This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

start-up takes forever

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My PC: Win Xp, AMD sempron Processor 3200+, 1.8GHz 576 MB of ram. Just a few days ago my computer started taking a long time to boot-up. After I turn on my computer it takes about 6 min for windows to boot-up, and start. My comp. was definitely not lightning before, but I didn't have enough time to go to the bathroom, and get a drink before loading like I do now. Your help and guidance in this matter is greatly appreciated. Below is my highjack and startup log.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:09:38 AM, on 7/2/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00

(8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Roxio\BackOnTrack\Disaster

Recovery\SaibSVC.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\CinemaNow\CinemaNow Media

Manager\CinemanowSvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\IObit\IObit Security

360\IS360srv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Security

Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\Alcohol Soft\Alcohol

120\StarWind\StarWindServiceAE.exe
C:\Program Files\Norton Security

Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\Program

Files\Yahoo!\SoftwareUpdate\YahooAUService.

exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common

Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program

Files\Google\GoogleToolbarNotifier\GoogleTo

olbarNotifier.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Nero\Nero 10\Nero

StartSmart\NeroStartSmart.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Nero\Nero 10\Nero

StartSmart\NMDllHost.exe
C:\Program Files\Nero\Nero 10\Nero

StartSmart\NMDllHost.exe
C:\Program Files\Nero\Nero 10\Nero

MediaHub\MediaHub.exe
C:\Program Files\Mozilla

Firefox\firefox.exe
C:\Program Files\Mozilla

Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend

Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://Bing.zugo.com/?cfg=2-71-0-1l3lg
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=6915

7
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=5489

6
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=5489

6
R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=6915

7
R0 - HKCU\Software\Microsoft\Internet

Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Local Page =
O2 - BHO: &Yahoo! Toolbar Helper -

{02478D38-C3F9-4efb-9B51-7695ECA05670} -

C:\Program

Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub -

{18DF081C-E8AD-4283-A596-FA578C2EBDC3} -

C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelperShi

m.dll
O2 - BHO: RealPlayer Download and Record

Plugin for Internet Explorer -

{3049C3E9-B461-4BC5-8870-4C09146192CA} -

C:\Documents and Settings\All

Users\Application

Data\Real\RealPlayer\BrowserRecordPlugin\IE

\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO -

{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -

C:\Program Files\Norton Security

Suite\Engine\4.2.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention -

{6D53EC84-6AAE-4787-AEEE-F4628F01010C} -

C:\Program Files\Norton Security

Suite\Engine\4.2.0.12\IPSBHO.DLL
O2 - BHO: Search Helper -

{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -

C:\Program Files\Microsoft\Search

Enhancement Pack\Search

Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper -

{9030D464-4C02-4ABF-8ECC-5164760863C6} -

C:\Program Files\Common Files\Microsoft

Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) -

{9D425283-D487-4337-BAB6-AB8354A81457} -

(no file)
O2 - BHO: Google Toolbar Helper -

{AA58ED58-01DD-4d91-8333-CF10577473F7} -

C:\Program Files\Google\Google

Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO -

{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -

C:\Program

Files\Google\GoogleToolbarNotifier\5.5.5126

.1836\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper -

{DBC80044-A445-435b-BC74-9C25C1C588A9} -

C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper -

{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} -

C:\Program Files\Windows

Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl -

{E7E6F031-17CE-4C07-BC86-EABFE594F69C} -

C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugi

n.dll
O2 - BHO: SingleInstance Class -

{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -

C:\Program

Files\Yahoo!\Companion\Installs\cpn\YTSingl

eInstance.dll
O3 - Toolbar: &Windows Live Toolbar -

{21FA44EF-376D-4D53-9B0F-8A89D3229068} -

C:\Program Files\Windows

Live\Toolbar\wltcore.dll
O3 - Toolbar: Norton Toolbar -

{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -

C:\Program Files\Norton Security

Suite\Engine\4.2.0.12\coIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar -

{EF99BD32-C1FB-11D2-892F-0090271D4F88} -

C:\Program

Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) -

{9D425283-D487-4337-BAB6-AB8354A81457} -

(no file)
O3 - Toolbar: Google Toolbar -

{2318C2B1-4965-11d4-9B18-009027A5CD4F} -

C:\Program Files\Google\Google

Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon]

RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter]

RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarI

nit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [QuickTime Task]

"C:\Program Files\QuickTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program

Files\Common

Files\Real\Update_OB\realsched.exe"

-osboot
O4 - HKLM\..\Run: [NBAgent] "C:\Program

Files\Nero\Nero 10\Nero

BackItUp\NBAgent.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount]

"D:\Program Files\Alcohol Soft\Alcohol

120\AxAutoMntSrv.exe" -automount
O4 - HKCU\..\Run: [swg] "C:\Program

Files\Google\GoogleToolbarNotifier\GoogleTo

olbarNotifier.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)]

"C:\PROGRA~1\Yahoo!\Messenger\YahooMessenge

r.exe" -quiet
O4 - Startup: CNET TechTracker.lnk =

C:\Documents and

Settings\Jeremy\Application Data\CBS

Interactive\CNET

TechTracker\TechTracker.exe
O4 - Startup: Secunia PSI.lnk = C:\Program

Files\Secunia\PSI\psi.exe
O4 - Global Startup: NETGEAR WPN111 Smart

Wizard.lnk = ?
O8 - Extra context menu item: E&xport to

Microsoft Excel -

res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.E

XE/3000
O8 - Extra context menu item: Google

Sidewiki… - res://C:\Program

Files\Google\Google

Toolbar\Component\GoogleToolbarDynamic_mui_

en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Blog This -

{219C3416-8CB2-491a-A3C7-D9FCDDC9D600} -

C:\Program Files\Windows

Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in

Windows Live Writer -

{219C3416-8CB2-491a-A3C7-D9FCDDC9D600} -

C:\Program Files\Windows

Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research -

{92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem:

@xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows

Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.cinemanow.com
O15 - Trusted Zone: http://*.qflix.com
O15 - Trusted Zone: http://*.roxio.com
O15 - Trusted Zone:

http://redirect.sonic.com
O15 - Trusted Zone:

http://redirect2.sonic.com
O16 - DPF:

{1E54D648-B804-468d-BC78-4AFFED8E262F}

(System Requirements Lab) -

http://www.nvidia.com/content/DriverDownloa

d/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF:

{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}

(Installation Support) - C:\Program

Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF:

{6414512B-B978-451D-A0D8-FCFDF33E833C}

(WUWebControl Class) -

http://update.microsoft.com/windowsupdate/v

6/V5Controls/en/x86/client/wuweb_site.cab?1

272971357187
O16 - DPF:

{74DBCB52-F298-4110-951D-AD2FF67BC8AB}

(NVIDIA Smart Scan) -

http://www.nvidia.com/content/DriverDownloa

d/nforce/NvidiaSmartScan.cab
O16 - DPF:

{E2883E8F-472F-4FB0-9522-AC9BF37916A7} -

http://platformdl.adobe.com/NOS/getPlusPlus

/1.6/gp.cab
O16 - DPF:

{E77F23EB-E7AB-4502-8F37-247DBAF1A147}

(Windows Live Hotmail Photo Upload Tool) -

http://gfx2.hotmail.com/mail/w4/pr01/photou

ploadcontrol/MSNPUpld.cab
O22 - SharedTaskScheduler: Browseui

preloader -

{438755C2-A8BA-11D1-B96B-00A0C90312E1} -

C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component

Categories cache daemon -

{8C7461EF-2B13-11d2-BE35-3078302C2030} -

C:\WINDOWS\system32\browseui.dll
O23 - Service: Roxio SAIB Service

(9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269) -

Unknown owner - C:\Program

Files\Roxio\BackOnTrack\Disaster

Recovery\SaibSVC.exe
O23 - Service: Agere Modem Call Progress

Audio (AgereModemAudio) - LSI Corporation -

C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: CinemaNow Service -

CinemaNow, Inc. - C:\Program

Files\CinemaNow\CinemaNow Media

Manager\CinemanowSvc.exe
O23 - Service: Google Update Service

(gupdate) (gupdate) - Google Inc. -

C:\Program

Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater

(gusvc) - Google - C:\Program

Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: IS360service - IObit -

C:\Program Files\IObit\IObit Security

360\IS360srv.exe
O23 - Service: Java Quick Starter

(JavaQuickStarterService) - Sun

Microsystems, Inc. - C:\Program

Files\Java\jre6\bin\jqs.exe
O23 - Service: Norton Security Suite (N360)

- Symantec Corporation - C:\Program

Files\Norton Security

Suite\Engine\4.2.0.12\ccSvcHst.exe
O23 - Service: @C:\Program

Files\Nero\Update\NASvc.exe,-200 (NAUpdate)

- Nero AG - C:\Program

Files\Nero\Update\NASvc.exe
O23 - Service: NVIDIA Display Driver

Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP -

C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RoxMediaDB12 - Sonic

Solutions - C:\Program Files\Common

Files\Roxio

Shared\12.0\SharedCOM\RoxMediaDB12.exe
O23 - Service: Roxio Hard Drive Watcher 12

(RoxWatch12) - Sonic Solutions - C:\Program

Files\Common Files\Roxio

Shared\12.0\SharedCOM\RoxWatch12.exe
O23 - Service: StarWind AE Service

(StarWindServiceAE) - StarWind Software -

D:\Program Files\Alcohol Soft\Alcohol

120\StarWind\StarWindServiceAE.exe
O23 - Service: Yahoo! Updater

(YahooAUService) - Yahoo! Inc. - C:\Program

Files\Yahoo!\SoftwareUpdate\YahooAUService.

exe

–
End of file - 11096 bytes

StartupList report, 7/2/2010, 5:14:18 AM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend

Micro\HiJackThis\HiJackThis.EXE
Detected: Windows XP SP3 (WinNT 5.01.2600)
Detected: Internet Explorer v8.00

(8.00.6001.18702)
* Using default options
===========================================

=======

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Roxio\BackOnTrack\Disaster

Recovery\SaibSVC.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\CinemaNow\CinemaNow Media

Manager\CinemanowSvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\IObit\IObit Security

360\IS360srv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Security

Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\Alcohol Soft\Alcohol

120\StarWind\StarWindServiceAE.exe
C:\Program Files\Norton Security

Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\Program

Files\Yahoo!\SoftwareUpdate\YahooAUService.

exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common

Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program

Files\Google\GoogleToolbarNotifier\GoogleTo

olbarNotifier.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Nero\Nero 10\Nero

StartSmart\NeroStartSmart.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Nero\Nero 10\Nero

StartSmart\NMDllHost.exe
C:\Program Files\Nero\Nero 10\Nero

StartSmart\NMDllHost.exe
C:\Program Files\Nero\Nero 10\Nero

MediaHub\MediaHub.exe
C:\Program Files\Mozilla

Firefox\firefox.exe
C:\Program Files\Mozilla

Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend

Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

——————————————-

——-

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Jeremy\Start

Menu\Programs\Startup]
CNET TechTracker.lnk = C:\Documents and

Settings\Jeremy\Application Data\CBS

Interactive\CNET

TechTracker\TechTracker.exe
Secunia PSI.lnk = C:\Program

Files\Secunia\PSI\psi.exe

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start

Menu\Programs\Startup]
NETGEAR WPN111 Smart Wizard.lnk = ?

——————————————-

——-

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows

NT\CurrentVersion\Winlogon]
UserInit =

C:\WINDOWS\system32\userinit.exe,

——————————————-

——-

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVers

ion\Run

NvCplDaemon = RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup
NvMediaCenter = RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarI

nit
nwiz = nwiz.exe /install
RTHDCPL = RTHDCPL.EXE
Alcmtr = ALCMTR.EXE
QuickTime Task = "C:\Program

Files\QuickTime\qttask.exe" -atboottime
TkBellExe = "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe"

-osboot
NBAgent = "C:\Program Files\Nero\Nero

10\Nero BackItUp\NBAgent.exe" /WinStart

——————————————-

——-

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVers

ion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
AlcoholAutomount = "D:\Program

Files\Alcohol Soft\Alcohol

120\AxAutoMntSrv.exe" -automount
swg = "C:\Program

Files\Google\GoogleToolbarNotifier\GoogleTo

olbarNotifier.exe"
Messenger (Yahoo!) =

"C:\PROGRA~1\Yahoo!\Messenger\YahooMessenge

r.exe" -quiet

——————————————-

——-

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVers

ion\Run

[OptionalComponents]
=

——————————————-

——-

Shell & screensaver key from

C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not

found*
HKLM\..\Policies: Shell=*Registry value not

found*

——————————————-

——-


Enumerating Browser Helper Objects:

(no name) - C:\Program

Files\Yahoo!\Companion\Installs\cpn\yt.dll

- {02478D38-C3F9-4efb-9B51-7695ECA05670}
AcroIEHelperStub - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelperShi

m.dll -

{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
(no name) - C:\Documents and Settings\All

Users\Application

Data\Real\RealPlayer\BrowserRecordPlugin\IE

\rpbrowserrecordplugin.dll -

{3049C3E9-B461-4BC5-8870-4C09146192CA}
Symantec NCO BHO - C:\Program Files\Norton

Security Suite\Engine\4.2.0.12\coIEPlg.dll

- {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
Symantec Intrusion Prevention - C:\Program

Files\Norton Security

Suite\Engine\4.2.0.12\IPSBHO.DLL -

{6D53EC84-6AAE-4787-AEEE-F4628F01010C}
Search Helper - C:\Program

Files\Microsoft\Search Enhancement

Pack\Search Helper\SearchHelper.dll -

{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}
(no name) - C:\Program Files\Common

Files\Microsoft Shared\Windows

Live\WindowsLiveLogin.dll -

{9030D464-4C02-4ABF-8ECC-5164760863C6}
(no name) - (no file) -

{9D425283-D487-4337-BAB6-AB8354A81457}
(no name) - C:\Program Files\Google\Google

Toolbar\GoogleToolbar_32.dll -

{AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program

Files\Google\GoogleToolbarNotifier\5.5.5126

.1836\swg.dll -

{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
(no name) - C:\Program

Files\Java\jre6\bin\jp2ssv.dll -

{DBC80044-A445-435b-BC74-9C25C1C588A9}
(no name) - C:\Program Files\Windows

Live\Toolbar\wltcore.dll -

{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}
JQSIEStartDetectorImpl - C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugi

n.dll -

{E7E6F031-17CE-4C07-BC86-EABFE594F69C}
(no name) - C:\Program

Files\Yahoo!\Companion\Installs\cpn\YTSingl

eInstance.dll -

{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}

——————————————-

——-

Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
AWC Update.job
ConfigExec.job
DataUpload.job
expressripShakeIcon.job
GoogleUpdateTaskMachineCore.job
GoogleUpdateTaskMachineUA.job
RealUpgradeLogonTaskS-1-5-18.job
RealUpgradeLogonTaskS-1-5-21-776561741-6067

47145-1801674531-1003.job
RealUpgradeLogonTaskS-1-5-21-776561741-6067

47145-1801674531-1005.job
RealUpgradeScheduledTaskS-1-5-18.job
RealUpgradeScheduledTaskS-1-5-21-776561741-

606747145-1801674531-1003.job
RealUpgradeScheduledTaskS-1-5-21-776561741-

606747145-1801674531-1005.job
SmartDefrag.job
User_Feed_Synchronization-{689FC3AC-1023-47

F4-A92C-57EC3B37E52C}.job

——————————————-

——-

Enumerating Download Program Files:

[Windows Genuine Advantage Validation Tool]
InProcServer32 =

C:\WINDOWS\system32\LegitCheckControl.DLL
CODEBASE =

http://download.microsoft.com/download/E/5/

6/E5611B10-0D6D-4117-8430-A67417AA88CD/Legi

tCheckControl.cab

[System Requirements Lab Class]
InProcServer32 = C:\WINDOWS\Downloaded

Program Files\sysreqlab_nvd.dll
CODEBASE =

http://www.nvidia.com/content/DriverDownloa

d/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
OSD = C:\WINDOWS\Downloaded Program

Files\sysreqlab.osd

[Installation Support]
InProcServer32 = C:\Program

Files\Yahoo!\Common\Yinsthelper.dll
CODEBASE = C:\Program

Files\Yahoo!\Common\Yinsthelper.dll

[WUWebControl Class]
InProcServer32 =

C:\WINDOWS\system32\wuweb.dll
CODEBASE =

http://update.microsoft.com/windowsupdate/v

6/V5Controls/en/x86/client/wuweb_site.cab?1

272971357187

[NVIDIA Smart Scan]
InProcServer32 =

C:\WINDOWS\DOWNLO~1\NVIDIA~1.OCX
CODEBASE =

http://www.nvidia.com/content/DriverDownloa

d/nforce/NvidiaSmartScan.cab

[{E2883E8F-472F-4FB0-9522-AC9BF37916A7}]
CODEBASE =

http://platformdl.adobe.com/NOS/getPlusPlus

/1.6/gp.cab

[Windows Live Hotmail Photo Upload Tool]
InProcServer32 = C:\WINDOWS\Downloaded

Program Files\MsnPUpld.dll
CODEBASE =

http://gfx2.hotmail.com/mail/w4/pr01/photou

ploadcontrol/MSNPUpld.cab

——————————————-

——-

Enumerating Winsock LSP files:

NameSpace #4:

C:\WINDOWS\system32\pnrpnsp.dll
NameSpace #5:

C:\WINDOWS\system32\pnrpnsp.dll

——————————————-

——-

Enumerating ShellServiceObjectDelayLoad

items:

PostBootReminder:

C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj:

C:\WINDOWS\system32\WPDShServiceObj.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll

——————————————-

——-
End of report, 9,807 bytes
Report generated in 0.359 seconds

Command line options:
/verbose - to add additional info on

each section
/complete - to include empty sections

and unsuspicious data
/full - to include several

rarely-important sections
/force9x - to include Win9x-only

startups even if running on WinNT
/forcent - to include WinNT-only

startups even if running on Win9x
/forceall - to include all Win9x and

WinNT startups, regardless of platform
/history - to list version history only
:welcome:

I cant read your logs the way you posted them, when they open in Notepad go to FORMAT and make sure Wordwrap is unchecked.

Go ahead and repost them and then run this program as well


Download DDS by sUBs from one of the following links. Save it to your desktop.
  • DDS.com
  • DDS.scr
  • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results, click no to the Optional_Scan
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control Here
Sorry about the word wrap, I did not know that would effect how it posted. Thanks for helping me with this problem. Here are my reports with word wrap turned off.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:42:14 PM, on 7/3/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Documents and Settings\Jeremy\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\WINDOWS\System32\snmp.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\Microsoft Fix it Center\Matsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://Bing.zugo.com/?cfg=2-71-0-1l3lg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.2.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.2.0.12\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.2.0.12\coIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NBAgent] "C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: CNET TechTracker.lnk = C:\Documents and Settings\Jeremy\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.cinemanow.com
O15 - Trusted Zone: http://*.qflix.com
O15 - Trusted Zone: http://*.roxio.com
O15 - Trusted Zone: http://redirect.sonic.com
O15 - Trusted Zone: http://redirect2.sonic.com
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1272971357187
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Roxio SAIB Service (9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269) - Unknown owner - C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: CinemaNow Service - CinemaNow, Inc. - C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RoxMediaDB12 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 10806 bytes


StartupList report, 7/3/2010, 11:43:06 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HiJackThis\HiJackThis.EXE
Detected: Windows XP SP3 (WinNT 5.01.2600)
Detected: Internet Explorer v8.00 (8.00.6001.18702)
* Using default options
* Including empty and uninteresting sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Documents and Settings\Jeremy\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\WINDOWS\System32\snmp.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\Microsoft Fix it Center\Matsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\NOTEPAD.EXE

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Jeremy\Start Menu\Programs\Startup]
CNET TechTracker.lnk = C:\Documents and Settings\Jeremy\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe
Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
NETGEAR WPN111 Smart Wizard.lnk = ?

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
RTHDCPL = RTHDCPL.EXE
Alcmtr = ALCMTR.EXE
NBAgent = "C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe ARM = "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

AlcoholAutomount = "D:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
Messenger (Yahoo!) = "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
=

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

————————————————–

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\system32\mshta.exe "%1" %*

————————————————–

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

————————————————–

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

————————————————–

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll - {02478D38-C3F9-4efb-9B51-7695ECA05670}
AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
(no name) - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll - {3049C3E9-B461-4BC5-8870-4C09146192CA}
Symantec NCO BHO - C:\Program Files\Norton Security Suite\Engine\4.2.0.12\coIEPlg.dll - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
Symantec Intrusion Prevention - C:\Program Files\Norton Security Suite\Engine\4.2.0.12\IPSBHO.DLL - {6D53EC84-6AAE-4787-AEEE-F4628F01010C}
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B}
(no name) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
(no name) - (no file) - {9D425283-D487-4337-BAB6-AB8354A81457}
(no name) - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
(no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}
(no name) - C:\Program Files\Windows Live\Toolbar\wltcore.dll - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}
JQSIEStartDetectorImpl - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}
(no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}

————————————————–

Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
AWC Update.job
ConfigExec.job
DataUpload.job
expressripShakeIcon.job
GoogleUpdateTaskMachineCore.job
GoogleUpdateTaskMachineUA.job
RealUpgradeLogonTaskS-1-5-18.job
RealUpgradeLogonTaskS-1-5-21-776561741-606747145-1801674531-1003.job
RealUpgradeLogonTaskS-1-5-21-776561741-606747145-1801674531-1005.job
RealUpgradeScheduledTaskS-1-5-18.job
RealUpgradeScheduledTaskS-1-5-21-776561741-606747145-1801674531-1003.job
RealUpgradeScheduledTaskS-1-5-21-776561741-606747145-1801674531-1005.job
SmartDefrag.job
User_Feed_Synchronization-{689FC3AC-1023-47F4-A92C-57EC3B37E52C}.job

————————————————–

Enumerating Download Program Files:

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL
CODEBASE = http://download.microsoft.com/download/E/5…heckControl.cab

[System Requirements Lab Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\sysreqlab_nvd.dll
CODEBASE = http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
OSD = C:\WINDOWS\Downloaded Program Files\sysreqlab.osd

[Installation Support]
InProcServer32 = C:\Program Files\Yahoo!\Common\Yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\Common\Yinsthelper.dll

[WUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\wuweb.dll
CODEBASE = http://update.microsoft.com/windowsupdate/…b?1272971357187

[NVIDIA Smart Scan]
InProcServer32 = C:\WINDOWS\DOWNLO~1\NVIDIA~1.OCX
CODEBASE = http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab

[Java Plug-in 1.6.0_20]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab

[Java Plug-in 1.6.0_20]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab

[Java Plug-in 1.6.0_20]
InProcServer32 = C:\Program Files\Java\jre6\bin\npjpi160_20.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab

[{E2883E8F-472F-4FB0-9522-AC9BF37916A7}]
CODEBASE = http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

[Windows Live Hotmail Photo Upload Tool]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
CODEBASE = http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab

————————————————–

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
NameSpace #4: C:\WINDOWS\system32\pnrpnsp.dll
NameSpace #5: C:\WINDOWS\system32\pnrpnsp.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll
Protocol #17: C:\WINDOWS\system32\mswsock.dll
Protocol #18: C:\WINDOWS\system32\mswsock.dll
Protocol #19: C:\WINDOWS\system32\mswsock.dll
Protocol #20: C:\WINDOWS\system32\mswsock.dll
Protocol #21: C:\WINDOWS\system32\mswsock.dll
Protocol #22: C:\WINDOWS\system32\mswsock.dll
Protocol #23: C:\WINDOWS\system32\mswsock.dll
Protocol #24: C:\WINDOWS\system32\mswsock.dll
Protocol #25: C:\WINDOWS\system32\mswsock.dll
Protocol #26: C:\WINDOWS\system32\mswsock.dll
Protocol #27: C:\WINDOWS\system32\mswsock.dll
Protocol #28: C:\WINDOWS\system32\mswsock.dll
Protocol #29: C:\WINDOWS\system32\mswsock.dll
Protocol #30: C:\WINDOWS\system32\mswsock.dll

————————————————–

Enumerating Windows NT logon/logoff scripts:

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll

————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

————————————————–

End of report, 19,505 bytes
Report generated in 0.187 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

here is what DDS popped up.

DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 0:38:51.14 on Sun 07/04/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.574.153 [GMT -7:00]

AV: Norton Security Suite *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Security Suite *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe
C:\Documents and Settings\Jeremy\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Nero\Nero 10\Nero InfoTool\InfoTool.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Jeremy\Desktop\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://Bing.zugo.com/?cfg=2-71-0-1l3lg
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\4.2.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\4.2.0.12\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\4.2.0.12\coIEPlg.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [AlcoholAutomount] "d:\program files\alcohol soft\alcohol 120\AxAutoMntSrv.exe" -automount
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NBAgent] "c:\program files\nero\nero 10\nero backitup\NBAgent.exe" /WinStart
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
StartupFolder: c:\docume~1\jeremy\startm~1\programs\startup\cnette~1.lnk - c:\documents and settings\jeremy\application data\cbs interactive\cnet techtracker\TechTracker.exe
StartupFolder: c:\docume~1\jeremy\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wpn111\wpn111.exe
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
Trusted Zone: cinemanow.com
Trusted Zone: qflix.com
Trusted Zone: roxio.com
Trusted Zone: sonic.com\redirect
Trusted Zone: sonic.com\redirect2
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1272971357187
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jeremy\applic~1\mozilla\firefox\profiles\if1tzmuf.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://seattle.craigslist.org/kit/
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\coffplgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\ipsffplgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\jeremy\local settings\application data\yahoo!\browserplus\2.8.1\plugins\npybrowserplus_2.8.1.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: LoudMo Contextual Ad Assistant: No Registry Reference - c:\program files\mozilla firefox\extensions\{d48ae653-71b2-5784-9c33-ea14b2983030}

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: google.toolbar.linkdoctor.enabled - false
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [2010-5-14 21488]
R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [2010-5-14 15856]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0402000.00c\symds.sys [2010-6-1 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0402000.00c\symefa.sys [2010-6-1 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\bashdefs\20100619.001\BHDrvx86.sys [2010-6-22 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0402000.00c\cchpx86.sys [2010-6-1 501888]
R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [2010-5-14 25584]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0402000.00c\ironx86.sys [2010-6-1 116784]
R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\roxio\backontrack\disaster recovery\SaibSVC.exe [2009-6-2 457200]
R2 CinemaNow Service;CinemaNow Service;c:\program files\cinemanow\cinemanow media manager\CinemaNowSvc.exe [2009-6-23 127352]
R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2008-4-13 14336]
R2 IS360service;IS360service;c:\program files\iobit\iobit security 360\is360srv.exe [2010-6-9 312152]
R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\4.2.0.12\ccsvchst.exe [2010-6-1 126392]
R2 NAUpdate;@c:\program files\nero\update\nasvc.exe,-200;c:\program files\nero\update\NASvc.exe [2010-3-25 490280]
R2 StarWindServiceAE;StarWind AE Service;d:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2009-12-23 370688]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2010-5-3 17149]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-26 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\ipsdefs\20100702.001\IDSXpx86.sys [2010-7-3 331640]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\virusdefs\20100703.003\NAVENG.SYS [2010-7-3 85552]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\virusdefs\20100703.003\NAVEX15.SYS [2010-7-3 1347504]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-4 135664]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\common files\roxio shared\12.0\sharedcom\RoxWatch12.exe [2009-7-24 219632]
S3 hp4200c;%usbscan.SvcDesc%;c:\windows\system32\drivers\HP4200C.SYS [2010-6-15 9312]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys –> c:\windows\system32\drivers\massfilter.sys [?]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2010-4-10 266544]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-5-28 14896]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-5-4 27064]
S3 RoxMediaDB12;RoxMediaDB12;c:\program files\common files\roxio shared\12.0\sharedcom\RoxMediaDB12.exe [2009-7-24 1116656]
S3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:\windows\system32\drivers\RTL8192su.sys [2010-1-6 594048]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [2010-5-3 384608]

=============== Created Last 30 ================

2010-07-02 12:05:53 0 d—–w- c:\program files\Trend Micro
2010-07-02 11:02:53 69 —-a-w- c:\windows\NeroDigital.ini
2010-07-02 08:02:33 0 d—–w- c:\docume~1\alluse~1\applic~1\Nero
2010-07-02 08:01:06 0 d—–w- c:\program files\Nero
2010-07-02 06:34:29 1974616 —-a-w- c:\windows\system32\D3DCompiler_42.dll
2010-07-02 06:33:59 1892184 —-a-w- c:\windows\system32\D3DX9_42.dll
2010-07-02 06:33:29 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll
2010-07-02 06:33:11 0 d—–w- c:\windows\Logs
2010-06-27 02:55:18 0 d—–w- c:\program files\VoipStunt.com
2010-06-26 18:25:38 0 d—–w- c:\docume~1\jeremy\applic~1\OpenOffice.org
2010-06-25 08:53:39 0 d—–w- c:\program files\JRE
2010-06-25 08:23:59 0 d—–w- c:\docume~1\jeremy\applic~1\CBS Interactive
2010-06-25 07:03:03 33280 —-a-w- c:\documents and settings\jeremy\DailyRoutines.doc
2010-06-22 22:02:39 0 d—–w- c:\windows\system32\RTCOM
2010-06-21 21:16:22 0 d—–w- c:\documents and settings\jeremy\Riven stuff
2010-06-21 19:46:58 0 ——w- c:\windows\QTW.ini
2010-06-21 19:46:47 0 —-a-w- c:\windows\PowerReg.dat
2010-06-21 19:13:31 10548064 —-a-w- c:\documents and settings\jeremy\Alcohol120_retail_2.0.0.1331.exe
2010-06-21 19:12:45 1293230 —-a-w- c:\documents and settings\jeremy\keymaker.exe
2010-06-21 10:43:03 0 d—–w- c:\documents and settings\all users\sonic
2010-06-21 04:35:45 0 d—–w- c:\documents and settings\jeremy\DailyRoutines_files
2010-06-21 04:35:44 32937 —-a-w- c:\documents and settings\jeremy\DailyRoutines.htm
2010-06-21 04:20:13 39936 —-a-w- c:\documents and settings\jeremy\sci162r2week5HomeWork.doc
2010-06-18 22:03:17 0 d—–w- c:\program files\Belkin
2010-06-18 22:02:50 0 d—–w- c:\windows\{3BDEAF49-D872-415F-919C-A2CCC962D8AE}
2010-06-16 06:56:21 0 d—–w- c:\docume~1\jeremy\applic~1\VS Revo Group
2010-06-15 22:28:14 0 d—–w- C:\col1832
2010-06-15 22:27:51 0 d—–w- C:\sj700
2010-06-15 22:27:11 0 d—–w- C:\col5319
2010-06-15 22:23:25 0 d—–w- C:\sj445
2010-06-15 22:21:39 0 d—–w- C:\sj654
2010-06-15 22:15:53 0 d—–w- C:\sj655
2010-06-15 22:07:25 87040 -c–a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2010-06-15 22:07:25 87040 —-a-w- c:\windows\system32\wiafbdrv.dll
2010-06-15 22:07:25 32768 -c–a-w- c:\windows\system32\dllcache\hpgtmcro.dll
2010-06-15 22:07:25 32768 —-a-w- c:\windows\system32\hpgtmcro.dll
2010-06-15 22:07:25 31232 -c–a-w- c:\windows\system32\dllcache\hpgt42tk.dll
2010-06-15 22:07:25 31232 —-a-w- c:\windows\system32\hpgt42tk.dll
2010-06-15 22:07:22 93696 -c–a-w- c:\windows\system32\dllcache\hpgt42.dll
2010-06-15 22:07:22 93696 —-a-w- c:\windows\system32\hpgt42.dll
2010-06-15 21:08:32 0 d—–w- c:\program files\HP
2010-06-12 11:39:07 0 d—–w- c:\docume~1\jeremy\applic~1\WinWay
2010-06-12 11:36:43 0 d—–w- c:\program files\WinWay Resume
2010-06-12 11:29:54 964608 —-a-w- c:\windows\system32\mfc70u.dll
2010-06-12 11:26:44 974848 —-a-w- c:\windows\system32\mfc70.dll
2010-06-12 11:18:42 487424 —-a-w- c:\windows\system32\msvcp70.dll
2010-06-12 11:18:42 344064 —-a-w- c:\windows\system32\msvcr70.dll
2010-06-12 11:17:52 103744 —-a-w- c:\windows\system32\mscomm32.ocx
2010-06-12 11:17:44 54784 —-a-w- c:\windows\system32\msvci70.dll
2010-06-12 11:09:05 0 d—–w- c:\program files\uTorrent
2010-06-12 11:08:43 0 d—–w- c:\docume~1\jeremy\applic~1\uTorrent
2010-06-09 12:31:35 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-09 08:27:46 0 d—–w- c:\docume~1\jeremy\applic~1\MotionDSP
2010-06-05 07:03:03 0 d—–w- c:\program files\MediaMonkey

==================== Find3M ====================

2010-06-28 11:25:10 18085888 —-a-w- c:\windows\RTHDCPL.EXE
2010-06-21 19:00:53 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-06-12 11:20:15 95792 —-a-r- c:\windows\fonts\WinWayBullets01.fon
2010-06-12 11:20:15 5636 —-a-r- c:\windows\fonts\winway.ttf
2010-05-28 11:04:52 14896 —-a-w- c:\windows\system32\drivers\psi_mf.sys
2010-05-16 02:34:02 361600 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-05-06 10:41:53 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 16:38:47 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-05-04 07:33:25 499712 —-a-w- c:\windows\system32\msvcp71.dll
2010-05-04 07:33:25 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-05-04 07:28:38 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2010-05-04 05:20:08 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-05-02 05:22:50 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30:08 285696 —-a-w- c:\windows\system32\atmfd.dll

============= FINISH: 0:39:42.81 ===============
Hi,

Thats much better thank you.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :dir
    C:\col1832
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt





Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.






Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
  • Double click GMER.exe.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 01:09 on 05/07/2010 by Jenn (Administrator - Elevation successful)

========== dir ==========

C:\col1832 - Parameters: "(none)"

—Files—
appdata.src –a— 12766 bytes [21:48 18/02/2004] [21:48 18/02/2004]
DeviceInfo.dll –a— 94208 bytes [21:48 18/02/2004] [21:48 18/02/2004]
HPAppEgn.dll –a— 81920 bytes [21:48 18/02/2004] [21:48 18/02/2004]
HpGenUi.dll –a— 139264 bytes [20:50 06/02/2004] [20:50 06/02/2004]
HpSdRes.dll –a— 61440 bytes [21:48 18/02/2004] [21:48 18/02/2004]
HpSdUi.dll –a— 126976 bytes [21:48 18/02/2004] [21:48 18/02/2004]
HPSysDig.exe –a— 356352 bytes [21:48 18/02/2004] [21:48 18/02/2004]
Logging.dll –a— 73728 bytes [21:48 18/02/2004] [21:48 18/02/2004]
SystemInfo.dll –a— 77824 bytes [21:48 18/02/2004] [21:48 18/02/2004]
zlib.dll –a— 53248 bytes [19:50 27/10/2003] [19:50 27/10/2003]

—Folders—
CVS d—– [22:28 15/06/2010]
cz d—– [22:28 15/06/2010]
da d—– [22:28 15/06/2010]
Du d—– [22:28 15/06/2010]
fi d—– [22:28 15/06/2010]
Fr d—– [22:28 15/06/2010]
ge d—– [22:28 15/06/2010]
gr d—– [22:28 15/06/2010]
hu d—– [22:28 15/06/2010]
it d—– [22:28 15/06/2010]
ja d—– [22:28 15/06/2010]
ko d—– [22:28 15/06/2010]
no d—– [22:28 15/06/2010]
po d—– [22:28 15/06/2010]
pol d—– [22:28 15/06/2010]
ru d—– [22:28 15/06/2010]
sc d—– [22:28 15/06/2010]
sp d—– [22:28 15/06/2010]
sw d—– [22:28 15/06/2010]
tc d—– [22:28 15/06/2010]
tu d—– [22:28 15/06/2010]

-=End Of File=-

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-05 03:41:11
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Jeremy\LOCALS~1\Temp\kxtdypog.sys


—- System - GMER 1.0.15 —-

SSDT 823912E0 ZwAlertResumeThread
SSDT 823F42E0 ZwAlertThread
SSDT 823922C8 ZwAllocateVirtualMemory
SSDT 8248E8A0 ZwAssignProcessToJobObject
SSDT 82CEC350 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xEBD85210]
SSDT 823F72C8 ZwCreateMutant
SSDT 82A40D60 ZwCreateSymbolicLinkObject
SSDT 823E26E8 ZwCreateThread
SSDT 826B0BD8 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xEBD85490]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xEBD859F0]
SSDT 823E32C8 ZwDuplicateObject
SSDT spau.sys ZwEnumerateKey [0xF84BCDA4]
SSDT spau.sys ZwEnumerateValueKey [0xF84BD132]
SSDT 823E52C8 ZwFreeVirtualMemory
SSDT 823F22E0 ZwImpersonateAnonymousToken
SSDT 823E12E0 ZwImpersonateThread
SSDT 82D83480 ZwLoadDriver
SSDT 823FD2C0 ZwMapViewOfSection
SSDT 823F7228 ZwOpenEvent
SSDT spau.sys ZwOpenKey [0xF84A40C0]
SSDT 823F62C8 ZwOpenProcess
SSDT 823F32D8 ZwOpenProcessToken
SSDT 823E8270 ZwOpenSection
SSDT 823A82C8 ZwOpenThread
SSDT 8248E7B0 ZwProtectVirtualMemory
SSDT spau.sys ZwQueryKey [0xF84BD20A]
SSDT spau.sys ZwQueryValueKey [0xF84BD08A]
SSDT 823F52E0 ZwResumeThread
SSDT 823EB2E0 ZwSetContextThread
SSDT 823F02D0 ZwSetInformationProcess
SSDT 826B0CB8 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xEBD85C40]
SSDT 823A7268 ZwSuspendProcess
SSDT 823E62E0 ZwSuspendThread
SSDT 82464050 ZwTerminateProcess
SSDT 823A12E0 ZwTerminateThread
SSDT 82DB52E0 ZwUnmapViewOfSection
SSDT 823E22C8 ZwWriteVirtualMemory

INT 0x62 ? 82F6DBF8
INT 0x73 ? 82F70F00
INT 0x82 ? 82F6DBF8
INT 0x83 ? 82F70F00
INT 0xB4 ? 82D95BF8

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 23B8 80501BF0 4 Bytes CALL 78889E3D
? spau.sys The system cannot find the file specified. !
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF75C3360, 0x20574D, 0xE8000020]
.text USBPORT.SYS!DllUnload F75A38AC 5 Bytes JMP 82D951D8
.text asxljbr9.SYS EEBCF386 35 Bytes [00, 00, 00, 00, 00, 00, 20, …]
.text asxljbr9.SYS EEBCF3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, …]
.text asxljbr9.SYS EEBCF3C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text asxljbr9.SYS EEBCF3C9 1 Byte [2E]
.text asxljbr9.SYS EEBCF3C9 11 Bytes [2E, 00, 00, 00, 5C, 02, 00, …] {ADD CS:[EAX], AL; ADD [EDX+EAX+0x0], BL; ADD [EAX], AL; ADD [EAX], AL}
.text …

—- Devices - GMER 1.0.15 —-

Device 82FDB1F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device 82394500
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device FF1C5500
Device Udfs.SYS (UDF File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\usbohci \Device\USBPDO-0 82C6C1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 82FDD1F8
Device \Driver\dmio \Device\DmControl\DmConfig 82FDD1F8
Device \Driver\dmio \Device\DmControl\DmPnP 82FDD1F8
Device \Driver\dmio \Device\DmControl\DmInfo 82FDD1F8
Device \Driver\usbehci \Device\USBPDO-1 82C681F8
Device \Driver\PCI_PNP6498 \Device\00000052 spau.sys

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\dmio \Device\HarddiskDmVolumes\PhysicalDmVolumes\RawVolume1 82FDD1F8
Device \Driver\dmio \Device\HarddiskDmVolumes\PhysicalDmVolumes\BlockVolume1 82FDD1F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 82F6E1F8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)

Device \Driver\Ftdisk \Device\HarddiskVolume2 82F6E1F8

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)

Device \Driver\Cdrom \Device\CdRom0 82D441F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{16932F9E-644F-4F47-A440-E60C84060343} 82B3F500
Device \Driver\Cdrom \Device\CdRom1 82D441F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 [F83F8B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F83F8B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F83F8B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-3 [F83F8B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f [F83F8B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom2 82D441F8
Device \Driver\USBSTOR \Device\00000080 82B69500
Device \Driver\USBSTOR \Device\00000081 82B69500
Device \Driver\NetBT \Device\NetBt_Wins_Export 82B3F500
Device \Driver\NetBT \Device\NetbiosSmb 82B3F500

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\sptd \Device\632853998 spau.sys

AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\usbohci \Device\USBFDO-0 82C6C1F8
Device \Driver\usbehci \Device\USBFDO-1 82C681F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 82A6D500
Device 82A6D500
Device \Driver\USBSTOR \Device\0000007c 82B69500
Device \Driver\Ftdisk \Device\FtControl 82F6E1F8
Device \Driver\USBSTOR \Device\0000007e 82B69500
Device \Driver\USBSTOR \Device\0000007f 82B69500
Device \Driver\nvgts \Device\Scsi\nvgts1Port2Path0Target0Lun0 82FDC1F8
Device \Driver\nvgts \Device\Scsi\nvgts1 82FDC1F8
Device \Driver\nvgts \Device\Scsi\nvgts2 82FDC1F8
Device \Driver\asxljbr9 \Device\Scsi\asxljbr91 82C23500
Device \Driver\asxljbr9 \Device\Scsi\asxljbr91Port4Path0Target0Lun0 82C23500

AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs FF7A81F8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 D:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x8E 0x10 0xC5 0xE9 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x56 0xD3 0x49 0x48 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x42 0x0A 0x24 0x90 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xED 0x08 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x06 0x40 0x7E 0xD2 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xB6 0x33 0xA6 0x49 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x25 0xC5 0x17 0xC3 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x60 0xB8 0x74 0xB6 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 D:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x8E 0x10 0xC5 0xE9 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x56 0xD3 0x49 0x48 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xC0 0x5C 0x38 0x67 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xED 0x08 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x06 0x40 0x7E 0xD2 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xB6 0x33 0xA6 0x49 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x25 0xC5 0x17 0xC3 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x60 0xB8 0x74 0xB6 …

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\Installer\MSI6B.tmp 0 bytes
File C:\WINDOWS\assembly\GACLock.dat 0 bytes

—- EOF - GMER 1.0.15 —-
Hi,

uTorrent <–Not recommended along with all the other file sharing programs , your downloading that file from an unknown source , malware writers know this and have hopped on the bandwagon and are infecting some sites that add malware to that download, your best off uninstalling this program from add remove programs in the control panel.

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI