This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

slow response with lockups

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, no2sun99
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





  • Please download OTL from one of the following mirrors:
    • This is THE Mirror
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <โ€“ Will be opened
    • Extra.txt <โ€“ Will be minimized





Download GMER from Here. Note the file's name and save it to your root folder, such as C:\.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
  • Click on this link to see a list of programs that should be disabled.
  • Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
  • Allow the driver to load if asked.
  • You may be prompted to scan immediately if it detects rootkit activity.
  • If you are prompted to scan your system click "No", save the log and post back the results.
  • If not prompted, click the "Rootkit/Malware" tab.
  • On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click the Scan button to begin. (Please be patient as it can take some time to complete)
  • When the scan is finished, click Save to save the scan results to your Desktop.
  • Save the file as Results.log and copy/paste the contents in your next reply.
  • Exit the program and re-enable all active protection when done.
Thanks Tom for your prompt response. I hope this is correct. I tried to attach the two files to your response but I could not do it. Again thank you and hope this is what you need.
Rich



OTL logfile created on: 6/29/2010 2:35:47 PM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\Rich\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): c:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.45 Gb Total Space | 58.90 Gb Free Space | 79.11% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 465.76 Gb Total Space | 456.89 Gb Free Space | 98.10% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DF5141F1
Current User Name: Rich
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/06/29 14:35:02 | 000,574,464 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Rich\Desktop\OTL.exe
PRC - [2010/06/28 16:57:18 | 002,837,864 | โ€”- | M] (AVAST Software) โ€“ C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/06/28 16:57:15 | 000,040,384 | โ€”- | M] (AVAST Software) โ€“ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/06/18 22:13:50 | 000,864,112 | โ€”- | M] (Lavasoft) โ€“ C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010/06/18 22:13:49 | 001,352,832 | โ€”- | M] (Lavasoft) โ€“ C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010/05/26 13:05:04 | 002,437,176 | โ€”- | M] (Check Point Software Technologies LTD) โ€“ C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PRC - [2010/05/26 13:03:36 | 001,043,968 | โ€”- | M] (Check Point Software Technologies LTD) โ€“ C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2008/08/14 00:04:44 | 000,201,968 | โ€”- | M] (SupportSoft, Inc.) โ€“ C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/06/24 19:56:38 | 000,431,384 | โ€”- | M] (Seagate) โ€“ C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\explorer.exe
PRC - [2007/05/25 12:38:46 | 000,112,176 | โ€”- | M] (SingleClick Systems) โ€“ C:\Program Files\Dell Network Assistant\hnm_svc.exe


========== Modules (SafeList) ==========

MOD - [2010/06/29 14:35:02 | 000,574,464 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Rich\Desktop\OTL.exe
MOD - [2008/04/13 20:10:20 | 000,110,592 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2010/06/28 16:57:15 | 000,040,384 | โ€”- | M] (AVAST Software) [On_Demand | Running] โ€“ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe โ€“ (avast! Web Scanner)
SRV - [2010/06/28 16:57:15 | 000,040,384 | โ€”- | M] (AVAST Software) [On_Demand | Running] โ€“ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe โ€“ (avast! Mail Scanner)
SRV - [2010/06/28 16:57:15 | 000,040,384 | โ€”- | M] (AVAST Software) [Auto | Running] โ€“ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe โ€“ (avast! Antivirus)
SRV - [2010/06/18 22:13:49 | 001,352,832 | โ€”- | M] (Lavasoft) [Auto | Running] โ€“ C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe โ€“ (Lavasoft Ad-Aware Service)
SRV - [2010/05/26 13:05:04 | 002,437,176 | โ€”- | M] (Check Point Software Technologies LTD) [Auto | Running] โ€“ C:\WINDOWS\System32\ZoneLabs\vsmon.exe โ€“ (vsmon)
SRV - [2010/03/29 08:51:54 | 000,068,000 | โ€”- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] โ€“ C:\Program Files\NOS\bin\getPlus_Helper.dll โ€“ (getPlusHelper) getPlusยฎ
SRV - [2009/04/26 14:29:24 | 000,090,352 | โ€”- | M] (PC Pitstop LLC) [Disabled | Stopped] โ€“ C:\Program Files\PCPitstop\PCPitstopScheduleService.exe โ€“ (PCPitstop Scheduling)
SRV - [2008/08/14 00:04:44 | 000,201,968 | โ€”- | M] (SupportSoft, Inc.) [Auto | Running] โ€“ C:\Program Files\Dell Support Center\bin\sprtsvc.exe โ€“ (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/06/24 19:56:38 | 000,431,384 | โ€”- | M] (Seagate) [Auto | Running] โ€“ C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe โ€“ (SgtSch2Svc)
SRV - [2007/05/25 12:38:46 | 000,112,176 | โ€”- | M] (SingleClick Systems) [Auto | Running] โ€“ C:\Program Files\Dell Network Assistant\hnm_svc.exe โ€“ (hnmsvc)
SRV - [2007/03/19 13:44:44 | 000,070,656 | โ€”- | M] () [On_Demand | Stopped] โ€“ C:\Program Files\DellSupport\brkrsvc.exe โ€“ (DSBrokerService)
SRV - [2006/09/02 17:36:33 | 002,528,960 | โ€”- | M] (Symantec Corporation) [On_Demand | Stopped] โ€“ C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE โ€“ (LiveUpdate)


========== Driver Services (SafeList) ==========

DRV - [2010/06/28 16:37:52 | 000,046,672 | โ€”- | M] (ALWIL Software) [Kernel | System | Running] โ€“ C:\WINDOWS\system32\drivers\aswTdi.sys โ€“ (aswTdi)
DRV - [2010/06/28 16:37:30 | 000,165,456 | โ€”- | M] (ALWIL Software) [Kernel | System | Running] โ€“ C:\WINDOWS\system32\drivers\aswSP.sys โ€“ (aswSP)
DRV - [2010/06/28 16:33:13 | 000,023,376 | โ€”- | M] (ALWIL Software) [Kernel | On_Demand | Running] โ€“ C:\WINDOWS\system32\drivers\aswRdr.sys โ€“ (aswRdr)
DRV - [2010/06/28 16:32:45 | 000,100,176 | โ€”- | M] (ALWIL Software) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\drivers\aswmon2.sys โ€“ (aswMon2)
DRV - [2010/06/28 16:32:33 | 000,017,744 | โ€”- | M] (ALWIL Software) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\drivers\aswFsBlk.sys โ€“ (aswFsBlk)
DRV - [2010/06/28 16:32:16 | 000,028,880 | โ€”- | M] (ALWIL Software) [Kernel | System | Running] โ€“ C:\WINDOWS\system32\drivers\aavmker4.sys โ€“ (Aavmker4)
DRV - [2010/06/18 22:14:04 | 000,064,288 | โ€”- | M] (Lavasoft AB) [File_System | Boot | Running] โ€“ C:\WINDOWS\system32\DRIVERS\Lbd.sys โ€“ (Lbd)
DRV - [2010/06/03 22:19:53 | 000,441,760 | โ€”- | M] (Acronis) [Kernel | Boot | Running] โ€“ C:\WINDOWS\system32\DRIVERS\timntr.sys โ€“ (timounter)
DRV - [2010/06/03 22:19:53 | 000,044,384 | โ€”- | M] (Acronis) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\drivers\tifsfilt.sys โ€“ (tifsfilter)
DRV - [2010/06/03 22:19:49 | 000,132,224 | โ€”- | M] (Acronis) [Kernel | Boot | Running] โ€“ C:\WINDOWS\system32\DRIVERS\snapman.sys โ€“ (snapman)
DRV - [2010/06/03 22:19:44 | 000,368,480 | โ€”- | M] (Acronis) [Kernel | Boot | Running] โ€“ C:\WINDOWS\system32\DRIVERS\tdrpman.sys โ€“ (tdrpman)
DRV - [2010/05/13 10:02:32 | 000,532,224 | โ€”- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] โ€“ C:\WINDOWS\system32\vsdatant.sys โ€“ (vsdatant)
DRV - [2010/03/10 17:25:58 | 000,020,968 | โ€”- | M] (Windows ยฎ Win 7 DDK provider) [Kernel | Auto | Running] โ€“ C:\WINDOWS\system32\drivers\cpuz133_x32.sys โ€“ (cpuz133)
DRV - [2009/05/09 01:14:20 | 000,014,736 | โ€”- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] โ€“ C:\WINDOWS\system32\drivers\nuidfltr.sys โ€“ (NuidFltr)
DRV - [2008/04/13 14:36:39 | 000,043,008 | โ€”- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\amdagp.sys โ€“ (amdagp)
DRV - [2008/04/13 14:36:39 | 000,040,960 | โ€”- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\sisagp.sys โ€“ (sisagp)
DRV - [2008/04/13 12:36:05 | 000,144,384 | โ€”- | M] (Windows ยฎ Server 2003 DDK provider) [Kernel | On_Demand | Running] โ€“ C:\WINDOWS\system32\drivers\hdaudbus.sys โ€“ (HDAudBus)
DRV - [2007/07/12 17:35:02 | 000,305,176 | โ€”- | M] (Intel Corporation) [Kernel | Boot | Running] โ€“ C:\WINDOWS\system32\drivers\iaStor.sys โ€“ (iaStor)
DRV - [2007/06/26 16:06:20 | 000,254,872 | โ€”- | M] (Intel Corporation) [Kernel | On_Demand | Running] โ€“ C:\WINDOWS\system32\drivers\e1e5132.sys โ€“ (e1express) Intelยฎ
DRV - [2007/05/02 16:21:22 | 004,403,712 | โ€”- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] โ€“ C:\WINDOWS\system32\drivers\RtkHDAud.sys โ€“ (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/04/16 21:16:26 | 005,760,096 | โ€”- | M] (Intel Corporation) [Kernel | On_Demand | Running] โ€“ C:\WINDOWS\system32\drivers\igxpmp32.sys โ€“ (ialm)
DRV - [2007/02/25 13:10:48 | 000,005,376 | โ€“S- | M] (Gteko Ltd.) [Kernel | Auto | Running] โ€“ C:\WINDOWS\system32\drivers\dsunidrv.sys โ€“ (dsunidrv)
DRV - [2006/12/18 20:01:20 | 000,012,672 | โ€”- | M] (SingleClick Systems) [Kernel | Auto | Running] โ€“ C:\WINDOWS\system32\drivers\packet.sys โ€“ (Packet)
DRV - [2006/10/05 18:07:28 | 000,004,736 | โ€”- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] โ€“ C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys โ€“ (DSproct)
DRV - [2006/08/18 14:18:08 | 000,009,400 | โ€”- | M] (Roxio) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\DLA\DLADResM.SYS โ€“ (DLADResM)
DRV - [2006/08/18 14:17:46 | 000,035,096 | โ€”- | M] (Roxio) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\DLA\DLABMFSM.SYS โ€“ (DLABMFSM)
DRV - [2006/08/18 14:17:44 | 000,097,848 | โ€”- | M] (Roxio) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\DLA\DLAUDF_M.SYS โ€“ (DLAUDF_M)
DRV - [2006/08/18 14:17:44 | 000,094,648 | โ€”- | M] (Roxio) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\DLA\DLAUDFAM.SYS โ€“ (DLAUDFAM)
DRV - [2006/08/18 14:17:42 | 000,026,008 | โ€”- | M] (Roxio) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\DLA\DLAOPIOM.SYS โ€“ (DLAOPIOM)
DRV - [2006/08/18 14:17:40 | 000,032,472 | โ€”- | M] (Roxio) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\DLA\DLABOIOM.SYS โ€“ (DLABOIOM)
DRV - [2006/08/18 14:17:38 | 000,104,472 | โ€”- | M] (Roxio) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\DLA\DLAIFS_M.SYS โ€“ (DLAIFS_M)
DRV - [2006/08/18 14:17:38 | 000,014,520 | โ€”- | M] (Roxio) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\DLA\DLAPoolM.SYS โ€“ (DLAPoolM)
DRV - [2006/08/11 12:05:58 | 000,051,768 | โ€”- | M] (Roxio) [File_System | Auto | Running] โ€“ C:\WINDOWS\system32\drivers\DRVNDDM.SYS โ€“ (DRVNDDM)
DRV - [2006/08/11 11:35:18 | 000,012,920 | โ€”- | M] (Roxio) [File_System | System | Running] โ€“ C:\WINDOWS\system32\drivers\DLACDBHM.SYS โ€“ (DLACDBHM)
DRV - [2006/08/11 11:35:16 | 000,028,184 | โ€”- | M] (Roxio) [File_System | System | Running] โ€“ C:\WINDOWS\system32\drivers\DLARTL_M.SYS โ€“ (DLARTL_M)
DRV - [2006/07/21 12:21:26 | 000,099,176 | โ€”- | M] (Sonic Solutions) [Kernel | Boot | Running] โ€“ C:\WINDOWS\System32\Drivers\DRVMCDB.SYS โ€“ (DRVMCDB)
DRV - [2004/08/04 06:00:00 | 000,179,584 | โ€”- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\dac2w2k.sys โ€“ (dac2w2k)
DRV - [2004/08/04 06:00:00 | 000,049,024 | โ€”- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\ql1280.sys โ€“ (ql1280)
DRV - [2004/08/04 06:00:00 | 000,045,312 | โ€”- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\ql12160.sys โ€“ (ql12160)
DRV - [2004/08/04 06:00:00 | 000,040,320 | โ€”- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\ql1080.sys โ€“ (ql1080)
DRV - [2004/08/04 06:00:00 | 000,036,736 | โ€”- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\ultra.sys โ€“ (ultra)
DRV - [2004/08/04 06:00:00 | 000,032,640 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\symc8xx.sys โ€“ (symc8xx)
DRV - [2004/08/04 06:00:00 | 000,030,688 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\sym_u3.sys โ€“ (sym_u3)
DRV - [2004/08/04 06:00:00 | 000,028,384 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\sym_hi.sys โ€“ (sym_hi)
DRV - [2004/08/04 06:00:00 | 000,026,496 | โ€”- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\asc.sys โ€“ (asc)
DRV - [2004/08/04 06:00:00 | 000,019,072 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\sparrow.sys โ€“ (Sparrow)
DRV - [2004/08/04 06:00:00 | 000,017,280 | โ€”- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\mraid35x.sys โ€“ (mraid35x)
DRV - [2004/08/04 06:00:00 | 000,016,256 | โ€”- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\symc810.sys โ€“ (symc810)
DRV - [2004/08/04 06:00:00 | 000,014,848 | โ€”- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\asc3550.sys โ€“ (asc3550)
DRV - [2004/08/04 06:00:00 | 000,006,656 | โ€”- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\cmdide.sys โ€“ (CmdIde)
DRV - [2004/08/04 06:00:00 | 000,005,248 | โ€”- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] โ€“ C:\WINDOWS\system32\DRIVERS\aliide.sys โ€“ (AliIde)
DRV - [2004/08/04 00:29:56 | 001,897,408 | โ€”- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] โ€“ C:\WINDOWS\system32\drivers\nv4_mini.sys โ€“ (nv)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071101
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071101

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2071101
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTermโ€ฆtf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2008/12/19 23:20:53 | 000,292,068 | Rโ€” | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 babe.the-killer.bz
O1 - Hosts: 127.0.0.1 www.babe.the-killer.bz
O1 - Hosts: 127.0.0.1 babe.k-lined.com
O1 - Hosts: 127.0.0.1 www.babe.k-lined.com
O1 - Hosts: 127.0.0.1 did.i-used.cc
O1 - Hosts: 127.0.0.1 www.did.i-used.cc
O1 - Hosts: 127.0.0.1 coolwwwsearch.com
O1 - Hosts: 127.0.0.1 www.coolwwwsearch.com
O1 - Hosts: 127.0.0.1 coolwebsearch.com
O1 - Hosts: 127.0.0.1 www.coolwebsearch.com
O1 - Hosts: 127.0.0.1 hi.studioaperto.net
O1 - Hosts: 127.0.0.1 www.hi.studioaperto.net
O1 - Hosts: 127.0.0.1 webbrowser.tv
O1 - Hosts: 127.0.0.1 www.webbrowser.tv
O1 - Hosts: 127.0.0.1 wazzupnet.com
O1 - Hosts: 127.0.0.1 www.wazzupnet.com
O1 - Hosts: 127.0.0.1 gueb.com
O1 - Hosts: 127.0.0.1 www.gueb.com
O1 - Hosts: 127.0.0.1 kabex.com
O1 - Hosts: 127.0.0.1 www.kabex.com
O1 - Hosts: 127.0.0.1 hityou.com
O1 - Hosts: 127.0.0.1 www.hityou.com
O1 - Hosts: 127.0.0.1 miosearch.com
O1 - Hosts: 127.0.0.1 www.miosearch.com
O1 - Hosts: 10059 more linesโ€ฆ
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = [binary data]
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7โ€ฆ/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdatโ€ฆb?1275269510203 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdatโ€ฆb?1275269498796 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shocโ€ฆash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Rich\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Rich\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 19:15:00 | 000,000,000 | โ€”- | M] () - C:\AUTOEXEC.BAT โ€“ [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008/12/19 17:35:35 | 000,000,000 | โ€”D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56590081070202880)

========== Files/Folders - Created Within 90 Days ==========

[2010/06/29 14:34:44 | 000,574,464 | โ€”- | C] (OldTimer Tools) โ€“ C:\Documents and Settings\Rich\Desktop\OTL.exe
[2010/06/29 09:24:57 | 000,000,000 | -HSD | C] โ€“ C:\Documents and Settings\Rich\IECompatCache
[2010/06/29 09:17:58 | 000,038,848 | โ€”- | C] (ALWIL Software) โ€“ C:\WINDOWS\avastSS.scr
[2010/06/28 19:00:13 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Rich\Application Data\Research In Motion
[2010/06/28 18:40:07 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Common Files\Research In Motion
[2010/06/28 18:40:02 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Research In Motion
[2010/06/23 19:27:08 | 000,000,000 | -HSD | C] โ€“ C:\Documents and Settings\Rich\PrivacIE
[2010/06/23 19:22:32 | 000,000,000 | -HSD | C] โ€“ C:\Documents and Settings\Rich\IETldCache
[2010/06/23 19:18:12 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\ie8updates
[2010/06/23 19:10:56 | 000,000,000 | -H-D | C] โ€“ C:\WINDOWS\ie8
[2010/06/22 20:26:51 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Rich\Application Data\FastStone
[2010/06/22 20:26:42 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\FastStone Image Viewer
[2010/06/22 20:17:26 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\IrfanView
[2010/06/22 20:08:57 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\NOS
[2010/06/22 20:08:57 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\NOS
[2010/06/22 19:58:00 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Common Files\Adobe AIR
[2010/06/22 19:47:18 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Rich\Application Data\GrabPro
[2010/06/22 19:47:18 | 000,000,000 | โ€”D | C] โ€“ C:\downloads
[2010/06/22 19:47:15 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Orbitdownloader
[2010/06/22 19:47:15 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Rich\Application Data\Orbit
[2010/06/18 22:14:46 | 000,064,288 | โ€”- | C] (Lavasoft AB) โ€“ C:\WINDOWS\System32\drivers\Lbd.sys
[2010/06/18 22:14:42 | 000,095,024 | โ€”- | C] (Sunbelt Software) โ€“ C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/06/18 22:09:02 | 000,000,000 | -H-D | C] โ€“ C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/06/15 22:21:39 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\TweakNow PowerPack 2010
[2010/06/15 22:21:39 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Rich\Application Data\TweakNow PowerPack 2010
[2010/06/12 03:19:53 | 000,020,968 | โ€”- | C] (Windows ยฎ Win 7 DDK provider) โ€“ C:\WINDOWS\System32\drivers\cpuz133_x32.sys
[2010/06/12 03:19:52 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\CPUID
[2010/06/05 15:51:26 | 000,000,000 | โ€”D | C] โ€“ C:\Intel
[2010/06/05 15:32:08 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Realtek
[2010/06/05 15:22:13 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/06/05 15:21:36 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Common Files\supportsoft
[2010/06/05 15:21:36 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Dell Support Center
[2010/06/05 15:11:17 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Rich\Local Settings\Application Data\Deployment
[2010/06/05 15:00:08 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\Dell
[2010/06/03 22:19:57 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Seagate
[2010/06/03 22:19:22 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Seagate
[2010/06/03 22:19:22 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Common Files\Seagate
[2010/06/03 20:27:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\NtmsData
[2010/06/03 20:02:59 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\Minidump
[2010/06/01 21:22:43 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Rich\Application Data\Office Genuine Advantage
[2010/05/30 22:32:50 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/05/30 22:32:46 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\PCPitstop
[2010/05/30 22:21:54 | 000,000,000 | โ€”D | C] โ€“ C:\ViewSonic
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\zh-TW
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\zh-HK
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\tr-TR
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\sv-SE
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\pt-BR
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\nl-NL
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\nb-NO
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\ko-KR
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\it-IT
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\he-IL
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\fr-FR
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\fi-FI
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\es-ES
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\el-GR
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\de-DE
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\da-DK
[2010/05/30 21:47:09 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\ar-SA
[2010/05/30 21:27:09 | 000,165,456 | โ€”- | C] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswSP.sys
[2010/05/30 21:27:09 | 000,017,744 | โ€”- | C] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/05/30 21:27:08 | 000,023,376 | โ€”- | C] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/05/30 21:27:06 | 000,046,672 | โ€”- | C] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/05/30 21:27:04 | 000,100,176 | โ€”- | C] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/05/30 21:27:04 | 000,094,544 | โ€”- | C] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswmon.sys
[2010/05/30 21:27:04 | 000,028,880 | โ€”- | C] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/05/30 21:26:46 | 000,165,032 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\aswBoot.exe
[2010/05/30 21:26:40 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/05/30 21:18:33 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Rich\My Documents\ForceField Shared Files
[2010/05/30 21:18:32 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Rich\Application Data\CheckPoint
[2010/05/30 21:18:10 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\CheckPoint
[2010/05/30 21:17:59 | 000,000,000 | โ€”D | C] โ€“ C:\WINDOWS\System32\ZoneLabs
[2010/05/30 21:17:57 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Zone Labs
[2010/05/30 20:29:48 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Geek Squad
[2010/05/30 13:18:42 | 000,000,000 | โ€”D | C] โ€“ C:\655edc36a587a73027e2d8bfb27c
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/06/29 14:35:02 | 000,574,464 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Rich\Desktop\OTL.exe
[2010/06/29 09:35:05 | 000,359,929 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\Desktop\dds.scr
[2010/06/29 09:23:27 | 000,000,472 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/06/29 09:21:36 | 000,013,702 | โ€”- | M] () โ€“ C:\WINDOWS\System32\wpa.dbl
[2010/06/29 09:19:17 | 000,000,236 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\OGALogon.job
[2010/06/29 09:19:15 | 000,000,006 | -Hโ€“ | M] () โ€“ C:\WINDOWS\tasks\SA.DAT
[2010/06/29 09:18:57 | 000,002,048 | โ€“S- | M] () โ€“ C:\WINDOWS\bootstat.dat
[2010/06/29 09:18:15 | 006,029,312 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\ntuser.dat
[2010/06/29 09:18:15 | 000,000,278 | -HS- | M] () โ€“ C:\Documents and Settings\Rich\ntuser.ini
[2010/06/29 09:18:01 | 000,002,626 | โ€”- | M] () โ€“ C:\WINDOWS\System32\CONFIG.NT
[2010/06/29 09:11:41 | 000,000,603 | โ€”- | M] () โ€“ C:\WINDOWS\win.ini
[2010/06/29 09:11:41 | 000,000,227 | โ€”- | M] () โ€“ C:\WINDOWS\system.ini
[2010/06/29 09:11:41 | 000,000,211 | -HS- | M] () โ€“ C:\boot.ini
[2010/06/29 08:48:56 | 000,000,256 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\pool.bin
[2010/06/28 19:19:37 | 000,000,256 | โ€”- | M] () โ€“ C:\WINDOWS\System32\pool.bin
[2010/06/28 19:17:31 | 004,589,510 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\My Documents\Backup-(2010-06-28)-1.ipd
[2010/06/28 19:05:47 | 004,589,510 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\My Documents\Backup-(2010-06-28).ipd
[2010/06/28 18:55:16 | 000,287,704 | โ€”- | M] () โ€“ C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/28 18:40:32 | 000,001,729 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Desktop Manager.lnk
[2010/06/28 16:57:33 | 000,038,848 | โ€”- | M] (ALWIL Software) โ€“ C:\WINDOWS\avastSS.scr
[2010/06/28 16:57:12 | 000,165,032 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\aswBoot.exe
[2010/06/28 16:37:52 | 000,046,672 | โ€”- | M] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/06/28 16:37:30 | 000,165,456 | โ€”- | M] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswSP.sys
[2010/06/28 16:33:13 | 000,023,376 | โ€”- | M] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/06/28 16:32:45 | 000,100,176 | โ€”- | M] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/06/28 16:32:42 | 000,094,544 | โ€”- | M] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswmon.sys
[2010/06/28 16:32:33 | 000,017,744 | โ€”- | M] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/06/28 16:32:16 | 000,028,880 | โ€”- | M] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/06/26 09:30:16 | 000,047,616 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\My Documents\June 26.doc
[2010/06/25 20:36:03 | 000,121,344 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\My Documents\Return Policy.doc
[2010/06/25 19:14:50 | 000,000,000 | โ€”- | M] () โ€“ C:\WINDOWS\System32\null
[2010/06/25 17:35:58 | 000,001,729 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/06/24 17:51:29 | 000,001,374 | โ€”- | M] () โ€“ C:\WINDOWS\imsins.BAK
[2010/06/23 20:28:17 | 000,000,804 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/06/23 19:22:37 | 000,000,815 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/06/22 20:26:43 | 000,000,780 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\FastStone Image Viewer.lnk
[2010/06/22 20:17:26 | 000,000,685 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\IrfanView.lnk
[2010/06/22 19:47:16 | 000,000,726 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\Desktop\Orbit.lnk
[2010/06/22 18:54:02 | 000,020,992 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\My Documents\Remember.doc
[2010/06/22 18:06:05 | 000,554,474 | โ€”- | M] () โ€“ C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/22 18:06:05 | 000,477,848 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfh009.dat
[2010/06/22 18:06:05 | 000,086,144 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfc009.dat
[2010/06/21 20:44:06 | 000,020,480 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\My Documents\Smith & Wesson Model 5906, 9mm,.doc
[2010/06/19 17:36:58 | 000,000,568 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.zip
[2010/06/18 22:14:38 | 000,095,024 | โ€”- | M] (Sunbelt Software) โ€“ C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/06/18 22:14:35 | 000,015,880 | โ€”- | M] () โ€“ C:\WINDOWS\System32\lsdelete.exe
[2010/06/18 22:14:04 | 000,064,288 | โ€”- | M] (Lavasoft AB) โ€“ C:\WINDOWS\System32\drivers\Lbd.sys
[2010/06/18 22:09:01 | 000,000,885 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/06/18 22:09:01 | 000,000,867 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/06/15 22:21:42 | 000,000,792 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\TweakNow PowerPack 2010.lnk
[2010/06/13 15:35:41 | 000,002,469 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/06/12 03:19:53 | 000,000,717 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\CPUID CPU-Z.lnk
[2010/06/09 19:02:28 | 006,422,936 | -Hโ€“ | M] () โ€“ C:\Documents and Settings\Rich\Local Settings\Application Data\IconCache.db
[2010/06/05 15:56:29 | 000,000,005 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\DELL_XPS_Vostro 200.MRK
[2010/06/05 15:56:29 | 000,000,005 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\1028_DELL_XPS_Vostro 200.MRK
[2010/06/03 22:19:43 | 000,000,808 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Seagate DiscWizard.lnk
[2010/06/03 22:15:15 | 000,029,512 | โ€”- | M] () โ€“ C:\WINDOWSSerifastd-black.otf
[2010/06/03 22:15:15 | 000,028,260 | โ€”- | M] () โ€“ C:\WINDOWSSerifastd-lightitalic.otf
[2010/06/03 22:15:15 | 000,028,252 | โ€”- | M] () โ€“ C:\WINDOWSSerifastd-italic.otf
[2010/06/03 22:15:15 | 000,027,772 | โ€”- | M] () โ€“ C:\WINDOWSSerifastd-bold.otf
[2010/06/03 22:15:15 | 000,027,452 | โ€”- | M] () โ€“ C:\WINDOWSSerifastd-roman.otf
[2010/06/03 22:15:15 | 000,027,440 | โ€”- | M] () โ€“ C:\WINDOWSSerifastd-light.otf
[2010/05/30 21:27:10 | 000,001,700 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/05/30 21:18:56 | 000,421,442 | โ€”- | M] () โ€“ C:\WINDOWS\System32\vsconfig.xml
[2010/05/30 21:18:09 | 000,004,212 | -Hโ€“ | M] () โ€“ C:\WINDOWS\System32\zllictbl.dat
[2010/05/30 21:18:09 | 000,000,731 | โ€”- | M] () โ€“ C:\Documents and Settings\Rich\Desktop\ZoneAlarm Security.lnk
[2010/05/29 03:08:16 | 000,000,000 | -Hโ€“ | M] () โ€“ C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2010/05/29 03:08:14 | 000,000,000 | -Hโ€“ | M] () โ€“ C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/29 09:35:00 | 000,359,929 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\Desktop\dds.scr
[2010/06/29 08:48:56 | 000,000,256 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\pool.bin
[2010/06/28 19:17:31 | 004,589,510 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\My Documents\Backup-(2010-06-28)-1.ipd
[2010/06/28 19:05:47 | 004,589,510 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\My Documents\Backup-(2010-06-28).ipd
[2010/06/28 19:00:17 | 000,000,256 | โ€”- | C] () โ€“ C:\WINDOWS\System32\pool.bin
[2010/06/28 18:40:32 | 000,001,729 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Desktop Manager.lnk
[2010/06/26 09:30:16 | 000,047,616 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\My Documents\June 26.doc
[2010/06/25 20:36:02 | 000,121,344 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\My Documents\Return Policy.doc
[2010/06/25 17:35:58 | 000,001,729 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/06/22 20:26:43 | 000,000,780 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\FastStone Image Viewer.lnk
[2010/06/22 20:17:26 | 000,000,685 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\IrfanView.lnk
[2010/06/22 19:47:16 | 000,000,726 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\Desktop\Orbit.lnk
[2010/06/22 18:54:02 | 000,020,992 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\My Documents\Remember.doc
[2010/06/20 21:35:14 | 000,020,480 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\My Documents\Smith & Wesson Model 5906, 9mm,.doc
[2010/06/19 17:36:58 | 000,000,568 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.zip
[2010/06/19 17:29:09 | 000,015,880 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lsdelete.exe
[2010/06/18 22:19:52 | 000,000,472 | โ€”- | C] () โ€“ C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/06/18 22:09:01 | 000,000,885 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/06/18 22:09:01 | 000,000,867 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/06/15 22:21:42 | 000,000,792 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\TweakNow PowerPack 2010.lnk
[2010/06/12 03:19:53 | 000,000,717 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\CPUID CPU-Z.lnk
[2010/06/05 15:56:29 | 000,000,005 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\DELL_XPS_Vostro 200.MRK
[2010/06/05 15:56:29 | 000,000,005 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\1028_DELL_XPS_Vostro 200.MRK
[2010/06/05 15:32:58 | 000,049,152 | โ€”- | C] () โ€“ C:\WINDOWS\System32\ChCfg.exe
[2010/06/05 15:25:28 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\System32\null
[2010/06/05 15:21:50 | 000,002,469 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2010/06/03 22:19:43 | 000,000,808 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Seagate DiscWizard.lnk
[2010/06/03 22:15:15 | 000,029,512 | โ€”- | C] () โ€“ C:\WINDOWSSerifastd-black.otf
[2010/06/03 22:15:15 | 000,028,260 | โ€”- | C] () โ€“ C:\WINDOWSSerifastd-lightitalic.otf
[2010/06/03 22:15:15 | 000,028,252 | โ€”- | C] () โ€“ C:\WINDOWSSerifastd-italic.otf
[2010/06/03 22:15:15 | 000,027,772 | โ€”- | C] () โ€“ C:\WINDOWSSerifastd-bold.otf
[2010/06/03 22:15:15 | 000,027,452 | โ€”- | C] () โ€“ C:\WINDOWSSerifastd-roman.otf
[2010/06/03 22:15:15 | 000,027,440 | โ€”- | C] () โ€“ C:\WINDOWSSerifastd-light.otf
[2010/06/03 20:44:36 | 000,160,217 | โ€”- | C] () โ€“ C:\WINDOWS\System32\PowerToysLicense.rtf
[2010/05/30 21:47:10 | 000,000,236 | โ€”- | C] () โ€“ C:\WINDOWS\tasks\OGALogon.job
[2010/05/30 21:27:10 | 000,001,700 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/05/30 21:18:09 | 000,000,731 | โ€”- | C] () โ€“ C:\Documents and Settings\Rich\Desktop\ZoneAlarm Security.lnk
[2010/05/30 21:17:58 | 000,421,442 | โ€”- | C] () โ€“ C:\WINDOWS\System32\vsconfig.xml
[2010/05/30 20:29:37 | 000,262,144 | -Hโ€“ | C] () โ€“ C:\Documents and Settings\Rich\ntuser.dat.LOG1
[2010/05/30 20:29:37 | 000,000,000 | -Hโ€“ | C] () โ€“ C:\Documents and Settings\Rich\ntuser.dat.LOG2
[2010/05/29 03:08:16 | 000,000,000 | -Hโ€“ | C] () โ€“ C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2010/05/29 03:08:14 | 000,000,000 | -Hโ€“ | C] () โ€“ C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2009/08/03 15:07:42 | 000,403,816 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OGACheckControl.dll
[2008/03/12 08:56:41 | 000,000,102 | โ€”- | C] () โ€“ C:\WINDOWS\VSWizard.ini
[2007/12/14 09:40:10 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\VPC32.INI
[2007/11/07 10:57:00 | 000,000,376 | โ€”- | C] () โ€“ C:\WINDOWS\ODBC.INI
[2007/11/01 13:12:21 | 000,000,061 | โ€”- | C] () โ€“ C:\WINDOWS\smscfg.ini
[2007/11/01 13:01:12 | 000,056,056 | โ€”- | C] () โ€“ C:\WINDOWS\System32\DLAAPI_W.DLL
[2007/11/01 13:01:12 | 000,000,120 | โ€”- | C] () โ€“ C:\WINDOWS\wininit.ini
[2007/11/01 12:35:43 | 000,204,800 | โ€”- | C] () โ€“ C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2007/11/01 12:34:23 | 000,001,032 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OEMINFO.INI
[2006/11/07 06:25:58 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\System32\px.ini
[2006/09/17 00:36:50 | 000,520,192 | โ€”- | C] () โ€“ C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/17 00:36:50 | 000,204,800 | โ€”- | C] () โ€“ C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2004/08/11 19:24:19 | 000,000,791 | โ€”- | C] () โ€“ C:\WINDOWS\orun32.ini
[2004/08/11 19:11:31 | 000,001,793 | โ€”- | C] () โ€“ C:\WINDOWS\System32\fxsperf.ini
[2004/08/04 06:00:00 | 000,755,200 | โ€”- | C] () โ€“ C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 06:00:00 | 000,338,432 | โ€”- | C] () โ€“ C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 06:00:00 | 000,200,192 | โ€”- | C] () โ€“ C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 06:00:00 | 000,183,808 | โ€”- | C] () โ€“ C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 06:00:00 | 000,120,320 | โ€”- | C] () โ€“ C:\WINDOWS\System32\ir41_qc.dll
[2003/01/07 03:05:08 | 000,002,695 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OUTLPERF.INI
[1999/01/22 14:46:56 | 000,065,536 | โ€”- | C] () โ€“ C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 04:00:00 | 000,040,448 | โ€”- | C] () โ€“ C:\WINDOWS\System32\REGOBJ.DLL

========== LOP Check ==========

[2010/05/30 21:26:40 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Alwil Software
[2007/12/26 12:02:29 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Avery
[2007/12/13 15:11:57 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Citrix
[2010/05/30 20:29:48 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Geek Squad
[2007/12/14 09:16:01 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Grisoft(2)
[2010/06/29 09:07:22 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\PCPitstop
[2007/11/07 11:00:47 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\SBT
[2010/06/03 22:19:57 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Seagate
[2007/11/01 13:08:24 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\SingleClick Systems
[2010/06/05 15:22:13 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/12/14 09:35:10 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/18 22:09:04 | 000,000,000 | -H-D | M] โ€“ C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/05/30 21:18:32 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Rich\Application Data\CheckPoint
[2010/06/22 19:47:18 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Rich\Application Data\GrabPro
[2008/03/12 08:57:20 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Rich\Application Data\Leadertech
[2007/12/14 09:14:34 | 000,000,000 | -H-D | M] โ€“ C:\Documents and Settings\Rich\Application Data\LogMeIn Rescue Calling Card
[2007/12/29 09:33:28 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Rich\Application Data\OfficeUpdate12
[2010/06/23 19:26:46 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Rich\Application Data\Orbit
[2010/06/28 19:00:13 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Rich\Application Data\Research In Motion
[2010/06/15 22:21:39 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Rich\Application Data\TweakNow PowerPack 2010
[2010/06/29 09:23:27 | 000,000,472 | โ€”- | M] () โ€“ C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/06/29 09:19:17 | 000,000,236 | โ€”- | M] () โ€“ C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 07:00:00 | 018,738,937 | โ€”- | M] () .cab file โ€“ C:\i386\sp2.cab:AGP440.sys
[2004/08/04 06:00:00 | 018,738,937 | โ€”- | M] () .cab file โ€“ C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/12/19 22:21:23 | 023,852,652 | โ€”- | M] () .cab file โ€“ C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/12/19 22:21:23 | 023,852,652 | โ€”- | M] () .cab file โ€“ C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | โ€”- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 โ€“ C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | โ€”- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 โ€“ C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 01:07:42 | 000,042,368 | โ€”- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB โ€“ C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 07:00:00 | 018,738,937 | โ€”- | M] () .cab file โ€“ C:\i386\sp2.cab:atapi.sys
[2004/08/04 06:00:00 | 018,738,937 | โ€”- | M] () .cab file โ€“ C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/12/19 22:21:23 | 023,852,652 | โ€”- | M] () .cab file โ€“ C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/12/19 22:21:23 | 023,852,652 | โ€”- | M] () .cab file โ€“ C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2006/08/28 04:02:10 | 000,095,872 | โ€”- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 โ€“ C:\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | โ€”- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 โ€“ C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | โ€”- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 โ€“ C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 06:00:00 | 000,095,360 | โ€”- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 โ€“ C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | โ€”- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 โ€“ C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | โ€”- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 โ€“ C:\WINDOWS\system32\eventlog.dll
[2004/08/04 06:00:00 | 000,055,808 | โ€”- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 โ€“ C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2007/07/12 17:35:02 | 000,305,176 | โ€”- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 โ€“ C:\WINDOWS\dell\iastor\iastor.sys
[2007/07/12 17:35:02 | 000,305,176 | โ€”- | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 โ€“ C:\WINDOWS\system32\drivers\iastor.sys
[2007/06/13 21:25:14 | 000,304,920 | โ€”- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 โ€“ C:\drivers\storage\R158515\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | โ€”- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 โ€“ C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | โ€”- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 โ€“ C:\WINDOWS\system32\netlogon.dll
[2004/08/04 06:00:00 | 000,407,040 | โ€”- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A โ€“ C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: NVATA.SYS >
[2006/10/18 18:31:38 | 000,105,472 | โ€”- | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A โ€“ C:\WINDOWS\dell\nvraid\nvata.sys

< MD5 for: NVATABUS.SYS >
[2006/10/18 17:31:38 | 000,105,472 | โ€”- | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A โ€“ C:\WINDOWS\dell\nvraid\NvAtaBus.sys

< MD5 for: SCECLI.DLL >
[2004/08/04 06:00:00 | 000,180,224 | โ€”- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A โ€“ C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | โ€”- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 โ€“ C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | โ€”- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 โ€“ C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794
< End of report >







OTL Extras logfile created on: 6/29/2010 2:35:47 PM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\Rich\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): c:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.45 Gb Total Space | 58.90 Gb Free Space | 79.11% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 465.76 Gb Total Space | 456.89 Gb Free Space | 98.10% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DF5141F1
Current User Name: Rich
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ€“ "%1" %*
cmdfile [open] โ€“ "%1" %*
comfile [open] โ€“ "%1" %*
exefile [open] โ€“ "%1" %*
htmlfile โ€“ "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] โ€“ "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] โ€“ "%1" %*
regfile [merge] โ€“ Reg Error: Key error.
scrfile [config] โ€“ "%1"
scrfile [install] โ€“ rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] โ€“ "%1" /S
txtfile โ€“ Reg Error: Key error.
Unknown [openas] โ€“ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with FastStone] โ€“ "C:\Program Files\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] โ€“ %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] โ€“ %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10421:UDP" = 10421:UDP:*:Enabled:SingleClick Discovery Protocol
"10426:UDP" = 10426:UDP:*:Enabled:SingleClick ICC

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Dell Network Assistant\ezi_hnm2.exe" = C:\Program Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Dell Network Assistant โ€“ (SingleClick Systems)
"C:\WINDOWS\LMI36.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI36.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue โ€“ File not found
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon โ€“ (Check Point Software Technologies LTD)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit โ€“ (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit โ€“ (Orbitdownloader.com)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Disc 2
"{0240BDFB-2995-4A3F-8C96-18D41282B716}" = Dell Network Assistant
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = QualxServ Service Agreement
"{1EBB57D4-63FF-87CC-A0F0-D73982CF6008}" = Adobe Media Player
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{281ECE39-F043-492B-8337-F2E546B5604A}" = PowerDVD
"{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}" = Dell DataSafe Online
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Javaโ„ข 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Javaโ„ข 6 Update 5
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{51BA0AFE-6AA5-4B8C-8BA9-FA6AE5B1EEE0}" = Roxio Media Manager
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intelยฎ PRO Network Connections [removed]
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{97AE00A8-1336-410F-B467-1C6623127BD6}" = DesignPro 5.0 Limited Edition
"{98DC111A-7C22-4C26-B2A1-E654264DAC1E}" = BlackBerry Desktop Software 4.7
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43E4B9C-14C8-4EB0-998B-85211B6EDD61}" = Seagate DiscWizard
"{C680AD48-AA56-4AF2-B75A-CB3BA851E737}" = PaperSolve Support
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{FC47C7A5-BE63-11D5-B7C9-005004566E4D}" = ViewSonic Windows XP x64 Signed Files
"Ad-Aware" = Ad-Aware
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"avast5" = avast! Free Antivirus
"BlackBerry_{98DC111A-7C22-4C26-B2A1-E654264DAC1E}" = BlackBerry Desktop Software 4.7
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.54
"FastStone Image Viewer" = FastStone Image Viewer 4.2
"HDMI" = Intelยฎ Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{97AE00A8-1336-410F-B467-1C6623127BD6}" = DesignPro 5.0 Limited Edition
"IrfanView" = IrfanView (remove only)
"LiveUpdate" = LiveUpdate 3.1 (Symantec Corporation)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Orbit_is1" = Orbit Downloader
"PC Pitstop Optimize3_is1" = PC Pitstop Optimize3 3.0
"SearchAssist" = SearchAssist
"Tweak UI 2.10" = Tweak UI
"TweakNow PowerPack 2010_is1" = TweakNow PowerPack 2010
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZoneAlarm" = ZoneAlarm

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/18/2008 3:33:25 PM | Computer Name = DF5141F1 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16640, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/13/2008 12:50:46 PM | Computer Name = DF5141F1 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16640, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/16/2008 10:09:59 AM | Computer Name = DF5141F1 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16640, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/18/2008 7:01:33 PM | Computer Name = DF5141F1 | Source = MsiInstaller | ID = 1008
Description = The installation of D:\ipoint\Setup\IP50.msi is not permitted due
to an error in software restriction policy processing. The object cannot be trusted.

Error - 12/18/2008 7:02:51 PM | Computer Name = DF5141F1 | Source = MsiInstaller | ID = 1008
Description = The installation of D:\ipoint\Setup\IP50.msi is not permitted due
to an error in software restriction policy processing. The object cannot be trusted.

Error - 12/18/2008 10:38:35 PM | Computer Name = DF5141F1 | Source = MsiInstaller | ID = 1008
Description = The installation of D:\ipoint\Setup\IP50.msi is not permitted due
to an error in software restriction policy processing. The object cannot be trusted.

Error - 5/30/2010 9:25:56 PM | Computer Name = DF5141F1 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 5/30/2010 9:25:56 PM | Computer Name = DF5141F1 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 6/2/2010 9:28:46 PM | Computer Name = DF5141F1 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17023, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/2/2010 9:29:04 PM | Computer Name = DF5141F1 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17023, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 6/9/2010 3:18:51 PM | Computer Name = DF5141F1 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.15.3 for the Network Card with network
address 001AA09EA8E0 has been denied by the DHCP server 192.168.15.1 (The DHCP Server
sent a DHCPNACK message).

Error - 6/9/2010 3:39:47 PM | Computer Name = DF5141F1 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.15.3 for the Network Card with network
address 001AA09EA8E0 has been denied by the DHCP server 192.168.15.1 (The DHCP Server
sent a DHCPNACK message).

Error - 6/9/2010 4:00:41 PM | Computer Name = DF5141F1 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.15.3 for the Network Card with network
address 001AA09EA8E0 has been denied by the DHCP server 192.168.15.1 (The DHCP Server
sent a DHCPNACK message).

Error - 6/12/2010 3:25:18 PM | Computer Name = DF5141F1 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.15.3 for the Network Card with network
address 001AA09EA8E0 has been denied by the DHCP server 192.168.15.1 (The DHCP Server
sent a DHCPNACK message).

Error - 6/28/2010 6:56:27 PM | Computer Name = DF5141F1 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher
9 service to connect.

Error - 6/29/2010 9:14:03 AM | Computer Name = DF5141F1 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher
9 service to connect.

Error - 6/29/2010 9:17:59 AM | Computer Name = DF5141F1 | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 6/29/2010 9:18:02 AM | Computer Name = DF5141F1 | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 6/29/2010 9:18:02 AM | Computer Name = DF5141F1 | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 6/29/2010 9:20:11 AM | Computer Name = DF5141F1 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher
9 service to connect.


< End of report >








GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-29 21:45:49
Windows 5.1.2600 Service Pack 3
Running: 7hcqvzl3.exe; Driver: C:\DOCUME~1\Rich\LOCALS~1\Temp\kwtoapog.sys


โ€”- System - GMER 1.0.15 โ€”-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xA8585CD2]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwConnectPort [0xA86B5534]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0xA86AF782]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xA8585B8E]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreatePort [0xA86B5CC0]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0xA86B5DF6]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0xA86B0398]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xA8586142]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xA858606C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xA8585764]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey [0xA86D093C]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0xA86D0B44]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0xA86AFFAA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xA8585C68]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xA85856A4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xA8585708]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xA8585D88]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xA8586210]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwReplaceKey [0xA86D1208]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xA86B50F4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xA8585D48]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0xA86B075C]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetSecurityObject [0xA86D1E12]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xA8585EC8]

โ€”- Kernel IAT/EAT - GMER 1.0.15 โ€”-

IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [A86BA672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [A86BA4C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [A86BACBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [A86B8C2A] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [A86B8C2A] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [A86BA672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [A86BA4C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [A86BACBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [A86BA672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [A86B8C2A] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [A86BACBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [A86BA4C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [A86BACBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [A86BA4C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [A86BA672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [A86B8C2A] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [A86BA672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [A86BA4C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [A86BACBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [A86BA672] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [A86B8C2A] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [A86BACBA] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [A86BA4C8] \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

โ€”- User IAT/EAT - GMER 1.0.15 โ€”-

IAT C:\WINDOWS\system32\services.exe[928] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[928] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

โ€”- Devices - GMER 1.0.15 โ€”-

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \Driver\Tcpip \Device\Ip vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Tcpip \Device\Tcp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)

Device \Driver\Tcpip \Device\Udp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Tcpip \Device\RawIp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device A7520D20

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)

โ€”- EOF - GMER 1.0.15 โ€”-
Hi :)


Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“

Double click on the renamed Combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Hello Tom, I down loaded combofix, closed all firewalls and antivirus. tried to run program and got an error messageโ€ฆreport to microsoftโ€ฆ.rebooted again tried to run program and received same message. will not let me run it. I have also noted that I can not return to this page after trying to run combofix and getting the error message. I get a message that my internet connection is not available. I must reboot to get back on the internet. 7-2-10 did some research on this problem. seem there was a problem with the download center. it was fixed and I was able to run the program. I am attaching the report. Rich
Hi,


[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.






Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic



Please open OTL, set the extra registry tab to use safe list and hit the run scan button, post back with the 2 logfiles.
we went away to visit my daughter, who had a son, the computer is still the sameโ€ฆโ€ฆslowโ€ฆas for the CARP..I guess they will not let me spell "CR AP" so it changed the spelling. go figure.
Hi,


Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean



Please post back with a fresh OTL Logfile.
Hello Thomas ran the scans here are the results. Thanks Rich BTW it takes 1 min from start until desktop backround appears 21/2 min until icons appear (31/2 min total) 1 min for IE to open just to give you an idea of the speed of the programs

Attachments:

Thanks for the time info :)




Download and Run StartupLite


This program will identify startup entries that are unnecessary to be started at bootup. This will help free some memory.

  • Download StartupLite.exe by MalwareBytes to your desktop.
  • Double click on StartUpLite.exe to run it. If you are using Windows Vista, right click the icon and select Run As Administrator.
  • A list of unecessary startup entries will be compiled.
  • Take a read at the description of each and for most of them you probably won't need it please make sure there is a checkmark next to Disable.
  • Leave all the items as Disabled and click Continue.
  • Restart your computer once it's done.


Please open OTL, set the extra registry tab to use safe list and hit the run scan button, post back with the 2 logfiles. Please post the logfiles in the thread, do not attach them :).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI