This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help - Fake Antivirus

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, please help I have a fave antivirus that keeps popping up. Here is my Hijack this log file, thanks in advance for any guidance. I am running this as admin but the strange thing is my normal family account appears to be the only one with the fake antivirus popping up.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:17:48 PM, on 6/17/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18470)
Boot mode: Normal

Running processes:
c:\PROGRA~2\mcafee.com\agent\mcagent.exe
C:\Program Files (x86)\Windows Media Player\wmpnscfg.exe
C:\Program Files (x86)\Dell Remote Access\ezi_ra.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Greetings Workshop\GWREMIND.EXE
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Dell Support Center\gs_agent\dsc.exe
C:\Users\dhoholik\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~2\mcafee\msk\mskapbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-21-2165948760-776771271-4270439850-1000\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-18\..\Run: [StartUp This] "C:\Program Files (x86)\Laplink\PCmover\LaunchSt.exe" (User '?')
O4 - HKUS\.DEFAULT\..\Run: [StartUp This] "C:\Program Files (x86)\Laplink\PCmover\LaunchSt.exe" (User 'Default user')
O4 - S-1-5-21-2165948760-776771271-4270439850-1000 Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE (User '?')
O4 - S-1-5-18 Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User '?')
O4 - .DEFAULT Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Greetings Workshop Reminders.lnk = C:\Program Files\Greetings Workshop\GWREMIND.EXE
O4 - Global Startup: Dell Remote Access.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {741747F6-83B4-4FB9-A268-8CA4010762C8} (Snapfish Activia2) - http://www2.snapfish.com/SnapfishActivia2.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A1662FB6-39BE-41BB-ACDC-0448FB1B5817} (Photo Upload Plugin Class) - http://images3.pnimedia.com/ProductAssets/…veX_Control.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DEA6994F-3ED5-40BC-B5E3-0FD02411B1B4} (Photo Upload Plugin Class) - http://www.costcophotocenter.com/upload/ac…veX_Control.cab?
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} (Photo Upload Plugin Class) - http://www.costcophotocenter.com/upload/ac…veX_Control.cab?
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\Windows\SysWow64\browseui.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Unknown owner - C:\Windows\system32\AERTSr64.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files (x86)\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxci_device - - C:\Windows\system32\lxcicoms.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~2\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files (x86)\Common Files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\PROGRA~2\COMMON~1\McAfee\McProxy\McProxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~2\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files (x86)\McAfee\MSK\MskSrver.exe
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks - C:\Windows\sminst\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

–
End of file - 12494 bytes
Hello Michigan Czar and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. OTL ncludes all the scan locations of HijackThis and more. It's not only a more comprehensive scan tool, but also offers more powerful removal features.

Vista users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Download and Run OTL
  • Download OTL to your desktop.
  • Right-click on the icon and choose "Run as Administrator". Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\drivers\*.sys /90
    %systemroot%\System32\config\*.sav

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
OTL logfile created on: 6/17/2010 9:11:10 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\dhoholik\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 63.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.11 Gb Total Space | 334.17 Gb Free Space | 57.50% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 6.13 Gb Free Space | 40.87% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOMEPC
Current User Name: dhoholik
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/06/17 21:09:41 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\dhoholik\Desktop\OTL.exe
PRC - [2010/06/10 06:58:32 | 000,865,832 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/10/29 07:54:44 | 001,218,008 | —- | M] (McAfee, Inc.) – c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
PRC - [2009/10/27 12:19:46 | 000,895,696 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee\MPF\MpfSrv.exe
PRC - [2009/09/16 09:28:38 | 000,606,736 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/07/08 14:48:48 | 000,026,640 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee\MSK\msksrver.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/07/07 19:10:02 | 002,482,848 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2009/07/07 10:23:00 | 001,779,952 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
PRC - [2009/06/04 18:41:22 | 000,451,904 | —- | M] () – C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
PRC - [2009/04/02 12:47:04 | 000,234,888 | —- | M] () – C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe
PRC - [2009/04/02 12:47:02 | 000,464,264 | —- | M] () – C:\Program Files (x86)\AskBarDis\bar\bin\AskService.exe
PRC - [2009/02/23 09:48:06 | 000,632,048 | —- | M] (SoftThinks) – C:\Windows\sminst\SftService.exe
PRC - [2009/02/04 21:26:38 | 000,128,232 | —- | M] (CyberLink Corp.) – C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2008/12/18 13:05:28 | 000,155,648 | —- | M] (Stardock Corporation) – C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/12/16 21:14:42 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/12/16 21:14:42 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/12/04 16:03:00 | 000,226,640 | —- | M] (Microsoft Corp.) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2008/01/20 22:50:38 | 000,299,520 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Internet Explorer\ieuser.exe
PRC - [2006/10/18 21:05:26 | 000,204,288 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Media Player\wmpnscfg.exe
PRC - [1997/09/04 01:00:00 | 000,050,688 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Greetings Workshop\GWREMIND.EXE


========== Modules (SafeList) ==========

MOD - [2010/06/17 21:09:41 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\dhoholik\Desktop\OTL.exe
MOD - [2008/01/20 22:50:03 | 000,450,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\comdlg32.dll
MOD - [2008/01/20 22:50:01 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2008/01/20 22:48:06 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/09/16 11:23:32 | 000,696,848 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV:64bit: - [2009/09/16 10:15:32 | 000,155,456 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\McAfee\VirusScan\Mcshield.exe – (McShield)
SRV:64bit: - [2009/02/24 03:49:22 | 000,901,120 | —- | M] () [Auto | Running] – C:\Windows\SysNative\Ati2evxx.exe – (Ati External Event Utility)
SRV:64bit: - [2008/12/18 13:05:28 | 000,155,648 | —- | M] (Stardock Corporation) [Auto | Running] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV:64bit: - [2008/07/18 08:42:16 | 000,086,016 | —- | M] () [Auto | Running] – C:\Windows\SysNative\AERTSr64.exe – (AERTFilters)
SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2006/05/15 09:24:50 | 000,452,608 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysNative\lxcicoms.exe – (lxci_device)
SRV - [2010/06/10 06:58:32 | 000,865,832 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe – (mcmscsvc)
SRV - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/10/27 12:19:46 | 000,895,696 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files (x86)\McAfee\MPF\MpfSrv.exe – (MpfService)
SRV - [2009/09/16 09:28:38 | 000,606,736 | —- | M] (McAfee, Inc.) [On_Demand | Running] – C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe – (McSysmon)
SRV - [2009/07/08 14:48:48 | 000,026,640 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files (x86)\McAfee\MSK\MskSrver.exe – (MSK80Service)
SRV - [2009/07/08 11:54:34 | 000,359,952 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe – (McProxy)
SRV - [2009/07/07 19:10:02 | 002,482,848 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe – (McNASvc)
SRV - [2009/06/04 18:41:22 | 000,451,904 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe – (FlipShare Service)
SRV - [2009/06/04 09:58:47 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2009/04/02 12:47:04 | 000,234,888 | —- | M] () [Auto | Running] – C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe – (ASKUpgrade)
SRV - [2009/04/02 12:47:02 | 000,464,264 | —- | M] () [Auto | Running] – C:\Program Files (x86)\AskBarDis\bar\bin\AskService.exe – (ASKService)
SRV - [2009/02/23 09:48:06 | 000,632,048 | —- | M] (SoftThinks) [Auto | Running] – C:\Windows\sminst\sftservice.EXE – (SftService)
SRV - [2009/01/05 17:19:10 | 000,824,560 | —- | M] (Dell Inc.) [Auto | Stopped] – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe – (hnmsvc)
SRV - [2008/12/16 21:14:42 | 000,206,064 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter)
SRV - [2008/12/04 16:03:00 | 000,226,640 | —- | M] (Microsoft Corp.) [Auto | Running] – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2008/07/27 14:01:49 | 000,093,184 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64)
SRV - [2007/02/01 22:13:46 | 000,537,520 | —- | M] ( ) [On_Demand | Stopped] – C:\Windows\SysWow64\lxcicoms.exe – (lxci_device)
SRV - [2006/11/03 20:20:06 | 000,271,128 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2006/11/02 02:35:15 | 000,060,994 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysWOW64\wbem\vds.mof – (vds)
SRV - [2005/09/23 07:28:32 | 000,029,896 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state)
SRV - [2002/12/17 17:26:22 | 007,520,337 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe – (MSSQL$SONY_MEDIAMGR)
SRV - [2002/12/17 17:23:30 | 000,311,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE – (SQLAgent$SONY_MEDIAMGR)
SRV - [2002/12/17 17:23:30 | 000,066,112 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe – (MSSQLServerADHelper)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/04/16 08:33:36 | 000,050,176 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2009/09/16 10:22:40 | 000,308,296 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\drivers\mfehidk.sys – (mfehidk)
DRV:64bit: - [2009/09/16 10:22:40 | 000,102,472 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfeavfk.sys – (mfeavfk)
DRV:64bit: - [2009/09/16 10:22:40 | 000,049,480 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfesmfk.sys – (mfesmfk)
DRV:64bit: - [2009/09/16 10:15:38 | 000,040,904 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mferkdk.sys – (mferkdk)
DRV:64bit: - [2009/07/16 12:32:26 | 000,176,144 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\Drivers\Mpfp.sys – (MPFP)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/02/24 03:49:28 | 004,598,784 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\atikmdag.sys – (R300)
DRV:64bit: - [2009/02/24 03:49:28 | 004,598,784 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/02/23 05:47:04 | 000,126,464 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV:64bit: - [2009/02/23 05:46:28 | 010,275,296 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\igdkmd64.sys – (igfx)
DRV:64bit: - [2008/12/19 22:24:48 | 000,041,032 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mfebopk.sys – (mfebopk)
DRV:64bit: - [2008/07/21 07:18:30 | 000,026,624 | —- | M] () [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\RtNdPt60.sys – (RtNdPt60)
DRV:64bit: - [2008/07/15 08:14:10 | 000,395,288 | —- | M] () [Kernel | Disabled | Stopped] – C:\Windows\SysNative\drivers\iastor.sys – (iaStor)
DRV:64bit: - [2008/07/10 07:28:50 | 000,170,496 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\Rtlh64.sys – (RTL8169)
DRV:64bit: - [2008/06/18 16:48:54 | 000,029,184 | —- | M] () [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\packet.sys – (Packet)
DRV:64bit: - [2008/01/20 22:50:35 | 000,009,728 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\umpass.sys – (UMPass)
DRV:64bit: - [2008/01/20 22:47:28 | 000,048,768 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\avc.sys – (Avc)
DRV:64bit: - [2008/01/20 22:47:28 | 000,046,080 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\wpdusb.sys – (WpdUsb)
DRV:64bit: - [2008/01/20 22:46:59 | 000,036,864 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\WinUSB.SYS – (winusb)
DRV:64bit: - [2008/01/20 22:46:57 | 000,058,496 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\61883.sys – (61883)
DRV:64bit: - [2008/01/20 22:46:55 | 000,317,952 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\e1e6032e.sys – (e1express) Intel®
DRV:64bit: - [2008/01/20 22:46:53 | 000,061,568 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\msdv.sys – (MSDV)
DRV:64bit: - [2007/11/14 03:00:00 | 000,053,488 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2006/11/02 01:28:10 | 000,273,920 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HdAudio.sys – (HdAudAddService)
DRV - [2008/11/04 19:16:40 | 000,028,152 | —- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Dell Support Center\HWDiag\bin\pcd5srvc_x64.pkms – (PCD5SRVC{048DBD20-445E8C82-05040104})
DRV - [2008/01/20 22:49:57 | 000,016,384 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\winusb.dll – (winusb)
DRV - [2006/09/18 17:36:40 | 000,003,066 | —- | M] () [Kernel | System | Running] – C:\Windows\SysWOW64\wbem\tcpip.mof – (Tcpip)
DRV - [2006/09/18 17:35:23 | 000,001,088 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\wbem\mpsdrv.mof – (mpsdrv)
DRV - [2002/09/03 13:09:27 | 000,009,344 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\vga.dll – (vga)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.2
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files (x86)\Real\RealPlayer\browserrecord [2009/06/13 20:56:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/05/07 17:34:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/06/07 15:08:53 | 000,000,000 | —D | M]

[2009/08/26 09:46:17 | 000,000,000 | —D | M] – C:\Users\dhoholik\AppData\Roaming\Mozilla\Extensions
[2010/03/23 21:29:44 | 000,000,000 | —D | M] – C:\Users\dhoholik\AppData\Roaming\Mozilla\Firefox\Profiles\pyq8y6hz.default\extensions
[2009/08/26 09:47:05 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\dhoholik\AppData\Roaming\Mozilla\Firefox\Profiles\pyq8y6hz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/26 09:47:05 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\dhoholik\AppData\Roaming\Mozilla\Firefox\Profiles\pyq8y6hz.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/10/09 21:33:16 | 000,000,000 | —D | M] (No name found) – C:\Users\dhoholik\AppData\Roaming\Mozilla\Firefox\Profiles\pyq8y6hz.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/08/09 23:13:46 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2008/06/18 03:43:04 | 000,086,016 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll

O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho64.dll ()
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] File not found
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [WPCUMI] C:\Windows\SysNative\WpcUmi.exe ()
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\dhoholik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Greetings Workshop Reminders.lnk = C:\Program Files (x86)\Greetings Workshop\GWREMIND.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysNative\wpclsp.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {741747F6-83B4-4FB9-A268-8CA4010762C8} http://www2.snapfish.com/SnapfishActivia2.cab (Snapfish Activia2)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {A1662FB6-39BE-41BB-ACDC-0448FB1B5817} http://images3.pnimedia.com/ProductAssets/…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DEA6994F-3ED5-40BC-B5E3-0FD02411B1B4} http://www.costcophotocenter.com/upload/ac…veX_Control.cab? (Photo Upload Plugin Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} http://www.costcophotocenter.com/upload/ac…veX_Control.cab? (Photo Upload Plugin Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18:64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll ()
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files (x86)\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/30 16:01:00 | 000,000,053 | -HS- | M] () - D:\AUTORUN.INF – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2008/01/20 23:06:38 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll ()
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll ()
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2009/06/13 21:08:20 | 000,000,000 | —D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2010/06/17 21:09:31 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Users\dhoholik\Desktop\OTL.exe
[2010/06/17 14:12:03 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\dhoholik\Desktop\HiJackThis.exe
[2010/06/17 14:03:45 | 000,000,000 | —D | C] – C:\Users\dhoholik\AppData\Roaming\PeerNetworking
[2010/06/17 14:02:44 | 000,000,000 | —D | C] – C:\Users\dhoholik\AppData\Roaming\DivX
[2010/06/17 14:02:19 | 000,000,000 | —D | C] – C:\Users\dhoholik\AppData\Roaming\Media Player Classic
[2010/06/09 22:30:27 | 000,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2010/06/09 22:30:26 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2010/06/09 22:30:23 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\asycfilt.dll
[2010/06/09 22:30:06 | 000,833,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wininet.dll
[2010/06/09 22:30:06 | 000,146,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2010/06/09 22:30:05 | 000,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2010/06/09 22:30:04 | 000,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstime.dll
[2010/06/09 22:30:04 | 000,476,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2010/06/09 22:30:04 | 000,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2010/06/09 22:30:04 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2010/06/09 22:30:04 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iedkcs32.dll
[2010/06/09 22:30:04 | 000,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2010/06/09 22:30:04 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010/06/09 22:30:04 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieencode.dll
[2010/06/09 22:30:04 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2010/06/09 22:30:03 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jsproxy.dll
[2010/06/09 22:29:28 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2009/09/29 19:31:28 | 000,643,072 | —- | C] ( ) – C:\Windows\SysWow64\lxcipmui.dll
[2009/09/29 19:31:28 | 000,413,696 | —- | C] ( ) – C:\Windows\SysWow64\lxciinpa.dll
[2009/09/29 19:31:28 | 000,397,312 | —- | C] ( ) – C:\Windows\SysWow64\lxciiesc.dll
[2009/09/29 19:31:27 | 001,224,704 | —- | C] ( ) – C:\Windows\SysWow64\lxciserv.dll
[2009/09/29 19:31:27 | 000,991,232 | —- | C] ( ) – C:\Windows\SysWow64\lxciusb1.dll
[2009/09/29 19:31:27 | 000,696,320 | —- | C] ( ) – C:\Windows\SysWow64\lxcihbn3.dll
[2009/09/29 19:31:27 | 000,684,032 | —- | C] ( ) – C:\Windows\SysWow64\lxcicomc.dll
[2009/09/29 19:31:27 | 000,585,728 | —- | C] ( ) – C:\Windows\SysWow64\lxcilmpm.dll
[2009/09/29 19:31:27 | 000,421,888 | —- | C] ( ) – C:\Windows\SysWow64\lxcicomm.dll
[2009/09/29 19:31:27 | 000,163,840 | —- | C] ( ) – C:\Windows\SysWow64\lxciprox.dll
[2009/09/29 19:31:27 | 000,094,208 | —- | C] ( ) – C:\Windows\SysWow64\lxcipplc.dll
[2007/04/09 13:32:58 | 000,065,536 | —- | C] ( ) – C:\Windows\SysWow64\a3d.dll

========== Files - Modified Within 30 Days ==========

[2010/06/17 21:11:13 | 007,340,032 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT
[2010/06/17 21:09:41 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\dhoholik\Desktop\OTL.exe
[2010/06/17 21:01:59 | 000,000,944 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2165948760-776771271-4270439850-1001UA.job
[2010/06/17 20:01:18 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/17 20:01:18 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/17 14:16:38 | 000,000,288 | —- | M] () – C:\Windows\tasks\RtlNICDiagVistaStart.job
[2010/06/17 14:15:43 | 000,524,288 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TMContainer00000000000000000001.regtrans-ms
[2010/06/17 14:15:43 | 000,065,536 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TM.blf
[2010/06/17 14:15:40 | 004,983,258 | -H– | M] () – C:\Users\dhoholik\AppData\Local\IconCache.db
[2010/06/17 14:12:11 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\dhoholik\Desktop\HiJackThis.exe
[2010/06/17 14:07:15 | 000,691,354 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/17 14:07:15 | 000,595,446 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/17 14:07:15 | 000,101,144 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/17 14:04:53 | 000,015,013 | —- | M] () – C:\Windows\SysNative\Config.MPF
[2010/06/17 14:03:45 | 000,023,909 | —- | M] () – C:\Users\dhoholik\AppData\Roaming\UserTile.png
[2010/06/17 14:01:27 | 002,851,880 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/06/17 14:01:18 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/17 14:01:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/17 14:01:09 | 4294,107,136 | -HS- | M] () – C:\hiberfil.sys
[2010/06/17 09:02:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2165948760-776771271-4270439850-1001Core.job
[2010/06/16 22:35:02 | 000,000,436 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{65AA9B57-87FA-4F6E-8073-93F0C0369054}.job
[2010/06/16 22:15:39 | 000,000,424 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{9140BB2F-11EB-45E4-AB6F-28AD9A8FDB29}.job
[2010/06/13 19:50:23 | 000,000,632 | RHS- | M] () – C:\Users\dhoholik\ntuser.pol
[2010/06/09 12:33:19 | 000,000,732 | —- | M] () – C:\Users\dhoholik\AppData\Local\d3d9caps64.dat
[2010/06/08 22:15:01 | 000,000,850 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/07 06:50:20 | 000,524,288 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TMContainer00000000000000000002.regtrans-ms
[2010/06/06 23:19:18 | 000,524,288 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT{d163e63a-5f44-11df-8ef7-0021705c34ea}.TMContainer00000000000000000001.regtrans-ms
[2010/06/06 23:19:18 | 000,065,536 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT{d163e63a-5f44-11df-8ef7-0021705c34ea}.TM.blf
[2010/05/26 12:53:52 | 000,048,128 | —- | M] () – C:\Windows\SysNative\atmlib.dll
[2010/05/26 12:16:50 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2010/05/26 10:56:53 | 000,366,080 | —- | M] () – C:\Windows\SysNative\atmfd.dll
[2010/05/26 10:25:15 | 000,289,792 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll

========== Files Created - No Company Name ==========

[2010/06/17 14:03:45 | 000,023,909 | —- | C] () – C:\Users\dhoholik\AppData\Roaming\UserTile.png
[2010/06/17 14:01:09 | 4294,107,136 | -HS- | C] () – C:\hiberfil.sys
[2010/06/09 22:30:27 | 000,366,080 | —- | C] () – C:\Windows\SysNative\atmfd.dll
[2010/06/09 22:30:27 | 000,048,128 | —- | C] () – C:\Windows\SysNative\atmlib.dll
[2010/06/09 22:30:23 | 000,084,480 | —- | C] () – C:\Windows\SysNative\asycfilt.dll
[2010/06/09 22:30:17 | 002,749,952 | —- | C] () – C:\Windows\SysNative\win32k.sys
[2010/06/09 22:30:08 | 005,690,368 | —- | C] () – C:\Windows\SysNative\mshtml.dll
[2010/06/09 22:30:06 | 007,006,208 | —- | C] () – C:\Windows\SysNative\ieframe.dll
[2010/06/09 22:30:06 | 001,426,944 | —- | C] () – C:\Windows\SysNative\urlmon.dll
[2010/06/09 22:30:06 | 001,032,704 | —- | C] () – C:\Windows\SysNative\wininet.dll
[2010/06/09 22:30:06 | 000,208,896 | —- | C] () – C:\Windows\SysNative\occache.dll
[2010/06/09 22:30:05 | 000,758,784 | —- | C] () – C:\Windows\SysNative\mshtmled.dll
[2010/06/09 22:30:05 | 000,422,400 | —- | C] () – C:\Windows\SysNative\ieapfltr.dll
[2010/06/09 22:30:04 | 001,129,984 | —- | C] () – C:\Windows\SysNative\mstime.dll
[2010/06/09 22:30:04 | 000,580,608 | —- | C] () – C:\Windows\SysNative\msfeeds.dll
[2010/06/09 22:30:04 | 000,485,376 | —- | C] () – C:\Windows\SysNative\html.iec
[2010/06/09 22:30:04 | 000,480,256 | —- | C] () – C:\Windows\SysNative\iedkcs32.dll
[2010/06/09 22:30:04 | 000,375,296 | —- | C] () – C:\Windows\SysNative\iertutil.dll
[2010/06/09 22:30:04 | 000,267,776 | —- | C] () – C:\Windows\SysNative\ieaksie.dll
[2010/06/09 22:30:04 | 000,249,856 | —- | C] () – C:\Windows\SysNative\iepeers.dll
[2010/06/09 22:30:04 | 000,086,528 | —- | C] () – C:\Windows\SysNative\ieencode.dll
[2010/06/09 22:30:04 | 000,032,768 | —- | C] () – C:\Windows\SysNative\ieUnatt.exe
[2010/06/09 22:30:03 | 001,383,424 | —- | C] () – C:\Windows\SysNative\mshtml.tlb
[2010/06/09 22:30:03 | 000,032,256 | —- | C] () – C:\Windows\SysNative\jsproxy.dll
[2010/06/09 22:29:28 | 001,570,816 | —- | C] () – C:\Windows\SysNative\quartz.dll
[2010/06/07 06:50:19 | 000,524,288 | -HS- | C] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TMContainer00000000000000000002.regtrans-ms
[2010/06/07 06:50:19 | 000,524,288 | -HS- | C] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TMContainer00000000000000000001.regtrans-ms
[2010/06/07 06:50:19 | 000,065,536 | -HS- | C] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TM.blf
[2010/05/25 13:54:01 | 000,002,048 | —- | C] () – C:\Windows\SysNative\tzres.dll
[2009/10/06 20:49:51 | 000,164,352 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2009/10/06 20:49:49 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2009/10/06 20:49:49 | 000,755,027 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2009/10/06 20:49:49 | 000,159,839 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2009/10/06 20:49:47 | 000,007,680 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2009/10/06 20:49:47 | 000,000,547 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll.manifest
[2009/09/29 19:31:28 | 000,385,024 | —- | C] () – C:\Windows\SysWow64\lxcicomx.dll
[2009/09/29 19:31:28 | 000,274,432 | —- | C] () – C:\Windows\SysWow64\lxciinst.dll
[2009/08/04 21:17:34 | 000,129,024 | —- | C] () – C:\Windows\SysWow64\AVERM.dll
[2009/08/04 21:17:34 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\AVEQT.dll
[2009/06/04 10:03:34 | 000,126,976 | —- | C] () – C:\Windows\SysWow64\STWmiM.dll
[2009/06/04 10:03:34 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\STShellVC6.dll
[2009/06/04 10:03:34 | 000,090,112 | —- | C] () – C:\Windows\SysWow64\wnaspi32.dll
[2009/06/04 10:03:34 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\zlib1.dll
[2009/06/04 10:03:34 | 000,066,048 | —- | C] () – C:\Windows\SysWow64\STWiz.dll
[2009/06/04 10:03:33 | 000,385,024 | —- | C] () – C:\Windows\SysWow64\STODD.dll
[2009/06/04 10:03:33 | 000,380,928 | —- | C] () – C:\Windows\SysWow64\STODDRD.dll
[2009/06/04 10:03:33 | 000,266,240 | —- | C] () – C:\Windows\SysWow64\STODDIM.dll
[2009/06/04 10:03:33 | 000,253,952 | —- | C] () – C:\Windows\SysWow64\STODDSC.dll
[2009/06/04 10:03:33 | 000,229,376 | —- | C] () – C:\Windows\SysWow64\STFiles.dll
[2009/06/04 10:03:33 | 000,122,880 | —- | C] () – C:\Windows\SysWow64\STLog.dll
[2009/06/04 10:03:33 | 000,115,712 | —- | C] () – C:\Windows\SysWow64\STNLS.dll
[2009/06/04 10:03:33 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\STPE.dll
[2009/06/04 10:03:33 | 000,098,304 | —- | C] () – C:\Windows\SysWow64\STFileMonitor.dll
[2009/06/04 10:03:33 | 000,094,208 | —- | C] () – C:\Windows\SysWow64\STMsXml.dll
[2009/06/04 10:03:33 | 000,077,824 | —- | C] () – C:\Windows\SysWow64\STLangXml.dll
[2009/06/04 10:03:33 | 000,069,632 | —- | C] () – C:\Windows\SysWow64\STRegistry.dll
[2009/06/04 10:03:33 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\STProcess.dll
[2009/06/04 10:03:32 | 001,118,208 | —- | C] () – C:\Windows\SysWow64\libxml2.dll
[2009/06/04 10:03:32 | 000,471,040 | —- | C] () – C:\Windows\SysWow64\PSTImage.dll
[2009/06/04 10:03:32 | 000,118,784 | —- | C] () – C:\Windows\SysWow64\STCrypto.dll
[2009/06/04 10:03:32 | 000,110,592 | —- | C] () – C:\Windows\SysWow64\PSTVdsDisk.dll
[2009/06/04 10:03:32 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\STCoreXml.dll
[2008/12/11 11:05:42 | 000,000,197 | —- | C] () – C:\Windows\SysWow64\MRT.INI
[2008/07/26 20:30:19 | 000,000,138 | —- | C] () – C:\Windows\cdplayer.ini
[2008/02/19 02:33:34 | 000,446,352 | —- | C] () – C:\Windows\SysWow64\OpenQuicktimeLib.dll
[2008/01/20 22:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 22:49:49 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008/01/19 19:33:36 | 000,000,481 | —- | C] () – C:\Windows\hegames.ini
[2008/01/17 12:51:18 | 000,000,000 | —- | C] () – C:\Windows\SETUP32.INI
[2007/12/23 12:30:52 | 000,000,231 | —- | C] () – C:\Windows\AC3API.INI
[2007/12/23 12:30:52 | 000,000,000 | —- | C] () – C:\Windows\SBWIN.INI
[2007/12/23 12:30:06 | 000,066,807 | —- | C] () – C:\Windows\SysWow64\Aud2_Del.ini
[2007/12/23 12:29:57 | 000,005,515 | —- | C] () – C:\Windows\SysWow64\ENSDEF.INI
[2007/12/23 12:29:57 | 000,000,180 | —- | C] () – C:\Windows\SysWow64\kill.ini
[2007/12/21 17:33:28 | 000,000,017 | —- | C] () – C:\Windows\MovingPicture.ini
[2007/12/19 22:42:38 | 000,000,523 | —- | C] () – C:\Windows\ATICIM.INI
[2007/12/19 22:39:14 | 000,012,288 | —- | C] () – C:\Windows\SysWow64\e100bmsg.dll
[2007/12/19 21:42:58 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2007/12/19 13:27:02 | 000,013,223 | —- | C] () – C:\Windows\SysWow64\tslabels.ini
[2007/12/19 13:27:01 | 000,001,931 | —- | C] () – C:\Windows\SysWow64\msdtcprf.ini
[2007/12/19 04:56:56 | 000,497,600 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2007/04/12 09:10:28 | 000,105,728 | —- | C] () – C:\Windows\SysWow64\APOMgrH.dll
[2007/04/09 13:55:14 | 000,097,785 | —- | C] () – C:\Windows\SysWow64\instwdm.ini
[2007/04/09 13:55:14 | 000,000,030 | —- | C] () – C:\Windows\SysWow64\ctzapxx.ini
[2007/04/09 13:33:50 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\CTBurst.dll
[2005/06/16 11:17:16 | 000,071,680 | —- | C] () – C:\Windows\SysWow64\ctmmactl.dll
[2002/09/03 13:12:01 | 000,013,312 | —- | C] () – C:\Windows\SysWow64\win87em.dll
[2002/09/03 13:07:26 | 000,015,360 | —- | C] () – C:\Windows\SysWow64\tsd32.dll
[2002/09/03 12:56:51 | 000,012,082 | —- | C] () – C:\Windows\SysWow64\rsvp.ini
[2002/09/03 12:54:43 | 000,003,458 | —- | C] () – C:\Windows\SysWow64\rasctrs.ini
[2002/09/03 12:53:06 | 000,006,877 | —- | C] () – C:\Windows\SysWow64\pschdprf.ini
[2002/09/03 12:52:57 | 000,000,343 | —- | C] () – C:\Windows\SysWow64\prodspec.ini
[2002/09/03 12:52:06 | 000,002,732 | —- | C] () – C:\Windows\SysWow64\perfwci.ini
[2002/09/03 12:52:00 | 000,001,152 | —- | C] () – C:\Windows\SysWow64\perffilt.ini
[2002/09/03 12:51:55 | 000,002,891 | —- | C] () – C:\Windows\SysWow64\perfci.ini
[2002/09/03 12:50:09 | 000,034,560 | —- | C] () – C:\Windows\SysWow64\ntio804.sys
[2002/09/03 12:50:08 | 000,035,424 | —- | C] () – C:\Windows\SysWow64\ntio412.sys
[2002/09/03 12:50:07 | 000,035,648 | —- | C] () – C:\Windows\SysWow64\ntio411.sys
[2002/09/03 12:50:07 | 000,034,560 | —- | C] () – C:\Windows\SysWow64\ntio404.sys
[2002/09/03 12:50:06 | 000,033,840 | —- | C] () – C:\Windows\SysWow64\ntio.sys
[2002/09/03 12:50:01 | 000,029,146 | —- | C] () – C:\Windows\SysWow64\ntdos804.sys
[2002/09/03 12:50:00 | 000,029,370 | —- | C] () – C:\Windows\SysWow64\ntdos411.sys
[2002/09/03 12:50:00 | 000,029,274 | —- | C] () – C:\Windows\SysWow64\ntdos412.sys
[2002/09/03 12:49:59 | 000,029,146 | —- | C] () – C:\Windows\SysWow64\ntdos404.sys
[2002/09/03 12:49:59 | 000,027,866 | —- | C] () – C:\Windows\SysWow64\ntdos.sys
[2002/09/03 12:44:28 | 000,094,282 | —- | C] () – C:\Windows\SysWow64\msencode.dll
[2002/09/03 12:44:27 | 000,004,126 | —- | C] () – C:\Windows\SysWow64\msdxmlc.dll
[2002/09/03 12:39:11 | 000,042,537 | —- | C] () – C:\Windows\SysWow64\keyboard.sys
[2002/09/03 12:39:08 | 000,042,809 | —- | C] () – C:\Windows\SysWow64\key01.sys
[2002/09/03 12:34:10 | 000,004,768 | —- | C] () – C:\Windows\SysWow64\himem.sys
[2002/09/03 12:32:37 | 001,015,477 | —- | C] () – C:\Windows\SysWow64\esentprf.ini
[2002/09/03 12:29:31 | 000,027,097 | —- | C] () – C:\Windows\SysWow64\country.sys
[2002/09/03 12:27:19 | 000,009,029 | —- | C] () – C:\Windows\SysWow64\ansi.sys
[2001/08/17 18:36:28 | 000,157,696 | —- | C] () – C:\Windows\SysWow64\paqsp.dll
[1997/11/17 18:13:16 | 000,010,240 | —- | C] () – C:\Windows\SysWow64\vidx16.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 02:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\Windows\SysWOW64\ReinstallBackups\0004\DriverFiles\i386\AGP440.SYS
[2004/08/04 02:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\Windows\SysWOW64\ReinstallBackups\0004\DriverFiles\i386\AGP440.SYS
[2008/01/20 22:46:51 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008/01/20 22:46:51 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/01/20 22:46:50 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009/06/04 13:03:16 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=5EB9EF6EEC5D873E94992095A1719BF6 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.22134_none_39c3f1ccf31998cb\atapi.sys
[2009/04/11 03:15:00 | 000,020,952 | —- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 – C:\Windows\SoftwareDistribution\Download\d15e0adcf011f7a00bde2023e8b74a00\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
[2009/06/04 13:03:16 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=F988BB0690CD660318037908E9B8DBF7 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18034_none_393a5501d9fbf901\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 07:16:48 | 000,014,848 | —- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\Windows\SysWOW64\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\Windows\SysWOW64\eventlog.dll

< MD5 for: IASTOR.SYS >
[2008/07/15 08:14:10 | 000,395,288 | —- | M] (Intel Corporation) MD5=07FB761600EFF44AF02C35B8B57E5863 – C:\Drivers\storage\R191912\IaStor.sys

< MD5 for: IASTORV.SYS >
[2008/01/20 22:46:59 | 000,290,872 | —- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2008/01/20 22:51:03 | 000,716,800 | —- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SoftwareDistribution\Download\d15e0adcf011f7a00bde2023e8b74a00\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009/04/11 03:11:16 | 000,717,312 | —- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB – C:\Windows\SoftwareDistribution\Download\d15e0adcf011f7a00bde2023e8b74a00\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008/01/20 22:48:28 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\SysWOW64\netlogon.dll
[2008/01/20 22:48:28 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\SysWOW64\netlogon.dll
[2008/01/20 22:48:28 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2008/01/20 22:46:54 | 000,054,328 | —- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/20 22:50:28 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\SysWOW64\scecli.dll
[2008/01/20 22:50:28 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\SysWOW64\scecli.dll
[2008/01/20 22:50:28 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008/01/20 22:49:49 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SoftwareDistribution\Download\d15e0adcf011f7a00bde2023e8b74a00\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/11 03:11:23 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B – C:\Windows\SoftwareDistribution\Download\d15e0adcf011f7a00bde2023e8b74a00\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWOW64\drivers\mbamswissarmy.sys

< %systemroot%\System32\config\*.sav >

========== Alternate Data Streams ==========

@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:5D432CE3
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:888AFB86
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:7E95B6FD
< End of report >

OTL Extras logfile created on: 6/17/2010 9:11:10 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\dhoholik\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 63.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.11 Gb Total Space | 334.17 Gb Free Space | 57.50% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 6.13 Gb Free Space | 40.87% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOMEPC
Current User Name: dhoholik
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l ()
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"FirewallDisableNotify" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{092CB153-90F4-4830-9649-09833F569E53}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{14A360C7-561B-4ABA-A6A9-E17458B25220}" = lport=10244 | protocol=6 | dir=in | app=system |
"{50C9F2B5-7A36-4693-B200-E286DB1ECEC4}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{581AE23F-D4FE-4099-B8F5-520C612B29B8}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{5A7A05B9-7AB1-46F8-A1B6-AC7E0922CCD5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{69C5CF4E-E996-4A0F-85E4-1F5C75E6BC8E}" = rport=10244 | protocol=6 | dir=out | app=system |
"{73D88AD2-7811-4A7D-AE5E-1806016E7AC0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8E953D14-0CFC-43D0-97B3-8B4FD0ED7BA6}" = lport=3390 | protocol=6 | dir=in | app=system |
"{9192ACA8-2349-4430-8C0A-7F99CE9EAC85}" = lport=10244 | protocol=6 | dir=in | app=system |
"{A4FBB121-C782-43C1-9C8C-8DD038BC4EA2}" = lport=3390 | protocol=6 | dir=in | app=system |
"{AC284B4C-E9B1-4052-B81C-06C530293504}" = lport=2869 | protocol=6 | dir=in | app=system |
"{AEA5EC86-D6D7-44D5-9228-006810F78267}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B007B773-51FF-4F65-82EE-F39199CA2ABF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C0F1A5D3-D55C-45B7-8695-001F6B27A6A0}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C1C42405-EAA7-4092-B140-1733871741A2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C4A81B6A-3C1A-470E-BF31-76F40CF927D6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C5F1C2B1-9188-4F43-8F8C-2DD162B00E1B}" = rport=10244 | protocol=6 | dir=out | app=system |
"{D167D677-F304-48B8-8511-D75415EAAD88}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E4504A30-3501-496C-8A58-E16A0B0E763C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E6272A5F-47EC-4573-80C5-090123E006EC}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E81AF518-4ED5-4355-A71F-4A30FD51C18F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EE7BAFAD-D949-437A-A3ED-E950C56F23E3}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{F5AD24F4-4913-4DB3-9ACB-B1570FAF419D}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{FF758897-15D5-47BD-B7AC-B38F24CC7058}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01013E00-760F-4CB8-8D33-E518E2169E12}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{03EC05E4-A0B4-46DB-ACB7-3C077F5F4ACF}" = protocol=6 | dir=in | app=c:\windows\syswow64\lxcicoms.exe |
"{20947C28-778E-4643-BEAF-6A6C431FDEA5}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{2B83A2A4-2D6B-4087-8EB5-A7EBB90F429A}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{3D8AE12B-5E67-4B41-BE38-6AFC15BD8630}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{3E49AACD-FFB5-414F-B56E-F27D6DF477FD}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{43EE62F1-5BEB-4DBF-8965-15E36F1A9632}" = protocol=6 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"{449518AC-0D64-4D33-BB85-6DF5EB5DBBBB}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{47284D4E-9EB5-40DA-866C-A01CB671D0F5}" = protocol=17 | dir=in | app=c:\windows\syswow64\lxcicoms.exe |
"{4E22E950-CB42-40A6-9F55-FD576B64CEF5}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{537094CD-245A-4D40-86D3-C4481F9E015C}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{56719402-2CFD-4103-9B05-F0AEA0B96381}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{59F39CD2-E02F-4514-9BB3-21F0E8C86AAA}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{69D30DC3-1552-40A7-AE24-47A798B9753D}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{6A62F2A2-8106-487C-A5EA-E56F58771A7B}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{6AB5F024-1742-4F7D-951E-FD170673366C}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{77E1AC18-B949-4291-AB68-9A9707885D80}" = protocol=17 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"{7D928E44-2D71-44E7-8CE3-101131353627}" = protocol=17 | dir=in | app=c:\program files (x86)\dell remote access\ezi_ra.exe |
"{7E4C3C2E-4604-409B-AFF6-7C0622376DEA}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent.exe |
"{818BA54D-44B7-4D30-A7AC-652B984FDF5B}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\dell\vlc\vlc.exe |
"{8D72708C-852E-4960-A5CD-9E28C9BED2C8}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\dell\advanced networking service\hnm_svc.exe |
"{9596F6BE-FDDF-475A-86ED-4893E21D2AF6}" = dir=in | app=c:\program files (x86)\common files\mcafee\mna\mcnasvc.exe |
"{9698ED76-36A4-4173-8901-D516B3711FCE}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{AA6F6B52-D750-4115-B5E3-2B6121F3CAEB}" = protocol=6 | dir=in | app=c:\program files (x86)\dell remote access\ezi_ra.exe |
"{AD282CD9-D897-4521-8D6A-754DDF63DFE0}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B8081BCD-60A1-4B2B-88B9-433476982051}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{B9152BC4-330A-45F3-8213-8E71A5100D56}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{C3D70AE7-53F5-4875-963D-808CC4B17C38}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{C73B08BB-BA8D-4953-87CE-EEFDBF27497D}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\dell\vlc\vlc.exe |
"{CCCDE053-F9AF-4127-AB22-E72B5F53C907}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{CCF67D29-91A5-44AF-8375-67DDF7D63901}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\dell\advanced networking service\hnm_svc.exe |
"{CF09279D-FF81-4D59-95A7-E7E0E9530EB1}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{F23A082C-433B-439A-970C-B2E3C64CE214}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent.exe |
"{F9BC8610-D105-4B4A-AB69-1CD78CC35F9B}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{2BEA2CD8-1A5D-4ADC-B000-C2A3207A6FCD}" = MobileMe Control Panel
"{404BB1FF-A84F-432F-B77B-301E88E8D1C7}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{838F7AB2-5DFE-60B3-1030-43ACC3454CD2}" = ccc-utility64
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96D5EB02-DE18-4DCD-A713-929B4461CA8D}" = iTunes
"{C19D4D8F-4433-4F6D-9F0C-79589FD0B973}" = Bonjour
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DD57342D-62B2-4D22-90FB-0BE732962410}" = Vegas Pro 9.0 (64-bit)
"{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock
"HDMI" = Intel® Graphics Media Accelerator Driver
"Lexmark 7300 Series" = Lexmark 7300 Series
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D3F9802-689F-9B6D-8E44-B55971F0CCBB}" = FlipShare
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0DB1C665-97DD-F405-1D03-60ED1DA95510}" = Catalyst Control Center Graphics Previews Vista
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{105CA5BB-9F30-149D-1AD4-144040CB3C1B}" = Catalyst Control Center Localization Spanish
"{1246FF64-3035-4A92-8FE6-A968275495EB}" = Sony Vegas Pro 8.0
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{1FECF5F8-8E75-432C-9FF7-1C04F1956B54}" = Realtek Ethernet Network Card Diagnostic tool for Windows Vista
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{299CF645-48C7-4FA1-8BCD-5CE200CF180D}" = Microsoft Search Enhancement Pack
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{2BEF1AF7-845D-78AE-D826-A87E8CDB0E7F}" = CCC Help Chinese Standard
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C36015E-F0F6-43D7-58ED-F4210D355CF9}" = Catalyst Control Center Localization Turkish
"{3FADAA19-E595-44CA-A072-58B6B0851768}" = Norton Security Scan
"{411F3ABA-2AB5-4799-AA19-6ADF0A8F7424}" = Adobe Setup
"{44033AD6-17D0-3611-1D73-2791646B0892}" = CCC Help Portuguese
"{45A1BF92-700A-4408-B95E-79F462E3D67D}" = Studio 11 Bonus DVD
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{46DAC53E-238A-410B-8BEF-2AD64254C398}" = MoviePod
"{47244975-454F-770B-79C1-0A705F17AA68}" = Catalyst Control Center Localization Chinese Standard
"{47D2D455-2C1C-4922-A520-3E3466D783E1}" = Sony Media Manager 2.0
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{4C4759BE-2BA4-2DA7-58F6-E5188062E6EB}" = CCC Help French
"{4D125AFC-0817-C6AC-B225-3C4E6EDB696D}" = CCC Help Japanese
"{4D97A48B-B4AB-4872-9F47-09D8C3455B84}" = PCmover
"{505DF7A3-88D5-4DD6-9AD5-C98C2ED0CEC4}" = Windows Live Sign-in Assistant
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{576FBE17-EBF2-4CC7-87A4-A28034CBE424}" = Sony Vegas 6.0b
"{57D57F9A-0CED-61D0-B3C6-75A874CB9F4D}" = Skins
"{5E0322C6-8CA9-A4BD-E9DC-CC8D8E7CB99E}" = Catalyst Control Center Graphics Previews Common
"{5F06BE49-28E6-771F-A57A-7AC8C97F38E1}" = Catalyst Control Center Core Implementation
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{60E5FF66-3F28-148C-8EE0-CE623C26233D}" = Catalyst Control Center Localization Portuguese
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{672BEEF8-6C95-8F97-74D4-BDF37412437B}" = CCC Help Spanish
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6E5AB107-172B-4F17-8ABB-357C59EF1B08}" = Vegas Pro 9.0
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{746F3251-0E32-08E4-D18F-43794D57588D}" = Catalyst Control Center Localization Italian
"{75C89AB1-F888-6B0B-6BB4-A06ED4BDDFC0}" = Catalyst Control Center Graphics Full Existing
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{788B97E8-D825-419A-8558-1C0B344C5371}" = Costco Photo Organizer
"{7A900EAB-DA37-4554-AF19-9C337476D05D}" = Creative MediaSource
"{7C7088C6-6347-150C-AEF4-A3190FF2F5AA}" = Catalyst Control Center Localization Hungarian
"{7CF7894B-D52C-F9E5-2ABF-DB6756CE21AC}" = CCC Help Turkish
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7E44C354-10A8-4214-9C56-F3F00775E415}_is1" = Stykz 1.0 for Windows (RC 3)
"{7EDFEE8E-F4F2-CB4E-618B-846D4A95CAC8}" = CCC Help Chinese Traditional
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{8380D40E-291B-144A-554F-4877F4B439DB}" = Catalyst Control Center InstallProxy
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{8587A68A-BF5F-9492-228C-FACFDBA1A4F4}" = CCC Help Hungarian
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8EB8E60B-315D-44EB-A896-10D88602EE46}" = Adobe Setup
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business
"{91155C7C-3404-C96D-78DA-E1D6AF73F6DA}" = Catalyst Control Center Graphics Full New
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD9026D-C3C6-0C40-9FD2-DD95A24CDEB2}" = Catalyst Control Center Localization French
"{A0422738-2E4A-B01F-D19E-ED0379A3C3CC}" = CCC Help English
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{ACE0BCCF-27A6-C275-0318-651F6388882F}" = CCC Help German
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B935C985-A17F-484B-8470-09E4FC27DC26}" = Dell-eBay
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = B57Inst
"{BEAD39CD-901D-4267-8B8B-EAA83CB4B70D}" = Pivot Stickfigure Animator
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4B556FF-ABE6-8FBE-EF7A-909F72492DA8}" = CCC Help Korean
"{C65F2D42-449D-45BF-83BE-1587AF005007}" = Belkin Wireless Utility
"{CA06B6B3-A775-50D6-3031-53C40A5202A6}" = Catalyst Control Center Localization Chinese Traditional
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{D0338BF1-DD06-8565-48A1-C8F3F991B959}" = Catalyst Control Center Localization Japanese
"{D259350E-936C-C6C0-5FDF-B6B4B95731ED}" = Catalyst Control Center Graphics Light
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{D81230AD-71DF-CFCB-CD05-52CFF26F8634}" = Catalyst Control Center Localization Korean
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E4A185BB-8E95-6FA7-2637-C9E4768DE2C3}" = ccc-core-static
"{E5F1AAA6-C0C8-326C-CAD2-B413CE1F5512}" = Catalyst Control Center Localization German
"{E62FFFA6-DCBC-189B-443E-D10A44901385}" = CCC Help Italian
"{E82BF103-904F-49C0-B77F-6EC110B71E87}" = Sound Blaster Audigy 2
"{EA8F701F-DA03-4A66-9950-7F24A16EA8B7}" = Microsoft Mike+Mary Speech Pack
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}" = Pinnacle Instant DVD Recorder
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F66A31D9-7831-4FBA-BA02-C411C0047CC5}" = Dell Remote Access
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only)
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_3dcb365ab9e01871fb8c6f27b0ea079" = Adobe After Effects CS4
"Adobe_5aab5a491a3a52ae624fd639f6aaa95" = Adobe After Effects CS4 Third Party Content
"Advanced Registry Optimizer_is1" = Advanced Registry Optimizer
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE
"Ask Toolbar_is1" = Vuze Toolbar
"AT&&T Yahoo! Messenger" = AT&T Yahoo! Messenger
"AviSynth" = AviSynth 2.5
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"CamStudio" = CamStudio
"Candy Land" = Candy Land
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Dell Video Chat" = Dell Video Chat
"Free DVD Decrypter_is1" = Free DVD Decrypter version 1.3
"Free YouTube Download_is1" = Free YouTube Download 2.3
"Free YouTube to iPod Converter_is1" = Free YouTube to iPod Converter version 3.1
"GoToAssist" = GoToAssist 8.0.0.514
"Greetings Workshop" = Greetings Workshop
"HandBrake" = HandBrake 0.9.3
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8 Beta 2
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Driver Installer
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.0.0 (Full)
"Magic DVD Ripper_is1" = Magic DVD Ripper V5.4.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mozilla Firefox (3.5.2)" = Mozilla Firefox (3.5.2)
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NSSSetup.{3FADAA19-E595-44CA-A072-58B6B0851768}" = Norton Security Scan (Symantec Corporation)
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"proDAD-Heroglyph-2.5" = proDAD Heroglyph 2.5
"proDAD-Vitascene-1.0" = proDAD Vitascene 1.0
"RealPlayer 6.0" = RealPlayer
"SystemRequirementsLab" = System Requirements Lab
"TuneUpMedia" = TuneUp Companion 1.5.9
"Ultra Mobile 3GP Video Converter_is1" = Ultra Mobile 3GP Video Converter 5.2.0603
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VideoLAN VLC media player 0.8.6d
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinFF_is1" = WinFF 1.0.4
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/31/2010 7:46:38 PM | Computer Name = HomePC | Source = Bonjour Service | ID = 100
Description = 432: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 5/31/2010 7:46:38 PM | Computer Name = HomePC | Source = Bonjour Service | ID = 100
Description = 424: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/1/2010 4:03:18 PM | Computer Name = HomePC | Source = Bonjour Service | ID = 100
Description = 456: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/1/2010 4:04:18 PM | Computer Name = HomePC | Source = Bonjour Service | ID = 100
Description = 460: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/1/2010 6:03:14 PM | Computer Name = HomePC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 7.0.6001.18444 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1490 Start Time: 01cb01d604f7fd5e Termination Time: 0

Error - 6/1/2010 10:02:14 PM | Computer Name = HomePC | Source = EventSystem | ID = 4621
Description =

Error - 6/4/2010 2:25:52 PM | Computer Name = HomePC | Source = Bonjour Service | ID = 100
Description = 456: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/5/2010 1:23:59 PM | Computer Name = HomePC | Source = Bonjour Service | ID = 100
Description = 456: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 6/6/2010 10:40:12 AM | Computer Name = HomePC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 7.0.6001.18444 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 379c Start Time: 01cb0586150ea694 Termination Time: 0

Error - 6/7/2010 10:50:19 PM | Computer Name = HomePC | Source = EventSystem | ID = 4621
Description =

[ Media Center Events ]
Error - 1/16/2010 10:56:54 PM | Computer Name = HomePC | Source = ehReplay | ID = 700
Description =

Error - 1/16/2010 10:57:03 PM | Computer Name = HomePC | Source = ehReplay | ID = 700
Description =

Error - 1/17/2010 12:58:04 AM | Computer Name = HomePC | Source = ehReplay | ID = 700
Description =

Error - 1/17/2010 12:59:29 AM | Computer Name = HomePC | Source = ehReplay | ID = 700
Description =

Error - 1/17/2010 1:13:07 AM | Computer Name = HomePC | Source = ehReplay | ID = 700
Description =

Error - 1/17/2010 1:14:11 AM | Computer Name = HomePC | Source = ehReplay | ID = 700
Description =

Error - 1/17/2010 3:46:04 PM | Computer Name = HomePC | Source = ehReplay | ID = 700
Description =

Error - 5/8/2010 12:19:07 AM | Computer Name = HomePC | Source = ehReplay | ID = 700
Description =

Error - 5/8/2010 12:19:15 AM | Computer Name = HomePC | Source = ehReplay | ID = 700
Description =

Error - 5/8/2010 12:19:42 AM | Computer Name = HomePC | Source = ehReplay | ID = 700
Description =

[ System Events ]
Error - 11/12/2009 4:19:19 AM | Computer Name = HomePC | Source = Service Control Manager | ID = 7034
Description =

Error - 11/13/2009 11:05:49 AM | Computer Name = HomePC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 10:03:19 AM on 11/13/2009 was unexpected.

Error - 11/13/2009 11:05:50 AM | Computer Name = HomePC | Source = HTTP | ID = 15016
Description =

Error - 11/13/2009 11:05:53 AM | Computer Name = HomePC | Source = Print | ID = 23
Description = Printer HP LaserJet 4L failed to initialize because a suitable HP
LaserJet 4L driver could not be found. The new printer settings that you specified
have not taken effect. Install or reinstall the printer driver. You might need
to contact the vendor for an updated driver.

Error - 11/13/2009 11:06:13 AM | Computer Name = HomePC | Source = Service Control Manager | ID = 7034
Description =

Error - 11/13/2009 11:12:22 AM | Computer Name = HomePC | Source = Service Control Manager | ID = 7000
Description =

Error - 11/14/2009 2:34:05 PM | Computer Name = HomePC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:32:19 PM on 11/14/2009 was unexpected.

Error - 11/14/2009 2:34:06 PM | Computer Name = HomePC | Source = HTTP | ID = 15016
Description =

Error - 11/14/2009 2:34:09 PM | Computer Name = HomePC | Source = Print | ID = 23
Description = Printer HP LaserJet 4L failed to initialize because a suitable HP
LaserJet 4L driver could not be found. The new printer settings that you specified
have not taken effect. Install or reinstall the printer driver. You might need
to contact the vendor for an updated driver.

Error - 11/14/2009 2:34:33 PM | Computer Name = HomePC | Source = Service Control Manager | ID = 7034
Description =


< End of report >
It looks as if you already have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates. Allow it to check for and apply any updates.
  • Select the Scanner tab, and Perform Quick Scan
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please post the log in your next reply.
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4211 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 6/18/2010 9:18:42 AM mbam-log-2010-06-18 (09-18-42).txt Scan type: Quick scan Objects scanned: 167611 Time elapsed: 5 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Please do a scan with Kaspersky Online Scanner
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
  • Text file [*.txt] Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply.
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Friday, June 18, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 64-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, June 18, 2010 15:59:06 Records in database: 4291682 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan statistics: Objects scanned: 235973 Threats found: 5 Infected objects found: 13 Suspicious objects found: 0 Scan duration: 03:41:59 File name / Threat / Threats count C:\Users\dhoholik\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\411c5bae-73b5c56f Infected: Trojan-Downloader.Java.Agent.ab 1 C:\Users\Family Account\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IESPP2RT\vj[1] Infected: Trojan-Clicker.JS.Iframe.bb 1 C:\Users\Family Account\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\56014c4b-2e69a747 Infected: Trojan-Downloader.Java.Agent.en 3 C:\Users\Family Account\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\30a456dc-59163730 Infected: Trojan-Downloader.Java.Agent.en 3 C:\Users\Family Account\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\4839f1b9-270dabae Infected: Trojan-Downloader.Java.OpenConnection.at 1 C:\Users\Family Account\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\47d62ac7-197eb2ce Infected: Trojan-Downloader.Java.Agent.en 3 C:\Users\Family Account\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\2e892388-1b53105e Infected: Trojan-Downloader.Java.Agent.al 1 Selected area has been scanned.
Run OTL.exe by right clicking the icon on your desktop and choosing Run as Administrator
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O4:64bit: - HKLM..\Run: [] File not found
    
    :Files
    C:\Users\dhoholik\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\411c5bae-73b5c56f	
    C:\Users\Family Account\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IESPP2RT\vj[1]	
    C:\Users\Family Account\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\56014c4b-2e69a747	
    C:\Users\Family Account\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\30a456dc-59163730	
    C:\Users\Family Account\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\4839f1b9-270dabae	
    C:\Users\Family Account\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\47d62ac7-197eb2ce	
    C:\Users\Family Account\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\2e892388-1b53105e	
    
    :Commands
    [purity]
    [emptytemp]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 20 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 20 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u20 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u20-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
Update Adobe Reader
There have been updates to Adobe Reader to address security vulnerabilities. You should download the latest version from the Adobe website.

In your reply please include the OTL log and let me know if you are still experiencing the Fake AV warnings on the family account.
Here is a paste of a notepad that opened up after reboot.

Files\Folders moved on Reboot…
File\Folder C:\Windows\temp\mcafee_bmlp6RpddQTdv2C not found!

Registry entries deleted on Reboot…

I then reran OTL with a regular scan (not custom) after the reboot and here are the results. I hope that is what you wanted me to do.

OTL logfile created on: 6/18/2010 9:45:12 PM - Run 2
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\dhoholik\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 65.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.11 Gb Total Space | 335.09 Gb Free Space | 57.66% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 6.13 Gb Free Space | 40.87% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOMEPC
Current User Name: dhoholik
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/06/18 21:29:00 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\dhoholik\Desktop\OTL.exe
PRC - [2010/06/17 10:28:22 | 000,231,888 | —- | M] (Adobe Systems, Inc.) – C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
PRC - [2010/06/10 06:58:32 | 000,865,832 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/10/29 07:54:44 | 001,218,008 | —- | M] (McAfee, Inc.) – c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
PRC - [2009/10/27 12:19:46 | 000,895,696 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee\MPF\MpfSrv.exe
PRC - [2009/09/16 09:28:38 | 000,606,736 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/07/08 14:48:48 | 000,026,640 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee\MSK\msksrver.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/07/07 19:10:02 | 002,482,848 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2009/07/07 10:23:00 | 001,779,952 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
PRC - [2009/06/04 18:41:22 | 000,451,904 | —- | M] () – C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
PRC - [2009/04/02 12:47:04 | 000,234,888 | —- | M] () – C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe
PRC - [2009/04/02 12:47:02 | 000,464,264 | —- | M] () – C:\Program Files (x86)\AskBarDis\bar\bin\AskService.exe
PRC - [2009/02/23 09:48:06 | 000,632,048 | —- | M] (SoftThinks) – C:\Windows\sminst\SftService.exe
PRC - [2009/02/04 21:26:38 | 000,128,232 | —- | M] (CyberLink Corp.) – C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2008/12/18 13:05:28 | 000,155,648 | —- | M] (Stardock Corporation) – C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/12/16 21:14:42 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/12/16 21:14:42 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/12/08 17:01:52 | 000,224,600 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Toolbar\wltuser.exe
PRC - [2008/12/04 16:03:00 | 000,226,640 | —- | M] (Microsoft Corp.) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2008/01/20 22:50:38 | 000,299,520 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Internet Explorer\ieuser.exe
PRC - [2006/10/18 21:05:26 | 000,204,288 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Media Player\wmpnscfg.exe
PRC - [1997/09/04 01:00:00 | 000,050,688 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Greetings Workshop\GWREMIND.EXE


========== Modules (SafeList) ==========

MOD - [2010/06/18 21:29:00 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\dhoholik\Desktop\OTL.exe
MOD - [2008/01/20 22:50:03 | 000,450,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\comdlg32.dll
MOD - [2008/01/20 22:50:01 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2008/01/20 22:48:06 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/09/16 11:23:32 | 000,696,848 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV:64bit: - [2009/09/16 10:15:32 | 000,155,456 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\McAfee\VirusScan\Mcshield.exe – (McShield)
SRV:64bit: - [2009/02/24 03:49:22 | 000,901,120 | —- | M] () [Auto | Running] – C:\Windows\SysNative\Ati2evxx.exe – (Ati External Event Utility)
SRV:64bit: - [2008/12/18 13:05:28 | 000,155,648 | —- | M] (Stardock Corporation) [Auto | Running] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV:64bit: - [2008/07/18 08:42:16 | 000,086,016 | —- | M] () [Auto | Running] – C:\Windows\SysNative\AERTSr64.exe – (AERTFilters)
SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2006/05/15 09:24:50 | 000,452,608 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysNative\lxcicoms.exe – (lxci_device)
SRV - [2010/06/10 06:58:32 | 000,865,832 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe – (mcmscsvc)
SRV - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/10/27 12:19:46 | 000,895,696 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files (x86)\McAfee\MPF\MpfSrv.exe – (MpfService)
SRV - [2009/09/16 09:28:38 | 000,606,736 | —- | M] (McAfee, Inc.) [On_Demand | Running] – C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe – (McSysmon)
SRV - [2009/07/08 14:48:48 | 000,026,640 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files (x86)\McAfee\MSK\MskSrver.exe – (MSK80Service)
SRV - [2009/07/08 11:54:34 | 000,359,952 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe – (McProxy)
SRV - [2009/07/07 19:10:02 | 002,482,848 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe – (McNASvc)
SRV - [2009/06/04 18:41:22 | 000,451,904 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe – (FlipShare Service)
SRV - [2009/06/04 09:58:47 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2009/04/02 12:47:04 | 000,234,888 | —- | M] () [Auto | Running] – C:\Program Files (x86)\AskBarDis\bar\bin\ASKUpgrade.exe – (ASKUpgrade)
SRV - [2009/04/02 12:47:02 | 000,464,264 | —- | M] () [Auto | Running] – C:\Program Files (x86)\AskBarDis\bar\bin\AskService.exe – (ASKService)
SRV - [2009/02/23 09:48:06 | 000,632,048 | —- | M] (SoftThinks) [Auto | Running] – C:\Windows\sminst\sftservice.EXE – (SftService)
SRV - [2009/01/05 17:19:10 | 000,824,560 | —- | M] (Dell Inc.) [Auto | Stopped] – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe – (hnmsvc)
SRV - [2008/12/16 21:14:42 | 000,206,064 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter)
SRV - [2008/12/04 16:03:00 | 000,226,640 | —- | M] (Microsoft Corp.) [Auto | Running] – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2008/07/27 14:01:49 | 000,093,184 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64)
SRV - [2007/02/01 22:13:46 | 000,537,520 | —- | M] ( ) [On_Demand | Stopped] – C:\Windows\SysWow64\lxcicoms.exe – (lxci_device)
SRV - [2006/11/03 20:20:06 | 000,271,128 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2006/11/02 02:35:15 | 000,060,994 | —- | M] () [On_Demand | Stopped] – C:\Windows\SysWOW64\wbem\vds.mof – (vds)
SRV - [2005/09/23 07:28:32 | 000,029,896 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state)
SRV - [2002/12/17 17:26:22 | 007,520,337 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe – (MSSQL$SONY_MEDIAMGR)
SRV - [2002/12/17 17:23:30 | 000,311,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE – (SQLAgent$SONY_MEDIAMGR)
SRV - [2002/12/17 17:23:30 | 000,066,112 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe – (MSSQLServerADHelper)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/04/16 08:33:36 | 000,050,176 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2009/09/16 10:22:40 | 000,308,296 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\drivers\mfehidk.sys – (mfehidk)
DRV:64bit: - [2009/09/16 10:22:40 | 000,102,472 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfeavfk.sys – (mfeavfk)
DRV:64bit: - [2009/09/16 10:22:40 | 000,049,480 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfesmfk.sys – (mfesmfk)
DRV:64bit: - [2009/09/16 10:15:38 | 000,040,904 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mferkdk.sys – (mferkdk)
DRV:64bit: - [2009/07/16 12:32:26 | 000,176,144 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\Drivers\Mpfp.sys – (MPFP)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/02/24 03:49:28 | 004,598,784 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\atikmdag.sys – (R300)
DRV:64bit: - [2009/02/24 03:49:28 | 004,598,784 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/02/23 05:47:04 | 000,126,464 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV:64bit: - [2009/02/23 05:46:28 | 010,275,296 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\igdkmd64.sys – (igfx)
DRV:64bit: - [2008/12/19 22:24:48 | 000,041,032 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mfebopk.sys – (mfebopk)
DRV:64bit: - [2008/07/21 07:18:30 | 000,026,624 | —- | M] () [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\RtNdPt60.sys – (RtNdPt60)
DRV:64bit: - [2008/07/15 08:14:10 | 000,395,288 | —- | M] () [Kernel | Disabled | Stopped] – C:\Windows\SysNative\drivers\iastor.sys – (iaStor)
DRV:64bit: - [2008/07/10 07:28:50 | 000,170,496 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\Rtlh64.sys – (RTL8169)
DRV:64bit: - [2008/06/18 16:48:54 | 000,029,184 | —- | M] () [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\packet.sys – (Packet)
DRV:64bit: - [2008/01/20 22:50:35 | 000,009,728 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\umpass.sys – (UMPass)
DRV:64bit: - [2008/01/20 22:47:28 | 000,048,768 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\avc.sys – (Avc)
DRV:64bit: - [2008/01/20 22:47:28 | 000,046,080 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\wpdusb.sys – (WpdUsb)
DRV:64bit: - [2008/01/20 22:46:59 | 000,036,864 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\WinUSB.SYS – (winusb)
DRV:64bit: - [2008/01/20 22:46:57 | 000,058,496 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\61883.sys – (61883)
DRV:64bit: - [2008/01/20 22:46:55 | 000,317,952 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\e1e6032e.sys – (e1express) Intel®
DRV:64bit: - [2008/01/20 22:46:53 | 000,061,568 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\msdv.sys – (MSDV)
DRV:64bit: - [2007/11/14 03:00:00 | 000,053,488 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2006/11/02 01:28:10 | 000,273,920 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HdAudio.sys – (HdAudAddService)
DRV - [2008/11/04 19:16:40 | 000,028,152 | —- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Dell Support Center\HWDiag\bin\pcd5srvc_x64.pkms – (PCD5SRVC{048DBD20-445E8C82-05040104})
DRV - [2008/01/20 22:49:57 | 000,016,384 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\winusb.dll – (winusb)
DRV - [2006/09/18 17:36:40 | 000,003,066 | —- | M] () [Kernel | System | Running] – C:\Windows\SysWOW64\wbem\tcpip.mof – (Tcpip)
DRV - [2006/09/18 17:35:23 | 000,001,088 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysWOW64\wbem\mpsdrv.mof – (mpsdrv)
DRV - [2002/09/03 13:09:27 | 000,009,344 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\vga.dll – (vga)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.2
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files (x86)\Real\RealPlayer\browserrecord [2009/06/13 20:56:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/05/07 17:34:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/06/07 15:08:53 | 000,000,000 | —D | M]

[2009/08/26 09:46:17 | 000,000,000 | —D | M] – C:\Users\dhoholik\AppData\Roaming\Mozilla\Extensions
[2010/03/23 21:29:44 | 000,000,000 | —D | M] – C:\Users\dhoholik\AppData\Roaming\Mozilla\Firefox\Profiles\pyq8y6hz.default\extensions
[2009/08/26 09:47:05 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\dhoholik\AppData\Roaming\Mozilla\Firefox\Profiles\pyq8y6hz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/26 09:47:05 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\dhoholik\AppData\Roaming\Mozilla\Firefox\Profiles\pyq8y6hz.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/10/09 21:33:16 | 000,000,000 | —D | M] (No name found) – C:\Users\dhoholik\AppData\Roaming\Mozilla\Firefox\Profiles\pyq8y6hz.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/08/09 23:13:46 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2008/06/18 03:43:04 | 000,086,016 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll

O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho64.dll ()
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] File not found
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [WPCUMI] C:\Windows\SysNative\WpcUmi.exe ()
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\dhoholik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Greetings Workshop Reminders.lnk = C:\Program Files (x86)\Greetings Workshop\GWREMIND.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysNative\wpclsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysNative\wpclsp.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {741747F6-83B4-4FB9-A268-8CA4010762C8} http://www2.snapfish.com/SnapfishActivia2.cab (Snapfish Activia2)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {A1662FB6-39BE-41BB-ACDC-0448FB1B5817} http://images3.pnimedia.com/ProductAssets/…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DEA6994F-3ED5-40BC-B5E3-0FD02411B1B4} http://www.costcophotocenter.com/upload/ac…veX_Control.cab? (Photo Upload Plugin Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} http://www.costcophotocenter.com/upload/ac…veX_Control.cab? (Photo Upload Plugin Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18:64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files (x86)\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll ()
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files (x86)\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/30 16:01:00 | 000,000,053 | -HS- | M] () - D:\AUTORUN.INF – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/18 21:31:43 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/18 21:28:51 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Users\dhoholik\Desktop\OTL.exe
[2010/06/17 14:12:03 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\dhoholik\Desktop\HiJackThis.exe
[2010/06/17 14:03:45 | 000,000,000 | —D | C] – C:\Users\dhoholik\AppData\Roaming\PeerNetworking
[2010/06/17 14:02:44 | 000,000,000 | —D | C] – C:\Users\dhoholik\AppData\Roaming\DivX
[2010/06/17 14:02:19 | 000,000,000 | —D | C] – C:\Users\dhoholik\AppData\Roaming\Media Player Classic
[2010/06/09 22:30:27 | 000,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2010/06/09 22:30:26 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2010/06/09 22:30:23 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\asycfilt.dll
[2010/06/09 22:30:06 | 000,833,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wininet.dll
[2010/06/09 22:30:06 | 000,146,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2010/06/09 22:30:05 | 000,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2010/06/09 22:30:04 | 000,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstime.dll
[2010/06/09 22:30:04 | 000,476,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2010/06/09 22:30:04 | 000,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2010/06/09 22:30:04 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2010/06/09 22:30:04 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iedkcs32.dll
[2010/06/09 22:30:04 | 000,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2010/06/09 22:30:04 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010/06/09 22:30:04 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieencode.dll
[2010/06/09 22:30:04 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2010/06/09 22:30:03 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jsproxy.dll
[2010/06/09 22:29:28 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2009/09/29 19:31:28 | 000,643,072 | —- | C] ( ) – C:\Windows\SysWow64\lxcipmui.dll
[2009/09/29 19:31:28 | 000,413,696 | —- | C] ( ) – C:\Windows\SysWow64\lxciinpa.dll
[2009/09/29 19:31:28 | 000,397,312 | —- | C] ( ) – C:\Windows\SysWow64\lxciiesc.dll
[2009/09/29 19:31:27 | 001,224,704 | —- | C] ( ) – C:\Windows\SysWow64\lxciserv.dll
[2009/09/29 19:31:27 | 000,991,232 | —- | C] ( ) – C:\Windows\SysWow64\lxciusb1.dll
[2009/09/29 19:31:27 | 000,696,320 | —- | C] ( ) – C:\Windows\SysWow64\lxcihbn3.dll
[2009/09/29 19:31:27 | 000,684,032 | —- | C] ( ) – C:\Windows\SysWow64\lxcicomc.dll
[2009/09/29 19:31:27 | 000,585,728 | —- | C] ( ) – C:\Windows\SysWow64\lxcilmpm.dll
[2009/09/29 19:31:27 | 000,421,888 | —- | C] ( ) – C:\Windows\SysWow64\lxcicomm.dll
[2009/09/29 19:31:27 | 000,163,840 | —- | C] ( ) – C:\Windows\SysWow64\lxciprox.dll
[2009/09/29 19:31:27 | 000,094,208 | —- | C] ( ) – C:\Windows\SysWow64\lxcipplc.dll
[2007/04/09 13:32:58 | 000,065,536 | —- | C] ( ) – C:\Windows\SysWow64\a3d.dll

========== Files - Modified Within 30 Days ==========

[2010/06/18 21:50:00 | 000,000,436 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{65AA9B57-87FA-4F6E-8073-93F0C0369054}.job
[2010/06/18 21:49:38 | 000,691,354 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/18 21:49:38 | 000,595,446 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/18 21:49:38 | 000,101,144 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/18 21:48:16 | 007,340,032 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT
[2010/06/18 21:45:01 | 000,567,677 | —- | M] () – C:\Users\dhoholik\Desktop\OTL.rar
[2010/06/18 21:42:42 | 000,015,013 | —- | M] () – C:\Windows\SysNative\Config.MPF
[2010/06/18 21:42:15 | 000,000,288 | —- | M] () – C:\Windows\tasks\RtlNICDiagVistaStart.job
[2010/06/18 21:42:05 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/18 21:42:05 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/18 21:42:02 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/18 21:42:01 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/18 21:41:58 | 4294,107,136 | -HS- | M] () – C:\hiberfil.sys
[2010/06/18 21:41:02 | 000,524,288 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TMContainer00000000000000000001.regtrans-ms
[2010/06/18 21:41:02 | 000,065,536 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TM.blf
[2010/06/18 21:40:59 | 004,983,840 | -H– | M] () – C:\Users\dhoholik\AppData\Local\IconCache.db
[2010/06/18 21:29:00 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\dhoholik\Desktop\OTL.exe
[2010/06/18 21:22:46 | 000,000,680 | —- | M] () – C:\Users\dhoholik\AppData\Local\d3d9caps.dat
[2010/06/18 19:02:00 | 000,000,944 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2165948760-776771271-4270439850-1001UA.job
[2010/06/18 09:02:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2165948760-776771271-4270439850-1001Core.job
[2010/06/18 00:51:15 | 000,000,424 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{9140BB2F-11EB-45E4-AB6F-28AD9A8FDB29}.job
[2010/06/17 14:12:11 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\dhoholik\Desktop\HiJackThis.exe
[2010/06/17 14:03:45 | 000,023,909 | —- | M] () – C:\Users\dhoholik\AppData\Roaming\UserTile.png
[2010/06/17 14:01:27 | 002,851,880 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/06/13 19:50:23 | 000,000,632 | RHS- | M] () – C:\Users\dhoholik\ntuser.pol
[2010/06/09 12:33:19 | 000,000,732 | —- | M] () – C:\Users\dhoholik\AppData\Local\d3d9caps64.dat
[2010/06/08 22:15:01 | 000,000,850 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/07 06:50:20 | 000,524,288 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TMContainer00000000000000000002.regtrans-ms
[2010/06/06 23:19:18 | 000,524,288 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT{d163e63a-5f44-11df-8ef7-0021705c34ea}.TMContainer00000000000000000001.regtrans-ms
[2010/06/06 23:19:18 | 000,065,536 | -HS- | M] () – C:\Users\dhoholik\NTUSER.DAT{d163e63a-5f44-11df-8ef7-0021705c34ea}.TM.blf
[2010/05/26 12:53:52 | 000,048,128 | —- | M] () – C:\Windows\SysNative\atmlib.dll
[2010/05/26 12:16:50 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2010/05/26 10:56:53 | 000,366,080 | —- | M] () – C:\Windows\SysNative\atmfd.dll
[2010/05/26 10:25:15 | 000,289,792 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll

========== Files Created - No Company Name ==========

[2010/06/18 21:45:01 | 000,567,677 | —- | C] () – C:\Users\dhoholik\Desktop\OTL.rar
[2010/06/17 14:03:45 | 000,023,909 | —- | C] () – C:\Users\dhoholik\AppData\Roaming\UserTile.png
[2010/06/17 14:01:09 | 4294,107,136 | -HS- | C] () – C:\hiberfil.sys
[2010/06/09 22:30:27 | 000,366,080 | —- | C] () – C:\Windows\SysNative\atmfd.dll
[2010/06/09 22:30:27 | 000,048,128 | —- | C] () – C:\Windows\SysNative\atmlib.dll
[2010/06/09 22:30:23 | 000,084,480 | —- | C] () – C:\Windows\SysNative\asycfilt.dll
[2010/06/09 22:30:17 | 002,749,952 | —- | C] () – C:\Windows\SysNative\win32k.sys
[2010/06/09 22:30:08 | 005,690,368 | —- | C] () – C:\Windows\SysNative\mshtml.dll
[2010/06/09 22:30:06 | 007,006,208 | —- | C] () – C:\Windows\SysNative\ieframe.dll
[2010/06/09 22:30:06 | 001,426,944 | —- | C] () – C:\Windows\SysNative\urlmon.dll
[2010/06/09 22:30:06 | 001,032,704 | —- | C] () – C:\Windows\SysNative\wininet.dll
[2010/06/09 22:30:06 | 000,208,896 | —- | C] () – C:\Windows\SysNative\occache.dll
[2010/06/09 22:30:05 | 000,758,784 | —- | C] () – C:\Windows\SysNative\mshtmled.dll
[2010/06/09 22:30:05 | 000,422,400 | —- | C] () – C:\Windows\SysNative\ieapfltr.dll
[2010/06/09 22:30:04 | 001,129,984 | —- | C] () – C:\Windows\SysNative\mstime.dll
[2010/06/09 22:30:04 | 000,580,608 | —- | C] () – C:\Windows\SysNative\msfeeds.dll
[2010/06/09 22:30:04 | 000,485,376 | —- | C] () – C:\Windows\SysNative\html.iec
[2010/06/09 22:30:04 | 000,480,256 | —- | C] () – C:\Windows\SysNative\iedkcs32.dll
[2010/06/09 22:30:04 | 000,375,296 | —- | C] () – C:\Windows\SysNative\iertutil.dll
[2010/06/09 22:30:04 | 000,267,776 | —- | C] () – C:\Windows\SysNative\ieaksie.dll
[2010/06/09 22:30:04 | 000,249,856 | —- | C] () – C:\Windows\SysNative\iepeers.dll
[2010/06/09 22:30:04 | 000,086,528 | —- | C] () – C:\Windows\SysNative\ieencode.dll
[2010/06/09 22:30:04 | 000,032,768 | —- | C] () – C:\Windows\SysNative\ieUnatt.exe
[2010/06/09 22:30:03 | 001,383,424 | —- | C] () – C:\Windows\SysNative\mshtml.tlb
[2010/06/09 22:30:03 | 000,032,256 | —- | C] () – C:\Windows\SysNative\jsproxy.dll
[2010/06/09 22:29:28 | 001,570,816 | —- | C] () – C:\Windows\SysNative\quartz.dll
[2010/06/07 06:50:19 | 000,524,288 | -HS- | C] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TMContainer00000000000000000002.regtrans-ms
[2010/06/07 06:50:19 | 000,524,288 | -HS- | C] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TMContainer00000000000000000001.regtrans-ms
[2010/06/07 06:50:19 | 000,065,536 | -HS- | C] () – C:\Users\dhoholik\NTUSER.DAT{4b2ae1b5-7222-11df-9896-0021705c34ea}.TM.blf
[2010/05/25 13:54:01 | 000,002,048 | —- | C] () – C:\Windows\SysNative\tzres.dll
[2009/10/06 20:49:51 | 000,164,352 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2009/10/06 20:49:49 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2009/10/06 20:49:49 | 000,755,027 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2009/10/06 20:49:49 | 000,159,839 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2009/10/06 20:49:47 | 000,007,680 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2009/10/06 20:49:47 | 000,000,547 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll.manifest
[2009/09/29 19:31:28 | 000,385,024 | —- | C] () – C:\Windows\SysWow64\lxcicomx.dll
[2009/09/29 19:31:28 | 000,274,432 | —- | C] () – C:\Windows\SysWow64\lxciinst.dll
[2009/08/04 21:17:34 | 000,129,024 | —- | C] () – C:\Windows\SysWow64\AVERM.dll
[2009/08/04 21:17:34 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\AVEQT.dll
[2009/06/04 10:03:34 | 000,126,976 | —- | C] () – C:\Windows\SysWow64\STWmiM.dll
[2009/06/04 10:03:34 | 000,102,400 | —- | C] () – C:\Windows\SysWow64\STShellVC6.dll
[2009/06/04 10:03:34 | 000,090,112 | —- | C] () – C:\Windows\SysWow64\wnaspi32.dll
[2009/06/04 10:03:34 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\zlib1.dll
[2009/06/04 10:03:34 | 000,066,048 | —- | C] () – C:\Windows\SysWow64\STWiz.dll
[2009/06/04 10:03:33 | 000,385,024 | —- | C] () – C:\Windows\SysWow64\STODD.dll
[2009/06/04 10:03:33 | 000,380,928 | —- | C] () – C:\Windows\SysWow64\STODDRD.dll
[2009/06/04 10:03:33 | 000,266,240 | —- | C] () – C:\Windows\SysWow64\STODDIM.dll
[2009/06/04 10:03:33 | 000,253,952 | —- | C] () – C:\Windows\SysWow64\STODDSC.dll
[2009/06/04 10:03:33 | 000,229,376 | —- | C] () – C:\Windows\SysWow64\STFiles.dll
[2009/06/04 10:03:33 | 000,122,880 | —- | C] () – C:\Windows\SysWow64\STLog.dll
[2009/06/04 10:03:33 | 000,115,712 | —- | C] () – C:\Windows\SysWow64\STNLS.dll
[2009/06/04 10:03:33 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\STPE.dll
[2009/06/04 10:03:33 | 000,098,304 | —- | C] () – C:\Windows\SysWow64\STFileMonitor.dll
[2009/06/04 10:03:33 | 000,094,208 | —- | C] () – C:\Windows\SysWow64\STMsXml.dll
[2009/06/04 10:03:33 | 000,077,824 | —- | C] () – C:\Windows\SysWow64\STLangXml.dll
[2009/06/04 10:03:33 | 000,069,632 | —- | C] () – C:\Windows\SysWow64\STRegistry.dll
[2009/06/04 10:03:33 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\STProcess.dll
[2009/06/04 10:03:32 | 001,118,208 | —- | C] () – C:\Windows\SysWow64\libxml2.dll
[2009/06/04 10:03:32 | 000,471,040 | —- | C] () – C:\Windows\SysWow64\PSTImage.dll
[2009/06/04 10:03:32 | 000,118,784 | —- | C] () – C:\Windows\SysWow64\STCrypto.dll
[2009/06/04 10:03:32 | 000,110,592 | —- | C] () – C:\Windows\SysWow64\PSTVdsDisk.dll
[2009/06/04 10:03:32 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\STCoreXml.dll
[2008/12/11 11:05:42 | 000,000,197 | —- | C] () – C:\Windows\SysWow64\MRT.INI
[2008/07/26 20:30:19 | 000,000,138 | —- | C] () – C:\Windows\cdplayer.ini
[2008/02/19 02:33:34 | 000,446,352 | —- | C] () – C:\Windows\SysWow64\OpenQuicktimeLib.dll
[2008/01/20 22:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 22:49:49 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008/01/19 19:33:36 | 000,000,481 | —- | C] () – C:\Windows\hegames.ini
[2008/01/17 12:51:18 | 000,000,000 | —- | C] () – C:\Windows\SETUP32.INI
[2007/12/23 12:30:52 | 000,000,231 | —- | C] () – C:\Windows\AC3API.INI
[2007/12/23 12:30:52 | 000,000,000 | —- | C] () – C:\Windows\SBWIN.INI
[2007/12/23 12:30:06 | 000,066,807 | —- | C] () – C:\Windows\SysWow64\Aud2_Del.ini
[2007/12/23 12:29:57 | 000,005,515 | —- | C] () – C:\Windows\SysWow64\ENSDEF.INI
[2007/12/23 12:29:57 | 000,000,180 | —- | C] () – C:\Windows\SysWow64\kill.ini
[2007/12/21 17:33:28 | 000,000,017 | —- | C] () – C:\Windows\MovingPicture.ini
[2007/12/19 22:42:38 | 000,000,523 | —- | C] () – C:\Windows\ATICIM.INI
[2007/12/19 22:39:14 | 000,012,288 | —- | C] () – C:\Windows\SysWow64\e100bmsg.dll
[2007/12/19 21:42:58 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2007/12/19 13:27:02 | 000,013,223 | —- | C] () – C:\Windows\SysWow64\tslabels.ini
[2007/12/19 13:27:01 | 000,001,931 | —- | C] () – C:\Windows\SysWow64\msdtcprf.ini
[2007/12/19 04:56:56 | 000,497,600 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2007/04/12 09:10:28 | 000,105,728 | —- | C] () – C:\Windows\SysWow64\APOMgrH.dll
[2007/04/09 13:55:14 | 000,097,785 | —- | C] () – C:\Windows\SysWow64\instwdm.ini
[2007/04/09 13:55:14 | 000,000,030 | —- | C] () – C:\Windows\SysWow64\ctzapxx.ini
[2007/04/09 13:33:50 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\CTBurst.dll
[2005/06/16 11:17:16 | 000,071,680 | —- | C] () – C:\Windows\SysWow64\ctmmactl.dll
[2002/09/03 13:12:01 | 000,013,312 | —- | C] () – C:\Windows\SysWow64\win87em.dll
[2002/09/03 13:07:26 | 000,015,360 | —- | C] () – C:\Windows\SysWow64\tsd32.dll
[2002/09/03 12:56:51 | 000,012,082 | —- | C] () – C:\Windows\SysWow64\rsvp.ini
[2002/09/03 12:54:43 | 000,003,458 | —- | C] () – C:\Windows\SysWow64\rasctrs.ini
[2002/09/03 12:53:06 | 000,006,877 | —- | C] () – C:\Windows\SysWow64\pschdprf.ini
[2002/09/03 12:52:57 | 000,000,343 | —- | C] () – C:\Windows\SysWow64\prodspec.ini
[2002/09/03 12:52:06 | 000,002,732 | —- | C] () – C:\Windows\SysWow64\perfwci.ini
[2002/09/03 12:52:00 | 000,001,152 | —- | C] () – C:\Windows\SysWow64\perffilt.ini
[2002/09/03 12:51:55 | 000,002,891 | —- | C] () – C:\Windows\SysWow64\perfci.ini
[2002/09/03 12:50:09 | 000,034,560 | —- | C] () – C:\Windows\SysWow64\ntio804.sys
[2002/09/03 12:50:08 | 000,035,424 | —- | C] () – C:\Windows\SysWow64\ntio412.sys
[2002/09/03 12:50:07 | 000,035,648 | —- | C] () – C:\Windows\SysWow64\ntio411.sys
[2002/09/03 12:50:07 | 000,034,560 | —- | C] () – C:\Windows\SysWow64\ntio404.sys
[2002/09/03 12:50:06 | 000,033,840 | —- | C] () – C:\Windows\SysWow64\ntio.sys
[2002/09/03 12:50:01 | 000,029,146 | —- | C] () – C:\Windows\SysWow64\ntdos804.sys
[2002/09/03 12:50:00 | 000,029,370 | —- | C] () – C:\Windows\SysWow64\ntdos411.sys
[2002/09/03 12:50:00 | 000,029,274 | —- | C] () – C:\Windows\SysWow64\ntdos412.sys
[2002/09/03 12:49:59 | 000,029,146 | —- | C] () – C:\Windows\SysWow64\ntdos404.sys
[2002/09/03 12:49:59 | 000,027,866 | —- | C] () – C:\Windows\SysWow64\ntdos.sys
[2002/09/03 12:44:28 | 000,094,282 | —- | C] () – C:\Windows\SysWow64\msencode.dll
[2002/09/03 12:44:27 | 000,004,126 | —- | C] () – C:\Windows\SysWow64\msdxmlc.dll
[2002/09/03 12:39:11 | 000,042,537 | —- | C] () – C:\Windows\SysWow64\keyboard.sys
[2002/09/03 12:39:08 | 000,042,809 | —- | C] () – C:\Windows\SysWow64\key01.sys
[2002/09/03 12:34:10 | 000,004,768 | —- | C] () – C:\Windows\SysWow64\himem.sys
[2002/09/03 12:32:37 | 001,015,477 | —- | C] () – C:\Windows\SysWow64\esentprf.ini
[2002/09/03 12:29:31 | 000,027,097 | —- | C] () – C:\Windows\SysWow64\country.sys
[2002/09/03 12:27:19 | 000,009,029 | —- | C] () – C:\Windows\SysWow64\ansi.sys
[2001/08/17 18:36:28 | 000,157,696 | —- | C] () – C:\Windows\SysWow64\paqsp.dll
[1997/11/17 18:13:16 | 000,010,240 | —- | C] () – C:\Windows\SysWow64\vidx16.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:5D432CE3
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:888AFB86
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:7E95B6FD
< End of report >
I reread your instructions and I realized I missed a response. I let my computer sit for an hour with no popups so I think I am all set. I will now do the Adobe and Java updates. Thanks for your help, it is much appreciated!
Okay, one last question, I am trying to find the Java symbol in classic view in the control panel but it is not there. I do know what it looks like. So I cannot do the last couple instructions here, any ideas? •After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup) ◦On the General tab, under Temporary Internet Files, click the Settings button. ◦Next, click on the Delete Files button ◦There are two options in the window to clear the cache - Leave BOTH Checked Applications and Applets Trace and Log Files •Click OK on Delete Temporary Files Window Note: This deletes ALL the Downloaded Applications and Applets from the CACHE. •Click OK to leave the Temporary Files Window •Click OK to leave the Java Control Panel.
If you do not see the coffee cup icon in the Windows Control Panel, you do not have the latest version of Java installed on your computer. If you already installed the file, perhaps something went wrong during the installation. Go ahead and reinstall it by right-clicking the file and choosing Run as Administrator. It can take several minutes for Java to finish installing. It should give you a pop up dialog letting you know when it has completed.

Then try the remainder of the steps again. Let me know if that fixes the problem or not.

To remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it (remember to rightt click and choose Run as Administrator)
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

If you notice any remaining tools or files you can delete them by right clicking and choosing delete.

Please let me know when you have completed these steps or if you have any additional problems getting Java installed. Also, can you please just confirm you tested the family account to make sure there were no pop-ups there any longer?
Are you still having problems getting Java installed and how is the computer behaving on the family account now?

Reminder: Topics with no reply in 4 days are closed!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI