This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Incredibly slow computer

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK SweetTech, I downloaded Malwarebytes' Anti-Malware, installed it and it updated as you said. In less than a minute I got BSOD which detected a problem "driver_irql_not_less_or_equal" and also to make sure any new hardware or software was properly installed. Where to now?
OK, I ran the program again and got the same result, BSOD. I then un-installed and re-installed the program, ran the scan again with the same result, again BSOD.
OK SweetTech, I followed the instructions for downloading and running Kapersky online scanner. As you said it took awhile to update the database but it did, however as soon as the update was complete I got this dialog box titled "message from webpage" telling me that the update failed and the program failed to start. It went to say to close the Kapersky window and re-open it and try again which i did and got the same dialog box. It also said I had to online to update the database and at the end of the message it had this (ERROR: Key is expired).
Hello,

Try this scan below:


AVP Tool by Kaspersky

IMPORTANT: Save these instructions so you can have access to them while in Safe Mode.

Download the AVP Tool by Kaspersky from Here & save it to your desktop. Be aware that this is a large file…. approximately 60mb.
  • Reboot your computer into Safe Mode

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears
    Use your up arrow key to highlight Safe Mode then press Enter


  • Double click the setup file to run it
  • Click Next to continue
  • Accept the License agreement then click Next
  • It will by default install to your desktop folder. Click Next
  • Once installed it will open a box. Click the Automatic scan tab
  • Under Automatic scan make sure the following are checked:

  • Hidden Startup Objects
  • System Memory
  • Disk Boot Sectors
  • My Computer
  • Also any other drives (Removable that you may have)

Leave the rest of the settings as they appear

  • Click on Scan at the top right hand corner
  • It will automatically neutralize any objects found
  • If some objects are left un-neutralized, click on Neutralize all
  • If you receive a message that an item cannot be neutralized then choose the Delete option when prompted
  • Once finished click the Reports button at the bottom
  • Name the file Kas & save it somewhere convenient like your desktop
  • Copy/paste only the detected Virus\malware from the report. It will be at the very top under Detected & post those results in your next reply

    Note: This program will self uninstall when you close it so save the log before closing it



NEXT:
OK, I ran the Kapersky AVP tool and here's the contents of the report it produced: Autoscan: completed 2 hours ago (events: 10, objects: 369201, time: 02:58:56) 7/15/2010 10:01:28 PM Task started 7/15/2010 10:27:28 PM Detected: Trojan-Downloader.Java.OpenConnection.ap C:\Documents and Settings\Greg\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-2dab1010-77ab5b22.zip/HiPointInstallShieldRT.class 7/15/2010 10:27:28 PM Detected: Trojan-Downloader.Java.OpenConnection.ap C:\Documents and Settings\Greg\Application Data\Sun\Java\Deployment\cache\6.0\36\d4e61e4-526ce150/HiPointInstallShieldRT.class 7/15/2010 10:52:32 PM Detected: Trojan-Downloader.Java.OpenConnection.ap C:\HelpAsst_backup\C\DOCUME~1\HELPAS~1\Application Data\Sun\Java\Deployment\cache\6.0\36\d4e61e4-526ce150/HiPointInstallShieldRT.class 7/15/2010 10:52:35 PM Detected: Trojan-Downloader.Java.OpenConnection.ap C:\HelpAsst_backup\C\DOCUME~1\HELPAS~1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-2dab1010-77ab5b22.zip/HiPointInstallShieldRT.class 7/15/2010 11:55:22 PM Deleted: Trojan-Downloader.Java.OpenConnection.ap C:\Documents and Settings\Greg\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-2dab1010-77ab5b22.zip/HiPointInstallShieldRT.class 7/15/2010 11:55:22 PM Deleted: Trojan-Downloader.Java.OpenConnection.ap C:\HelpAsst_backup\C\DOCUME~1\HELPAS~1\Application Data\Sun\Java\Deployment\cache\6.0\36\d4e61e4-526ce150/HiPointInstallShieldRT.class 7/15/2010 11:55:22 PM Deleted: Trojan-Downloader.Java.OpenConnection.ap C:\Documents and Settings\Greg\Application Data\Sun\Java\Deployment\cache\6.0\36\d4e61e4-526ce150/HiPointInstallShieldRT.class 7/15/2010 11:55:22 PM Deleted: Trojan-Downloader.Java.OpenConnection.ap C:\HelpAsst_backup\C\DOCUME~1\HELPAS~1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-2dab1010-77ab5b22.zip/HiPointInstallShieldRT.class 7/16/2010 1:00:24 AM Task completed Thanks,
Hello,

Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader
Alternative Option: after uninstalling Adobe Reader, you could try installing Foxit Reader from >here< Foxit Reader has fewer add-ons therefore loads more quickly.



NEXT:



Java Outdated
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "JDK 6 Update 21 (JDK or JRE)".
  • Click the "Download JRE" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586.exe to install the newest version.
  • If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
– Starting with Java 6u10, the uninstaller incorporated in each new release uses Enhanced Auto update to automatically remove the previous version when updating to a later update release. It will not remove older versions, so they will need to be removed manually.
– Java is updated frequently. If you want to be automatically notified of future updates, just turn on the Java Automatic Update feature and you will not have to remember to update when Java releases a new version.


Note:
The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
Click Ok and reboot your computer.


NEXT



Clean Java Cache & Temporary Files
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT:



Please download JavaRa and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location and post it in your next reply.


NEXT:



Security Check
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.



NEXT


OTL Custom Scan

We need to run an OTL Custom Scan
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following bolded text into the [external image: Posted Image] textbox.


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Push [external image: Posted Image]
  • A report will open. Copy and Paste that report in your next reply.
OK SweetTech, here we go.

1. Results from javara program:

JavaRa 1.15 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Fri Jul 16 21:04:03 2010

Found and removed: C:\Program Files\Java\j2re1.4.2_03

Found and removed: C:\Program Files\Java\jre1.6.0_03

Found and removed: Software\JavaSoft\Java2D\1.5.0_06

Found and removed: Software\JavaSoft\Java2D\1.5.0_09

Found and removed: Software\JavaSoft\Java2D\1.5.0_10

Found and removed: SOFTWARE\Classes\JavaPlugin.150_03

Found and removed: SOFTWARE\Classes\JavaPlugin.150_06

Found and removed: SOFTWARE\Classes\JavaPlugin.150_09

Found and removed: SOFTWARE\Classes\JavaPlugin.150_10

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410203

Found and removed: SOFTWARE\Classes\JavaPlugin.142_03

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

————————————

Finished reporting.



2. Results from Security Check:

Results of screen317's Security Check version 0.99.4
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
McAfee SecurityCenter
McAfee Shredder
Antivirus up to date! (On Access scanning disabled!)
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
Java™ 6 Update 21
Out of date Java installed!
Adobe Flash Player
Adobe Reader 9.3.3
````````````````````````````````
Process Check:
objlist.exe by Laurent

McAfee VIRUSS~1 mcshield.exe
America Online 9.0 aoltray.exe
````````````````````````````````
DNS Vulnerability Check:


``````````End of Log````````````


3. Results form OTL Scan:

OTL logfile created on: 7/16/2010 9:11:49 PM - Run 1
OTL by OldTimer - Version 3.2.7.1 Folder = C:\Documents and Settings\Greg\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 607.00 Mb Available Physical Memory | 59.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 23.78 Gb Free Space | 34.07% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 668.00 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
G: Drive not present or media not loaded
Drive H: | 232.23 Gb Total Space | 214.46 Gb Free Space | 92.35% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: SARA
Current User Name: Greg
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Greg\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Research in Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MSK\msksrver.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe (Mattel Inc.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe (Dell)
PRC - C:\WINDOWS\system32\dlcdcoms.exe ()
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\gth.dll (Google Inc.)
MOD - C:\Documents and Settings\Greg\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\McAfee\SiteAdvisor\sahook.dll ()
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (MSK80Service) – C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) – c:\program files\common files\mcafee\mna\mcnasvc.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (dlcd_device) – C:\WINDOWS\System32\dlcdcoms.exe ()
SRV - (IAANTMon) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (MPFP) – C:\WINDOWS\system32\drivers\Mpfp.sys (McAfee, Inc.)
DRV - (SMSIVZAM5) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMSIVZAM5.sys (Smith Micro Inc.)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (MCSTRM) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (iastor) – C:\WINDOWS\system32\drivers\iastor.sys (Intel Corporation)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/03/10 06:50:33 | 000,000,000 | —D | M]


O1 HOSTS File: ([2004/08/10 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (CafeMom Toolbar) - {8151A608-00FB-4D5C-8B8D-40E239E32A42} - C:\Program Files\CafeMom Toolbar\cmtb.dll (CMI Marketing, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Freecause Toolbar BHO) - {FC78E410-0EFA-4BEC-B283-D1DB1922F420} - C:\Program Files\CoolChaser Layout Auto Insert\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (CafeMom Toolbar) - {8151A608-00FB-4D5C-8B8D-40E239E32A42} - C:\Program Files\CafeMom Toolbar\cmtb.dll (CMI Marketing, Inc.)
O3 - HKLM\..\Toolbar: (CoolChaser Layout Auto Insert) - {B0208007-27C1-4BCD-93EF-EFF5DB61FC22} - C:\Program Files\CoolChaser Layout Auto Insert\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (CoolChaser Layout Auto Insert) - {B0208007-27C1-4BCD-93EF-EFF5DB61FC22} - C:\Program Files\CoolChaser Layout Auto Insert\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [DACSMiniApp] C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe (Mattel Inc.)
O4 - HKLM..\Run: [DLCDCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCDtime.DLL ()
O4 - HKLM..\Run: [dlcdmon.exe] C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe (Dell)
O4 - HKLM..\Run: [EPSON PictureMate] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MemoryCardManager] C:\Program Files\Dell Photo AIO Printer 944\memcard.exe ()
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
O4 - Startup: C:\Documents and Settings\Greg\Start Menu\Programs\Startup\MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe (Smith Micro Software, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : CafeMom Toolbar - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - Reg Error: Value error. File not found
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe File not found
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab (MSN Games – Matchmaking)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/f/0…tualEarth3D.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1A595EDD-978A-48C7-B730-AF3B9CC64DAB} https://vmodlms.widerthanam.com/component/VZWDLManager.cab (DLManager Class)
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} http://dlmanager.akamaitools.com.edgesuite…vex-2.0.6.0.cab (DownloadManager Control)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab (MSN Games – Game Chat)
O16 - DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} http://utilities.pcpitstop.com/Exterminate…opAntiVirus.dll (PCPitstop AntiVirus)
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} http://www.worldwinner.com/games/v41/freecell/freecell.cab (FreeCell Control)
O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} http://zone.msn.com/bingame/zpagames/zpa_dmno.cab55579.cab (ZPA_DMNO Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} http://zone.msn.com/bingame/zpagames/zpa_wof.cab55579.cab (ZPA_WheelOfFortune Object)
O16 - DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} http://utilities.pcpitstop.com/DiskMD3/DiskMD3Ctrl.dll (diskhealth Class)
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab70018.cab (MSN Games – Hearts)
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab (MSN Games – Texas Holdem Poker)
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} https://mppv2flash3.valueactive.com/SportsI…ion/FlashAX.cab (FlashXControl Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} http://apps.corel.com/nos_dl_manager/plugi…NetOpPlugin.ocx (Get_ActiveX Control)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…991/mcfscan.cab (McFreeScan Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Desktop Uninstall) - C:\WINDOWS\warnhp.html
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Greg\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Greg\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 05:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/06/18 16:12:18 | 000,000,088 | —- | M] () - F:\autorun.inf – [ UDF ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mp42 - C:\WINDOWS\System32\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2010/07/16 21:02:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Greg\Desktop\JavaRa
[2010/07/16 20:54:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/07/16 20:54:03 | 000,423,656 | —- | C] (Oracle) – C:\WINDOWS\System32\deployJava1.dll
[2010/07/16 20:54:03 | 000,153,376 | —- | C] (Oracle) – C:\WINDOWS\System32\javaws.exe
[2010/07/16 20:54:03 | 000,145,184 | —- | C] (Oracle) – C:\WINDOWS\System32\javaw.exe
[2010/07/16 20:54:03 | 000,145,184 | —- | C] (Oracle) – C:\WINDOWS\System32\java.exe
[2010/07/16 20:54:03 | 000,073,728 | —- | C] (Oracle) – C:\WINDOWS\System32\javacpl.cpl
[2010/07/16 20:34:23 | 016,066,336 | —- | C] (Oracle) – C:\Documents and Settings\Greg\Desktop\jre-6u21-windows-i586.exe
[2010/07/16 20:17:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2010/07/16 20:12:28 | 000,000,000 | —D | C] – C:\Program Files\NOS
[2010/07/16 20:12:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2010/07/15 21:54:27 | 074,024,144 | —- | C] ( ) – C:\Documents and Settings\Greg\Desktop\setup_9.0.0.722_16.07.2010_06-02.exe
[2010/07/14 19:47:26 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/14 19:47:23 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/14 19:35:08 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/14 19:18:58 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/14 19:16:56 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Greg\Desktop\mbam-setup-1.46.exe
[2010/07/13 21:52:10 | 000,000,000 | —D | C] – C:\HelpAsst_backup
[2010/07/13 19:00:11 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Greg\Desktop\mbam-setup.exe
[2010/07/12 20:59:29 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/07/12 20:51:48 | 000,000,000 | –SD | C] – C:\svkkfddu
[2010/07/07 22:10:33 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/07/07 22:10:33 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/07/07 22:10:33 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/07/07 22:10:24 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/07/07 22:09:51 | 000,000,000 | —D | C] – C:\Qoobox
[2010/07/07 20:44:48 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\swreg.exe
[2010/07/05 13:02:21 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Greg\Desktop\OTL.exe
[2010/07/05 08:56:33 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/06/18 18:43:59 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/06/18 18:30:39 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Greg\Desktop\HijackThis.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/16 21:07:45 | 000,867,892 | —- | M] () – C:\Documents and Settings\Greg\Desktop\SecurityCheck.exe
[2010/07/16 21:02:21 | 000,071,798 | —- | M] () – C:\Documents and Settings\Greg\Desktop\JavaRa.zip
[2010/07/16 20:53:49 | 000,423,656 | —- | M] (Oracle) – C:\WINDOWS\System32\deployJava1.dll
[2010/07/16 20:53:49 | 000,153,376 | —- | M] (Oracle) – C:\WINDOWS\System32\javaws.exe
[2010/07/16 20:53:49 | 000,145,184 | —- | M] (Oracle) – C:\WINDOWS\System32\javaw.exe
[2010/07/16 20:53:49 | 000,145,184 | —- | M] (Oracle) – C:\WINDOWS\System32\java.exe
[2010/07/16 20:53:49 | 000,073,728 | —- | M] (Oracle) – C:\WINDOWS\System32\javacpl.cpl
[2010/07/16 20:51:09 | 000,302,562 | —- | M] () – C:\logfile
[2010/07/16 20:50:50 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/16 20:50:12 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/16 20:50:03 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/16 20:50:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/16 20:49:58 | 1071,812,608 | -HS- | M] () – C:\hiberfil.sys
[2010/07/16 20:49:19 | 004,456,448 | -H– | M] () – C:\Documents and Settings\Greg\ntuser.dat
[2010/07/16 20:49:16 | 000,036,715 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2010/07/16 20:49:14 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Greg\ntuser.ini
[2010/07/16 20:34:23 | 016,066,336 | —- | M] (Oracle) – C:\Documents and Settings\Greg\Desktop\jre-6u21-windows-i586.exe
[2010/07/16 20:33:14 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/16 20:17:33 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/07/16 03:47:05 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/15 21:54:29 | 074,024,144 | —- | M] ( ) – C:\Documents and Settings\Greg\Desktop\setup_9.0.0.722_16.07.2010_06-02.exe
[2010/07/14 19:47:29 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/14 19:14:12 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Greg\Desktop\mbam-setup-1.46.exe
[2010/07/13 18:53:17 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Greg\Desktop\mbam-setup.exe
[2010/07/12 22:26:01 | 000,507,490 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/12 22:26:01 | 000,445,370 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/12 22:26:01 | 000,072,576 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/12 20:59:29 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2010/07/11 22:18:03 | 003,736,761 | R— | M] () – C:\Documents and Settings\Greg\Desktop\svkkfddu.exe
[2010/07/10 21:16:37 | 000,001,917 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/07/07 22:18:45 | 000,000,279 | —- | M] () – C:\Boot.bak
[2010/07/07 19:46:58 | 000,490,232 | —- | M] () – C:\Documents and Settings\Greg\Desktop\HelpAsst_mebroot_fix.exe
[2010/07/05 22:25:51 | 000,485,896 | —- | M] () – C:\Documents and Settings\Greg\Desktop\HAMeb_check.exe
[2010/07/05 13:34:36 | 000,293,376 | —- | M] () – C:\Documents and Settings\Greg\Desktop\r139bsrq.exe
[2010/07/05 12:59:16 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Greg\Desktop\OTL.exe
[2010/07/05 12:55:24 | 000,440,536 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/05 10:14:32 | 000,000,762 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/18 18:30:00 | 000,000,354 | —- | M] () – C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (SARA-SaraAnn).job
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/16 21:07:41 | 000,867,892 | —- | C] () – C:\Documents and Settings\Greg\Desktop\SecurityCheck.exe
[2010/07/16 21:02:21 | 000,071,798 | —- | C] () – C:\Documents and Settings\Greg\Desktop\JavaRa.zip
[2010/07/16 20:17:33 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/07/16 17:26:38 | 1071,812,608 | -HS- | C] () – C:\hiberfil.sys
[2010/07/14 19:47:29 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/12 20:47:49 | 003,736,761 | R— | C] () – C:\Documents and Settings\Greg\Desktop\svkkfddu.exe
[2010/07/07 22:18:45 | 000,000,279 | —- | C] () – C:\Boot.bak
[2010/07/07 22:18:33 | 000,260,272 | —- | C] () – C:\cmldr
[2010/07/07 22:10:33 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/07/07 22:10:33 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/07/07 22:10:33 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/07/07 20:59:08 | 000,000,443 | —- | C] () – C:\Documents and Settings\Greg\mbr.log
[2010/07/07 20:44:48 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/07/07 20:44:48 | 000,077,312 | —- | C] () – C:\WINDOWS\mbr.exe
[2010/07/07 20:44:11 | 000,490,232 | —- | C] () – C:\Documents and Settings\Greg\Desktop\HelpAsst_mebroot_fix.exe
[2010/07/07 05:50:18 | 000,485,896 | —- | C] () – C:\Documents and Settings\Greg\Desktop\HAMeb_check.exe
[2010/07/05 19:15:10 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/05 13:37:34 | 000,293,376 | —- | C] () – C:\Documents and Settings\Greg\Desktop\r139bsrq.exe
[2008/02/04 19:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/08/13 17:43:04 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\vcnt3.dll
[2007/05/09 03:01:23 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/04/28 21:42:42 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\VZWDLManager.dll
[2006/08/17 19:07:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/06/17 15:55:08 | 000,000,000 | —- | C] () – C:\WINDOWS\Textart.INI
[2006/04/30 09:50:04 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\805ED6FF80.sys
[2006/02/24 12:34:09 | 000,000,072 | —- | C] () – C:\WINDOWS\JascCmdPrint.INI
[2006/02/20 17:29:21 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dlcdcfg.dll
[2006/02/10 10:39:46 | 000,012,288 | —- | C] () – C:\WINDOWS\impborl.dll
[2005/12/27 16:34:36 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2005/11/22 22:44:24 | 000,000,061 | —- | C] () – C:\WINDOWS\PrintWorkShop2006.ini
[2005/11/17 21:02:49 | 000,000,021 | —- | C] () – C:\WINDOWS\CS_SETUP.ini
[2005/11/17 20:46:07 | 000,000,040 | —- | C] () – C:\WINDOWS\System32\EAL.INI
[2005/11/17 20:45:52 | 000,000,073 | —- | C] () – C:\WINDOWS\PICTURM8.ini
[2005/11/17 20:27:30 | 000,007,520 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/11/17 20:27:30 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\80FFD65E80.sys
[2005/11/14 22:23:02 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/14 22:16:05 | 000,000,186 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/11/14 21:50:34 | 000,000,387 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/16 05:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/05 15:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/07/22 14:51:40 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\dlcdinsr.dll
[2005/07/22 14:51:36 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\dlcdcur.dll
[2005/07/22 14:51:22 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\dlcdjswr.dll
[2005/07/22 14:50:34 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlcdinsb.dll
[2005/07/22 14:50:30 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\dlcdcub.dll
[2005/07/22 14:50:24 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\dlcdcu.dll
[2005/07/22 14:50:22 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdins.dll
[2005/07/22 14:48:52 | 000,430,080 | —- | C] () – C:\WINDOWS\System32\dlcdutil.dll
[2005/06/21 15:27:56 | 000,638,976 | —- | C] () – C:\WINDOWS\System32\dlcdpmui.dll
[2005/06/21 15:27:02 | 001,183,744 | —- | C] () – C:\WINDOWS\System32\dlcdserv.dll
[2005/06/21 15:22:06 | 000,483,328 | —- | C] () – C:\WINDOWS\System32\dlcdlmpm.dll
[2005/06/21 15:21:40 | 000,413,696 | —- | C] () – C:\WINDOWS\System32\dlcdcomm.dll
[2005/06/21 15:19:48 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\dlcdpplc.dll
[2005/06/21 15:18:58 | 000,704,512 | —- | C] () – C:\WINDOWS\System32\dlcdcomc.dll
[2005/06/21 15:18:24 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlcdprox.dll
[2005/06/21 15:12:48 | 001,134,592 | —- | C] () – C:\WINDOWS\System32\dlcdusb1.dll
[2005/06/21 15:09:22 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\dlcdhbn3.dll
[2005/04/09 17:49:48 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/02/23 10:53:36 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlcdvs.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/04/29 15:13:05 | 000,000,000 | -H– | M] () – C:\.protected
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/07/07 22:18:45 | 000,000,279 | —- | M] () – C:\Boot.bak
[2010/07/12 20:59:29 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2010/07/12 20:59:29 | 000,000,324 | —- | M] () – C:\CF-RC.txt
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/11/14 21:56:24 | 000,005,800 | RH– | M] () – C:\dell.sdr
[2010/07/14 19:39:09 | 000,008,604 | —- | M] () – C:\dlcd.log
[2010/03/31 20:42:31 | 000,013,830 | —- | M] () – C:\dlcdscan.log
[2010/07/13 21:58:36 | 000,002,533 | —- | M] () – C:\HelpAsst.log
[2010/07/16 20:49:58 | 1071,812,608 | -HS- | M] () – C:\hiberfil.sys
[2005/11/17 21:23:18 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2010/07/16 21:04:04 | 000,006,901 | —- | M] () – C:\JavaRa.log
[2007/08/20 21:37:46 | 003,360,533 | —- | M] () – C:\kenzie invite.wpd
[2010/07/16 20:51:09 | 000,302,562 | —- | M] () – C:\logfile
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2009/12/30 12:15:27 | 000,000,948 | —- | M] () – C:\net_save.dna
[2004/08/10 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/19 10:26:15 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/07/16 20:49:57 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2010/07/12 21:22:38 | 000,000,382 | —- | M] () – C:\Shortcut to CF-RC.txt.lnk
[2005/10/31 10:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2005/11/14 22:14:27 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2008/11/21 08:51:47 | 000,001,780 | —- | M] () – C:\UBSoftUpdate.log

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/16 05:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2005/06/21 10:46:26 | 000,073,728 | —- | M] (Dell, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlcdPP5C.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >
[2001/05/07 18:14:22 | 000,303,104 | —- | M] () – C:\WINDOWS\Film Factory.scr
[2006/02/10 10:42:39 | 000,626,688 | —- | M] (ScreenTime Media) – C:\WINDOWS\KCsaver1_PC.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2006/04/26 20:16:02 | 000,000,251 | —- | M] () – C:\Program Files\wt3d.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 19:11:51 | 001,267,200 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\comsvcs.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/08/16 05:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/16 05:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/16 05:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2008/04/13 19:12:08 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B – C:\WINDOWS\system32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/13 19:12:10 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A – C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/13 19:12:10 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 – C:\WINDOWS\system32\ws2help.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-15 23:29:12

========== Alternate Data Streams ==========

@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CDD30F0D
< End of report >


Just an additional note, the machine is now running much better and hasn't locked up recently. Thanks.
Hello,

Your logs are looking good. We are almost done.

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
    O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - No CLSID value found.
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected ()
    O9 - Extra 'Tools' menuitem : CafeMom Toolbar - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - Reg Error: Value error. File not found
    O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe File not found
    O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe File not found
    O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/f/0…tualEarth3D.cab (Reg Error: Key error.)
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
    [2010/07/16 21:02:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Greg\Desktop\JavaRa
    [2010/07/16 20:34:23 | 016,066,336 | —- | C] (Oracle) – C:\Documents and Settings\Greg\Desktop\jre-6u21-windows-i586.exe
    [2010/07/14 19:16:56 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Greg\Desktop\mbam-setup-1.46.exe
    [2010/07/13 19:00:11 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Greg\Desktop\mbam-setup.exe
    [2010/07/16 21:07:45 | 000,867,892 | —- | M] () – C:\Documents and Settings\Greg\Desktop\SecurityCheck.exe
    [2010/07/16 21:02:21 | 000,071,798 | —- | M] () – C:\Documents and Settings\Greg\Desktop\JavaRa.zip
    [2010/07/07 20:59:08 | 000,000,443 | —- | C] () – C:\Documents and Settings\Greg\mbr.log
    [2010/07/05 13:37:34 | 000,293,376 | —- | C] () – C:\Documents and Settings\Greg\Desktop\r139bsrq.exe
    [2005/10/31 10:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
    @Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CDD30F0D
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
OK, ran OTL fix and here is the report it generated: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{5CBE2611-C31B-401F-89BC-4CBB25E853D7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5CBE2611-C31B-401F-89BC-4CBB25E853D7}\ not found. C:\Documents and Settings\All Users\Start Menu\Programs\Startup\.protected moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{07DB8C18-9FD9-4e43-AF16-043E44D89768}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07DB8C18-9FD9-4e43-AF16-043E44D89768}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{F4430FE8-2638-42e5-B849-800749B94EED}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F4430FE8-2638-42e5-B849-800749B94EED}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{F4430FE8-2638-42e5-B849-800749B94EED}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F4430FE8-2638-42e5-B849-800749B94EED}\ not found. Starting removal of ActiveX control {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} C:\WINDOWS\Downloaded Program Files\VE3DInstall.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0DB074F0-617E-4EE9-912C-2965CF2AA5A4}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{361ac05d-0e0d-11da-9aa9-806d6172696f}\ not found. File E:\setup.exe not found. C:\Documents and Settings\Greg\Desktop\JavaRa folder moved successfully. C:\Documents and Settings\Greg\Desktop\jre-6u21-windows-i586.exe moved successfully. C:\Documents and Settings\Greg\Desktop\mbam-setup-1.46.exe moved successfully. C:\Documents and Settings\Greg\Desktop\mbam-setup.exe moved successfully. C:\Documents and Settings\Greg\Desktop\SecurityCheck.exe moved successfully. C:\Documents and Settings\Greg\Desktop\JavaRa.zip moved successfully. C:\Documents and Settings\Greg\mbr.log moved successfully. C:\Documents and Settings\Greg\Desktop\r139bsrq.exe moved successfully. C:\StubInstaller.exe moved successfully. ADS C:\Documents and Settings\All Users\Application Data\TEMP:CDD30F0D deleted successfully. ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: Greg ->Temp folder emptied: 151046703 bytes ->Temporary Internet Files folder emptied: 150483936 bytes ->Java cache emptied: 4529132 bytes ->Flash cache emptied: 1148843 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 1748394 bytes ->Flash cache emptied: 405 bytes User: LULUBUG ->Temp folder emptied: 491121 bytes ->Temporary Internet Files folder emptied: 258236949 bytes ->Flash cache emptied: 6959 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: SaraAnn ->Temp folder emptied: 11221786022 bytes ->Temporary Internet Files folder emptied: 240223434 bytes ->Java cache emptied: 53969933 bytes ->Flash cache emptied: 2249646 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 609642008 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 64153548 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34318 bytes RecycleBin emptied: 309918 bytes Total Files Cleaned = 12,169.00 mb [EMPTYFLASH] User: Administrator User: All Users User: Default User User: Greg ->Flash cache emptied: 0 bytes User: LocalService ->Flash cache emptied: 0 bytes User: LULUBUG ->Flash cache emptied: 0 bytes User: NetworkService User: SaraAnn ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.7.1 log created on 07172010_130126 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\SaraAnn\Local Settings\Temp\Temporary Internet Files\Content.IE5\FVTLP80P\%3D0%2F%2A%24,http%3A%2F%2Fsports.yahoo[1].com%2Fmma%2Fnews%3B_ylt%3Dasrjnv4uv8lohosrfnp3gjg9eo14%3Fslug%3Dmmajunkie-ufc_sues_bar%26prov%3Dmmajunkie%26type%3Dlgns,;ord=1262962641 not found! File\Folder C:\Documents and Settings\SaraAnn\Local Settings\Temp\Temporary Internet Files\Content.IE5\FVTLP80P\%3DhrzRxkwNdHE9grbbRDcL6iPyS0GMiEtHRzUAA.X8%2FB%3Dvo5bAGKImks-%2FJ%3D1262962485295041%2FK%3D9LOiQ5va6xIUJVKgOceHRg%2FA%3D5762049%2FR%3D0%2F%2A%24,http%3A%2F%2Fsports.yahoo[1].htm not found! File\Folder C:\Documents and Settings\SaraAnn\Local Settings\Temp\Temporary Internet Files\Content.IE5\FVTLP80P\gi5OzWgSmrlQtJtbOoQ3sJhKb3sDm578VcDNnWJY5QW4u0WX.Is.X7G8776FRu0uqIgn4RuDNmo i37ejterG16Ie7n42p1ktNPK7yZgOGL25SHLqBhdgGFqDNVcYIx.lmJrk5ueI8yYmweruVMsi4ULfcRZR lsXXdnRzzd8AdC[1].P_4- not found! File\Folder C:\Documents and Settings\SaraAnn\Local Settings\Temp\Temporary Internet Files\Content.IE5\FVTLP80P\KTtYrvdNZU7459U5mniEi6g6FA6s5g6AP7M6BPzCAtKUgTJgzcqs6ANVBwGxCiP68L7Xftay5jH C8h7_0fB4grcqUd.L1jY0GtDmYt.4v_8k1SbmUc_z5lAldTCRIXWZ[1].piPMVjjR22Ry9Pht9VLBW4pw GhrwZXrgryb_IvNG_a7g– not found! File\Folder C:\Documents and Settings\SaraAnn\Local Settings\Temp\Temporary Internet Files\Content.IE5\FVTLP80P\s-%2FJ%3D1262962485295041%2FK%3D9LOiQ5va6xIUJVKgOceHRg%2FA%3D5762049%2FR%3D0%2F%2A%24,http%3A%2F%2Fsports.yahoo[1].com%2Fufc%3B_ylt%3Dairisvh1ioelhegyn5sbebnjvbyf,;ord=1262962486 not found! File\Folder C:\Documents and Settings\SaraAnn\Local Settings\Temp\Temporary Internet Files\Content.IE5\A4M4VQQL\e5WXrWYC9r2Rs6n5[1].ODtlDggcMbqiXhRgpGqGFyuAtHEideFMM3qTfYIEpl4ucGQCErb9E5I A4OqXzBZHAv3KEw25XU4IxxJOibozdkUoFFkrfMxoWutSeQ8QJTXaHaxEGk1ONVZY9WA5qxlXbmzM8r7L vusztV2cfh9Ff_A6KeSGA- not found! File\Folder C:\Documents and Settings\SaraAnn\Local Settings\Temp\Temporary Internet Files\Content.IE5\5YJRQKWF\MJo9XCHH.d_FYvELbkYB8levfacNgILM31beWkxF7T9hZ5Pz8eAtlLgkcMLqjXhTgpGqGF2uCtH EqdeFMMnqUNgthupwQXjRNA3J.[1].aSQVWSd53Mi50q1NBxivM9RFrjFGk1KWQFU_5CAtoxlbahTM_tz B03Xt3rrK34_m3_gtA3xt1 not found! File\Folder C:\Documents and Settings\SaraAnn\Local Settings\Temp\Temporary Internet Files\Content.IE5\5YJRQKWF\QYihbiyTSt.T.iNQ8NpD57VejBEJY6Q7Chi9y1aRkFtJsoqzcwxiO9Ma5zhtnPtozeFe.GlNdK6 UrYDCFYoiYrfGNBn[1].PgFISD7iUhLKIpWmu8Ee6EEgcelwk0IujEGPySa5f7hM7Bo3pNKlAbgCnhO_s 790_1XyEX3MncAtU2IGA– not found! File\Folder C:\Documents and Settings\SaraAnn\Local Settings\Temp\Temporary Internet Files\Content.IE5\0DQ7KLEJ\BOCbYIpjJmvHoi_K_pWMy8YMkLS.riHp_NbxcJpyy5GkYu7AxQD3Q843SghO_8mEH9QvEAjC9pM j[1].SDodohuoxwjJvzMS4CjIfJu1cCCoeVszuXDO81u1DgFuZaMUqYmK0e7xJAkDgHUCW1dqFCj2sYuu 6ru1TZ5_nyqv8D6rkllw– not found! File\Folder C:\Documents and Settings\SaraAnn\Local Settings\Temp\Temporary Internet Files\Content.IE5\0DQ7KLEJ\rMVrzmnlUDdTD9WVreYC.p2IOfu.SxQF3JhDO6Aaom4kYASipsN7h48sREvgu6TxPpYx0JlDvsG QCEth.iU0OAw64NE4YZ.Iuibi_V5JAwLR2tJNRR61F4h4x3muhp1OCNzqcerip8jBFQNWtoUctivMHTde 3etsrfz9a_[1].Gzi3Oig- not found! File\Folder C:\Documents and Settings\SaraAnn\Local Settings\Temp\Temporary Internet Files\Content.IE5\0DQ7KLEJ\ZHK1vAEeXu8.uMNYVqlBTyHcfAiKNouJD7PoXfuyx0W08fuYLqXAqK.qNj5V.KX_L7v_sgMJwYZ TftSQVZepwuCKY.UYcgUawI7QzFcgE15whJpstsFYtBxZd9r8jPw8JzZbuITlOjtfxzr_W6KpzRT1UFB1 GRWdqrpt[1].0HyxwT8Q– not found! File\Folder C:\WINDOWS\temp\mcmsc_G0wfTiza9UfBMT5 not found! File\Folder C:\WINDOWS\temp\mcmsc_vHDEaJ1h8LLFeV3 not found! Registry entries deleted on Reboot…
Hello,

Your logs appear to be clean, so if you have no further issues with your computer, then please proceed with the following housekeeping procedures outlined below.



NEXT:



Please do the following:

Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

helpasst -cleanup


NEXT:



Time for some housekeeping
The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bolded text into the Run box and click OK: svkkfddu /Uninstall



NEXT:



OTL Clean-Up
Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.



NEXT:



All Clean Speech

===> Make sure you've re-enabled any Security Programs that we may have disabled during the malware removal process. <===

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at: http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated. Its important to keep programs up to date so that malware doesn't exploit any old security flaws.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE
  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from Here
    • If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
      • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Cheers,
SweetTech.
SweetTech, I performed the housekeeping tasks you outlined in you previous post, however, the second one that required running svkkfddu /Uninstall, I got a message that windows couldn't find that file so I just deleted the svkkfddu.exe file from the desktop. I hope that will be OK. The antivirus software on this machine was expired as my son didn't renew it. I purchased new antivirus software for him so I'll uninstall what he has and install this new one for him. Thank you so, so much for your help, I really appreciate it!
You are more than welcome. I'm truly glad that I was able to be of assistance to you. Please take care and stay clean and safe out their on the Internet. Cheers, ST.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI