff6deefde7429ebdcaa4310df36 c:\program files\norton 360\engine\4.1.0.32\ispwd.dll, 113008, 535bd7b2343994826a352fa2a4cf98ed c:\program files\norton 360\engine\4.1.0.32\ivplugin.dll, 485744, c1bd2af7c84e842dc0f8c017192a3d14 c:\program files\norton 360\engine\4.1.0.32\jwncu.dll, 52592, 17ae2d4f4725771fc1eac4ff670b65e2 c:\program files\norton 360\engine\4.1.0.32\jwrc.dll, 52592, c100a08937a6e8fc94649235d0b62503 c:\program files\norton 360\engine\4.1.0.32\jwwdf.dll, 91504, e5a704a1d86313af162f3552b81e2ca0 c:\program files\norton 360\engine\4.1.0.32\lue.dll, 965984, 9398ed5db6592bfb2cbaefdba3b482c6 c:\program files\norton 360\engine\4.1.0.32\mcmgr32.dll, 108400, e61945158f1896f60e77ecb0b08e7bf5 c:\program files\norton 360\engine\4.1.0.32\mcstatus.dll, 296304, f9989aa37fe787c354828d9852fb3710 c:\program files\norton 360\engine\4.1.0.32\mcui32.exe, 377200, 068f48ef85d87f026b0f497fc59cd2f9 c:\program files\norton 360\engine\4.1.0.32\microsoft.vc90.crt\msvcm90.dll, 225280, 78cec510cf7dfdd431618272c69e245b c:\program files\norton 360\engine\4.1.0.32\microsoft.vc90.crt\msvcp90.dll, 569664, c3fff4eff42061f193fad831b7e8868e c:\program files\norton 360\engine\4.1.0.32\microsoft.vc90.crt\msvcr90.dll, 653120, 86491617670f6e74dc5c9145aee2d0f4 c:\program files\norton 360\engine\4.1.0.32\msl.dll, 271736, 6378e56d07d4791fba2657a8ffbe6c9b c:\program files\norton 360\engine\4.1.0.32\msouplug.dll, 247664, 058e8393a80764bdab50caae48db3dcc c:\program files\norton 360\engine\4.1.0.32\navlogv.dll, 462192, b205bf61046e177cc84a149593959d06 c:\program files\norton 360\engine\4.1.0.32\navrcui.dll, 203632, 1bce6b06186369d88d07e7fc837b2c36 c:\program files\norton 360\engine\4.1.0.32\navshext.dll, 101744, 293c96e334a246eeaddf2ff6501c4195 c:\program files\norton 360\engine\4.1.0.32\navtskwz.dll, 606576, a7edfd55c67cf319457eaf82ac468ae3 c:\program files\norton 360\engine\4.1.0.32\navw32.exe, 118128, cba4a7b75dd7c13073e4a236517c36b6 c:\program files\norton 360\engine\4.1.0.32\navwnt.exe, 61808, 42ed8c51e3bf576767950d5e2d534198 c:\program files\norton 360\engine\4.1.0.32\ncolue.dll, 226672, 2f36fa4b2f62e713041741b529ae340d c:\program files\norton 360\engine\4.1.0.32\ncw.dll, 2161520, 645cb31891c5a261a9a11cf3d0c79025 c:\program files\norton 360\engine\4.1.0.32\netmap.dll, 306032, 46461f40a9c2cd16caa721ba19ee0330 c:\program files\norton 360\engine\4.1.0.32\nispinst.dll, 51568, f89a73408bd5b375a7bdc864dc1fcdd4 c:\program files\norton 360\engine\4.1.0.32\nmapapp.exe, 199536, 922a72e08f8f0eeb64cbbb3d315f0543 c:\program files\norton 360\engine\4.1.0.32\nnmgr.dll, 1210736, bcf4af6432cdfcbec6342cd9f5ae33b1 c:\program files\norton 360\engine\4.1.0.32\npc360ui.dll, 602480, d84ab5a8888c8f626d4970e4770697d3 c:\program files\norton 360\engine\4.1.0.32\npcgadget.dll, 73584, 2d0863c87a71fc00e2e6b2d741fea4e6 c:\program files\norton 360\engine\4.1.0.32\npctray.dll, 251760, 7dba1c2fc985963cf627d44470a7b9d3 c:\program files\norton 360\engine\4.1.0.32\numeng.dll, 134000, fd705091b09638223fcf01876cb5b610 c:\program files\norton 360\engine\4.1.0.32\numgui.dll, 163184, 2ba5e7eee6545cb6966c0cefe2748ed9 c:\program files\norton 360\engine\4.1.0.32\oeheur.dll, 47480, 353400e93daec3d8d880ebd0410695c1 c:\program files\norton 360\engine\4.1.0.32\officeav.dll, 73072, d903291d5f854a2c2719f8424f15b967 c:\program files\norton 360\engine\4.1.0.32\patch25d.dll, 74120, f9807df98f15644a6b30ca1a0f8b869a c:\program files\norton 360\engine\4.1.0.32\pifscr.dll, 1763720, d4f77193127fd04f4ed04c27920bcd21 c:\program files\norton 360\engine\4.1.0.32\pifutil.dll, 25992, ec3c5a6d146981e2f88d45805afa1670 c:\program files\norton 360\engine\4.1.0.32\qbackup.dll, 111984, bc17552596f8e39615a2dacdb064c607 c:\program files\norton 360\engine\4.1.0.32\qsplugin.dll, 142192, ad7a9c853108812a1b3ec0cb192f28f3 c:\program files\norton 360\engine\4.1.0.32\qstartui.dll, 106864, 070403de3fb3098bfd60efcfa23b9e44 c:\program files\norton 360\engine\4.1.0.32\rf.dll, 1213888, 0e6b85543193d53858caf15a574f3b45 c:\program files\norton 360\engine\4.1.0.32\rfpxy3.dll, 537968, 50ef39896e8ba798e565725d565d9809 c:\program files\norton 360\engine\4.1.0.32\rptcrdui.dll, 225648, 374ae8ab0ef1e1bcf9c1d060a3d2443b c:\program files\norton 360\engine\4.1.0.32\rscan.dll, 126832, 30993fc5eedbb65548c51c1247e6ebbf c:\program files\norton 360\engine\4.1.0.32\ruleui.dll, 489328, 6fb4a30294228db89e9d30dec3112ec7 c:\program files\norton 360\engine\4.1.0.32\savrt32.dll, 32112, 290a286e9f734474627d4b22e785f930 c:\program files\norton 360\engine\4.1.0.32\scanless.dll, 199536, 6258e57dfe28a8ef4f68ab2380f2aa0f c:\program files\norton 360\engine\4.1.0.32\sdkcmn.dll, 334192, e29f51b0769d76c8f4a324661e947134 c:\program files\norton 360\engine\4.1.0.32\settings.dll, 754544, 8cffb48e684d8d463c880c5196424cd3 c:\program files\norton 360\engine\4.1.0.32\sevinst.exe, 832904, d758427d7317376e6da8672f521637cb c:\program files\norton 360\engine\4.1.0.32\sndsvc.dll, 310152, ce3b3cfdda2c960edd525ba676b69179 c:\program files\norton 360\engine\4.1.0.32\srtsp32.dll, 301936, 4ea31ccbb25200383536ffc362f2c48b c:\program files\norton 360\engine\4.1.0.32\symdgnhc.exe, 113032, 4bb2922ecf51f38b77c3e4e31a709fc7 c:\program files\norton 360\engine\4.1.0.32\symdltcl.dll, 206216, f2813816a2626a7896600019e6dcc46f c:\program files\norton 360\engine\4.1.0.32\symerr.exe, 785264, 0bd5bca242f831e9c97230a4a8efbd75 c:\program files\norton 360\engine\4.1.0.32\symhtml.dll, 2374488, 277dda4b3e5fba7fbee6ff58cf50bde8 c:\program files\norton 360\engine\4.1.0.32\symimins.exe, 232328, ea221d2a4d81bd130ecea3dcb6a93cfa c:\program files\norton 360\engine\4.1.0.32\symneti.dll, 221576, e1f9ce86b32c7ee8e981bbe9718789aa c:\program files\norton 360\engine\4.1.0.32\symrdrsv.dll, 41352, 5a87607e2adbde1535427f9ef36db762 c:\program files\norton 360\engine\4.1.0.32\symredir.dll, 53128, 66c775d2bba2b6553fe0e9ffb112b31c c:\program files\norton 360\engine\4.1.0.32\taskwiz.dll, 180592, 277c4e342a5962126e1106f1d7246040 c:\program files\norton 360\engine\4.1.0.32\tudatapr.dll, 97136, 917659ebfb7533beebc53ff3fa784654 c:\program files\norton 360\engine\4.1.0.32\tuih.exe, 84848, 564b19aabee09bd6da23c15288e1eecf c:\program files\norton 360\engine\4.1.0.32\tumcfplg.dll, 67952, 90d0c17a2ae9e9ca6310f104828bd8ed c:\program files\norton 360\engine\4.1.0.32\tutw.dll, 63344, d0c133c5c919dfa621489e703d6d4299 c:\program files\norton 360\engine\4.1.0.32\tuui.dll, 105840, eb26a34cc9e0107cbc678be41c368aaa c:\program files\norton 360\engine\4.1.0.32\uialert.dll, 529776, acd2ae504a0b9e0bb492efa2775d56ee c:\program files\norton 360\engine\4.1.0.32\uicldst.dll, 77168, 6efd73c8650a8e60f1228d2732450480 c:\program files\norton 360\engine\4.1.0.32\uigadctl.dll, 61296, 66b8eb2a01226a6f97411403768e9000 c:\program files\norton 360\engine\4.1.0.32\uihost.dll, 97136, 15bbaddcb8412046d36a47e00ceb0fdd c:\program files\norton 360\engine\4.1.0.32\uiperf.dll, 185712, 6fd72ad3dcd5f45d8935e49af377b750 c:\program files\norton 360\engine\4.1.0.32\uistub.exe, 105840, 9b81cc6794c73820f619dcbda7ac7af2 c:\program files\norton 360\engine\4.1.0.32\uiwebhst.dll, 106352, 2556df78d7081de3c687b0a9392b6e71 c:\program files\norton 360\engine\4.1.0.32\wfpunins.exe, 168328, 1ce0473008329834122384c15c323d97 c:\program files\norton 360\engine\4.1.0.32\wscstub.exe, 99040, d309af53bf52c64a7ce0b79617c9b971 c:\program files\norton 360\engine\4.1.0.32\x64\difxapi.dll, 525792, 06669d78b4bec773e54e51b2dcef5271 c:\program files\norton 360\engine\4.1.0.32\x64\difxinstall64.exe, 86376, f03832171c4684614e501b941f67d35f c:\program files\norton 360\engine\4.1.0.32\x64\x64\gearaspi.dll, 107368, 116ff93cbc02e3e43299b86cfe0611b5 c:\program files\norton 360\engine\4.1.0.32\x64\x64\gearaspi64.dll, 126312, bd1723cfc628dbd0574f206ff87f630e c:\program files\norton 360\engine\4.1.0.32\x86\difxapi.dll, 319456, 2cea87ee88c420f1036819be6d2462bf c:\program files\norton 360\engine\4.1.0.32\x86\difxinstall32.exe, 75112, b3abc30dfe245f002b7cea7a455d7806 c:\program files\norton 360\engine\4.1.0.32\x86\x86\gearaspi.dll, 107368, 116ff93cbc02e3e43299b86cfe0611b5 c:\program files\norton 360\mui\4.1.0.32\09\01\rcalert.dll, 53112, 69706e7410babcce9d0712c62b595bfc c:\program files\norton 360\mui\4.1.0.32\09\01\rcemlpxy.dll, 12664, 561efb9d2019937ac43b787ecb73a47f c:\program files\norton 360\mui\4.1.0.32\09\01\rcerrdsp.dll, 22904, 81135617e337e472fbc08eb506d64c25 c:\program files\norton 360\mui\4.1.0.32\09\01\rcsvchst.dll, 8568, 9d6df3bc38a4cb1411bc400879c2f831 c:\program files\norton 360\mui\4.1.0.32\images\360base.dll, 3757936, a7db59750f271ffa3a3d08ba2010bb2c c:\program files\nortoninstaller\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360\562c4dd5\4.1.0.32\ccl90u.dll, 646008, 81c945d25ff22fb0402b658600051ac2 c:\program files\nortoninstaller\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360\562c4dd5\4.1.0.32\engine.dll, 1636392, ab018b47bf7cdd5e2604d54b7bc62a68 c:\program files\nortoninstaller\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360\562c4dd5\4.1.0.32\inststub.exe, 731440, 8f64372df155cf7baf203707bdc7067d c:\program files\nortoninstaller\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360\562c4dd5\4.1.0.32\instui.dll, 1793064, 08abc1497c7e39af0d622f79e69beda2 c:\program files\nortoninstaller\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360\562c4dd5\4.1.0.32\microsoft.vc90.crt\msvcm90.dll, 225280, 78cec510cf7dfdd431618272c69e245b c:\program files\nortoninstaller\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360\562c4dd5\4.1.0.32\microsoft.vc90.crt\msvcp90.dll, 569664, c3fff4eff42061f193fad831b7e8868e c:\program files\nortoninstaller\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360\562c4dd5\4.1.0.32\microsoft.vc90.crt\msvcr90.dll, 653120, 86491617670f6e74dc5c9145aee2d0f4 c:\program files\nortoninstaller\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360\562c4dd5\4.1.0.32\prodcbk.dll, 320880, 8831f3828d716ccaacaa716b303aae78 c:\program files\symantec\s32evnt1.dll, 60808, d2844222b08dfb934b77d49982e96d6f c:\windows\installer\{90120000-006e-0409-0000-0000000ff1ce}\misc.exe, 217864, 00777a08b2893e65f44906d7fd917f2f c:\windows\system32\lame_enc.dll, 126464, efc44719f26a3939d3b5f21a654ffbe6 c:\windows\system32\mcdvd_32.dll, 261632, 63202574fa8440e978f1a8838eea1288 c:\windows\system32\nctaudiocompress2.dll, 1810432, 147b81cccb79aad04eba73541120a3be c:\windows\system32\nctaudiocompress3.dll, 2564096, 5eb4bfb646f4b192a12511e2b563f453 c:\windows\system32\nctaudiofile2.dll, 1986560, b5856dda6e004a565689ed3ed86b033f c:\windows\system32\nctavifile.dll, 294912, 7309012ea6c5ac1c9aab830e38058cc4 c:\windows\system32\nctquicktimefile.dll, 282624, 57a846aafdef799029f75fbbb2c2e675 c:\windows\system32\nctrmfile.dll, 1245184, 8cc99c2b726f504166e583fea6e77223 c:\windows\system32\nctvideocompress.dll, 2260992, 7233c0f36058e0ff2b56f01e81d4d193 c:\windows\system32\nctvideocorem.dll, 991232, a3e74927e9442ff38209dee7e410c837 c:\windows\system32\nctvideocoreu.dll, 106496, 577c2d42949892a63030ee8484d4b756 c:\windows\system32\nctvideofile.dll, 139264, 8d18daaced7bd5ee45e7e21a8da15f7d c:\windows\system32\nctwmvfile.dll, 196608, 629d639430f260528be63097523025e2 c:\windows\system32\rmbin\codecs\atrc.dll, 44544, 66e418d8e24787de80d3b5e24df71d38 c:\windows\system32\rmbin\codecs\colorcvt.dll, 139776, ab98f92e53572bf09a1259cebc81ec3e c:\windows\system32\rmbin\codecs\cook.dll, 38912, 53a0613726597392beb689ec74baf2fb c:\windows\system32\rmbin\codecs\erv2.dll, 186880, 6621a9e9fe2c298db04c097bd953960b c:\windows\system32\rmbin\codecs\erv3.dll, 143872, 1b5eff9f4767b8ad7a81d4b79632436e c:\windows\system32\rmbin\codecs\erv4.dll, 163840, ed6fb42133a444dd62a5ad44abfee0e5 c:\windows\system32\rmbin\codecs\sipr.dll, 57856, ca8a0e1f00c3bc159353b70edae65e22 c:\windows\system32\rmbin\common\encn3260.dll, 186368, 4b5e9dc4677b4c7057a3c3b8346810b1 c:\windows\system32\rmbin\common\remb3260.dll, 173056, bafff3f76d35ef0857e8c517211d0fa7 c:\windows\system32\rmbin\plugins\auth3260.dll, 27136, e5e855c02f0d7a1ae937544c23ed9c38 c:\windows\system32\rmbin\plugins\basc3260.dll, 25088, e60fe6c640acf48c3b0c6c8a92194906 c:\windows\system32\rmbin\plugins\rmwrtr.dll, 119296, 118cfe838c5cc87d89b03e23492ba5c0 c:\windows\system32\rmbin\plugins\rn5a3260.dll, 24064, 44dcc5b4f9859fa205bff94b049fb25e c:\windows\system32\rmbin\plugins\sdpp3260.dll, 33792, fca86c6639c460534b0fe9a63fdf091c c:\windows\system32\rmbin\plugins\smplfsys.dll, 36864, c7c727e6938a8c026c77e12fd9d9e9c7 c:\windows\system32\rmbin\pncrt.dll, 128512, 2abaed9cb979de97edc1727c0617798a c:\windows\system32\rmbin\tools\audiofmtconverter.dll, 29184, 210b0a1b9fd7e724d3aa026cb61d4282 c:\windows\system32\rmbin\tools\audiolimiter.dll, 29184, 476ec9deb383a37a777c8e8bcfd94d8d c:\windows\system32\rmbin\tools\audiometer.dll, 31744, 9008ca16f7e21bf07171910737593b1a c:\windows\system32\rmbin\tools\audioresampler.dll, 206848, 7f835efe735c7baf49a9fa41041bc724 c:\windows\system32\rmbin\tools\avireader.dll, 36864, adab8cb1d1bb1ee28e1430fdacc3f795 c:\windows\system32\rmbin\tools\capture.dll, 121344, c549acc84afe9af4bfd3f9f29d61032c c:\windows\system32\rmbin\tools\dsreader.dll, 79872, a623a8fd80ac8f01c5e1fb0793d88b9f c:\windows\system32\rmbin\tools\encnetbroadcast.dll, 41984, 6f051a0911ce2a9c7fb10c3610f23585 c:\windows\system32\rmbin\tools\encsession.dll, 289792, b001c96a00ea53d69f0e3a704ba269bb c:\windows\system32\rmbin\tools\enlv3260.dll, 20480, c1222a09dd9e3e47e1edc3e375b95d45 c:\windows\system32\rmbin\tools\eventpack.dll, 29696, 522840a6f6abb1de93595160d54607b0 c:\windows\system32\rmbin\tools\log.dll, 76288, f081a88ba46de1a3f4c69cd36ad52c2e c:\windows\system32\rmbin\tools\logobserver.dll, 23552, 4f5f008ec2269309408b31ad68c242f5 c:\windows\system32\rmbin\tools\mediasink.dll, 29696, 0a5d22faa55d3f74dcb09d0794303451 c:\windows\system32\rmbin\tools\movreader.dll, 40448, a81575d962cdca2c3672a9b50100b16e c:\windows\system32\rmbin\tools\qtreader.dll, 36352, 9ae3ab1c64782d77ee6d218f30c4709f c:\windows\system32\rmbin\tools\rbsbroadcast.dll, 150528, 75c1d4bcb966d1ba9b885cc2ca19cac5 c:\windows\system32\rmbin\tools\rmme3260.dll, 215552, c4f6752eb67199b038bfc93cb4079cce c:\windows\system32\rmbin\tools\rmto3260.dll, 160256, c3957489f550f59a28c28613b131ec3e c:\windows\system32\rmbin\tools\rmwriter.dll, 111616, 434e712bddce22e88c3869de680c8842 c:\windows\system32\rmbin\tools\rnaudiocodec.dll, 36352, f5351202192faa5bb0ba6f67419743b9 c:\windows\system32\rmbin\tools\rnaudiointerleaver.dll, 34816, 646562c8b939d3b43691b8c818391d17 c:\windows\system32\rmbin\tools\rnvideocodec.dll, 47616, 63450c708d138438b1fdb0fe4a4a871f c:\windows\system32\rmbin\tools\videocolorconverter.dll, 28160, dcb5b046126b62e4fef9c4a592559960 c:\windows\system32\rmbin\tools\videolumaadj.dll, 26624, ee59dc9d50177e191ea421ff53dc7c99 c:\windows\system32\rmbin\tools\videonoisefilter.dll, 32256, 19ef345a73ee84d470f5863b390da3b7 c:\windows\system32\rmbin\tools\videoprogressive.dll, 32256, 39a8095e50a78f937f3bb3f6e6581670 c:\windows\system32\rmbin\tools\wavreader.dll, 22528, adf91251875286db64cb5115b8c6230a c:\windows\system32\s32evnt1.dll, 60808, d2844222b08dfb934b77d49982e96d6f c:\windows\system32\volumemsprlam.dll, 0, e52e9dea9011c315fa911aa9fd09538f
Hi drishi8, That wasn't MBAM you downloaded. The download links are located as shown in the image below. If you should get a yellow information bar at the top of Internet Explorer when you click on the link, right click it and select "download file". MBAM is free as are all the other tools I recommend. 📎mbamdownload.JPG

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI