This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

soooooooo sloooooooooow!

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:30:16 PM, on 8/8/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\WINDOWS\system32\lxdvcoms.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Lexmark X5400 Series\lxdvmon.exe
C:\Program Files\Lexmark X5400 Series\lxdvamon.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] "C:\Program Files\Verizon\McciTrayApp.exe"
O4 - HKLM\..\Run: [lxdvmon.exe] "C:\Program Files\Lexmark X5400 Series\lxdvmon.exe"
O4 - HKLM\..\Run: [lxdvamon] "C:\Program Files\Lexmark X5400 Series\lxdvamon.exe"
O4 - HKLM\..\Run: [Lexmark X5400 Series Fax Server] "C:\Program Files\Lexmark X5400 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe (User 'Default user')
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Copy Location - C:\WINDOWS\WEB\graburl.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\System32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to R&estricted Zone - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\System32\webzone.dll
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\System32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\System32\webzone.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Offline - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - C:\WINDOWS\System32\oline.dll
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-36.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1172773383140
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,16/mcgdmgr.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - file://D:\Bin\html\files\MotivePreQual.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O21 - SSODL: Cabmon - {9EAF44D1-D87A-4CA6-857D-194F77C84427} - C:\WINDOWS\system32\socknt.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: lxdvCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdvserv.exe
O23 - Service: lxdv_device - - C:\WINDOWS\system32\lxdvcoms.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe

–
End of file - 11714 bytes


thanks so muck for looking…
Hello devildog4

:welcome:

My name is Blottedisk, I'll be happy to assist you with all your malware problems you have on your computer. Solving any malware-related problem may or may not solve other issues you have with your machine. Before we start fixing your computer, there are a few points you need to know:

  • Please don't start a new topic, but reply on this one.
  • If you don't understand something, please ask!
  • If you find any new problems and/or details, please post them!
  • If you are unresponsive to this thread within three days, the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
  • As I'm still in training at What The Tech, all my posts needs to be checked by an expert first. This may cause a delay, but I will do my best to keep it as short as possible.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process. Please do not delete anything unless instructed to.

Remember: absence of symptoms does not mean your computer is clean.

Reply to this topic until I say your computer is clean. Please bear with me, I will post back to you as soon as I can.
Hi, I´m back. Lets start off with some homework for you :D

Please follow the steps below in order:


Step 1 | Please go to the following site to scan a file:

Virus Total

Click on Browse, and upload the following file for analysis:
  • C:\WINDOWS\system32\socknt.dll
Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.


Step 2 | Please download OTL from one of the following mirrors:

This is THE Mirror

——————————————————————–

  • Save it to your desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg 
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav 
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


Step 3 | Please download GMER from one of the following locations and save it to your desktop:

Main Mirror - This version will download a randomly named file (Recommended)
Zipped Mirror - This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

——————————————————————–

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.

Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

[external image: Posted Image]

  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Make sure all options are checked except:
    • IAT/EAT
    • Drives/Partition other than Systemdrive, which is typically C:\
    • Show All (This is important, so do not forget to untick it.)

    [external image: Posted Image]
    Click the image to enlarge it

  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.

– If you encounter any problems, try running GMER in Safe Mode.
Please keep the post open. I am posting from work as my home PC took a cr*p on me. I started it up and the HD started making terrible noises and would not boot. Now it is the shop awaiting word…
first link to virus total opened with Oops! This link appears broken.DNS error occurred. Server cannot be found.

OTL logfile created on: 8/14/2010 2:29:09 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\marty\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 416.00 Mb Available Physical Memory | 41.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 52.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 19.35 Gb Free Space | 51.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D22SP141
Current User Name: marty
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\marty\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lexmark X5400 Series\lxdvmon.exe ()
PRC - C:\Program Files\Lexmark X5400 Series\lxdvamon.exe ()
PRC - C:\WINDOWS\SYSTEM32\lxdvcoms.exe ( )
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Verizon\SmartBridge\MotiveSB.exe (Motive Communications, Inc.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe ()
PRC - C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe (Verizon)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (Musicmatch, Inc.)
PRC - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
PRC - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
PRC - C:\Program Files\Dell\Media Experience\PCM2.exe (CyberLink Corp.)
PRC - C:\Program Files\Microsoft Money\System\mnyexpr.exe (Microsoft Corp.)
PRC - C:\WINDOWS\SYSTEM32\brsvc01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\SYSTEM32\brss01a.exe (brother Industries Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\marty\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Common Files\Motive\McciContextHook_DSR.dll (Alcatel-Lucent)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\Verizon\SmartBridge\SBHook.dll (Motive Communications, Inc.)
MOD - C:\WINDOWS\SYSTEM32\cerdat.dll ()
MOD - C:\Documents and Settings\marty\Local Settings\Temp\IadHide5.dll (BackWeb)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (lxdv_device) – C:\WINDOWS\System32\lxdvcoms.exe ( )
SRV - (lxdvCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdvserv.exe ()
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (Brother XP spl Service) – C:\WINDOWS\SYSTEM32\brsvc01a.exe (brother Industries Ltd)


========== Driver Services (SafeList) ==========

DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (iAimTV2) – C:\WINDOWS\System32\DRIVERS\wATV03nt.sys File not found
DRV - (A4SII300) – C:\WINDOWS\System32\drivers\A4SII300.SYS File not found
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (BrScnUsb) – C:\WINDOWS\SYSTEM32\DRIVERS\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (tfsnudfa) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (sscdbhk5) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: *CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/06/05 14:34:50 | 000,000,000 | —D | M]


O1 HOSTS File: ([2008/12/24 11:43:33 | 000,291,477 | R— | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 10039 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [Lexmark X5400 Series Fax Server] C:\Program Files\Lexmark X5400 Series\fm3032.exe ()
O4 - HKLM..\Run: [lxdvamon] C:\Program Files\Lexmark X5400 Series\lxdvamon.exe ()
O4 - HKLM..\Run: [lxdvmon.exe] C:\Program Files\Lexmark X5400 Series\lxdvmon.exe ()
O4 - HKLM..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [Motive SmartBridge] C:\Program Files\Verizon\SmartBridge\MotiveSB.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Scansoft, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe (Verizon)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [MoneyAgent] C:\Program Files\Microsoft Money\System\mnyexpr.exe (Microsoft Corp.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKLM..\RunOnceEx: [] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Copy Location - C:\WINDOWS\Web\graburl.htm ()
O9 - Extra 'Tools' menuitem : Add to R&estricted Zone - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\SYSTEM32\webzone.dll ()
O9 - Extra 'Tools' menuitem : Add to Tr&usted Zone - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\SYSTEM32\webzone.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Offline - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - C:\WINDOWS\SYSTEM32\oline.dll ()
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.windowsupdate] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.windowsupdate] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([download] http in Trusted sites)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: whatthetech.com ([forums] http in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/d/4…0367/wmavax.CAB (Reg Error: Key error.)
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} http://www.pcpitstop.com/internet/pcpConnCheck.cab (iCC Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Yahoo! Audio Conferencing)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-36.cab (EPUImageControl Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1172773383140 (MUWebControl Class)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab (HouseCall Control)
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Yahoo! Audio UI1)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://bin.mcafee.com/molbin/shared/mcgdmg…,16/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} file://D:\Bin\html\files\MotivePreQual.cab (PreQualifier Class)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O21 - SSODL: Cabmon - {9EAF44D1-D87A-4CA6-857D-194F77C84427} - C:\WINDOWS\SYSTEM32\socknt.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\marty\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\marty\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 07:59:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: Ip6FwHlp - File not found

Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\MSG711.ACM (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\MSG723.ACM (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\MSGSM32.ACM (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\MSACM32.DRV (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902053519425536)

========== Files/Folders - Created Within 30 Days ==========

[2010/08/14 13:54:23 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\marty\Desktop\OTL.exe
[2010/08/14 13:48:23 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/08/10 12:02:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/08/10 11:06:57 | 000,000,000 | —D | C] – C:\Program Files\RegCure
[2010/08/10 11:06:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\RegCure
[2010/08/10 10:42:27 | 000,000,000 | -HSD | C] – C:\Documents and Settings\marty\IECompatCache
[2010/08/10 10:32:53 | 000,000,000 | —D | C] – C:\Documents and Settings\marty\Application Data\ElevatedDiagnostics
[2010/08/10 10:27:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2010/08/10 10:24:56 | 000,000,000 | -HSD | C] – C:\Documents and Settings\marty\PrivacIE
[2010/08/10 10:20:17 | 000,000,000 | -HSD | C] – C:\Documents and Settings\marty\IETldCache
[2010/08/10 10:15:45 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2010/08/10 10:10:19 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/08/10 09:59:44 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/08/09 05:31:15 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2010/08/09 00:28:32 | 003,129,400 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\marty\My Documents\WindowsXP-KB936929-SP3-x86-ENU.exe
[2010/08/08 22:35:42 | 001,372,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2010/08/08 22:35:42 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2010/08/08 22:35:29 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2010/08/08 22:35:26 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2010/08/08 22:35:26 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2010/08/08 22:35:24 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2010/08/08 22:35:24 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2010/08/08 22:35:24 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2010/08/08 22:35:24 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2010/08/08 22:35:24 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2010/08/08 22:35:24 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3api.dll
[2010/08/08 22:35:24 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3dlg.dll
[2010/08/08 22:35:23 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2010/08/08 22:35:23 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2010/08/08 22:35:23 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2010/08/08 22:35:23 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappcfg.dll
[2010/08/08 22:35:23 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2010/08/08 22:35:23 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappprxy.dll
[2010/08/08 22:35:23 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapolqec.dll
[2010/08/08 22:35:22 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2010/08/08 22:35:21 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2010/08/08 22:35:20 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2010/08/08 22:35:20 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2010/08/08 22:35:20 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2010/08/08 22:35:19 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2010/08/08 22:35:19 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2010/08/08 22:35:18 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2010/08/08 22:35:18 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2010/08/08 22:35:18 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2010/08/08 22:35:18 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2010/08/08 22:35:18 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2010/08/08 22:35:17 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2010/08/08 22:35:17 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2010/08/08 22:35:17 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\onex.dll
[2010/08/08 22:35:17 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2010/08/08 22:35:15 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2010/08/08 22:35:15 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2010/08/08 22:35:15 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qutil.dll
[2010/08/08 22:35:15 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2010/08/08 22:35:15 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rasqec.dll
[2010/08/08 22:35:15 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2010/08/08 22:35:14 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2010/08/08 22:35:12 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2010/08/08 22:35:09 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2010/08/08 22:35:06 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2010/08/08 22:35:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2010/08/08 22:25:21 | 000,144,384 | —- | C] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\System32\drivers\hdaudbus.sys
[2010/08/08 16:28:45 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/06 22:47:38 | 000,000,000 | RH-D | C] – C:\Documents and Settings\marty\Recent
[2008/05/07 13:57:34 | 000,438,272 | —- | C] ( ) – C:\WINDOWS\System32\LXDVhcp.dll
[2008/05/07 13:57:34 | 000,360,448 | —- | C] ( ) – C:\WINDOWS\System32\lxdvinpa.dll
[2008/05/07 13:57:33 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdviesc.dll
[2008/05/07 13:57:27 | 000,954,368 | —- | C] ( ) – C:\WINDOWS\System32\lxdvusb1.dll
[2008/05/07 13:57:26 | 001,069,056 | —- | C] ( ) – C:\WINDOWS\System32\lxdvserv.dll
[2008/05/07 13:57:26 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdvprox.dll
[2008/05/07 13:57:25 | 000,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxdvpmui.dll
[2008/05/07 13:57:24 | 000,569,344 | —- | C] ( ) – C:\WINDOWS\System32\lxdvlmpm.dll
[2008/05/07 13:57:16 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\lxdvhbn3.dll
[2008/05/07 13:57:10 | 000,851,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdvcomc.dll
[2008/05/07 13:57:10 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxdvcomm.dll
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/14 13:54:28 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\marty\Desktop\OTL.exe
[2010/08/14 13:48:34 | 000,002,473 | —- | M] () – C:\Documents and Settings\marty\Desktop\Microsoft Word.lnk
[2010/08/14 13:43:46 | 063,430,874 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/08/14 13:39:12 | 003,213,312 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2010/08/14 13:39:11 | 001,573,888 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2010/08/14 13:36:52 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/08/14 13:36:08 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/08/14 13:32:35 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3866278144-2575844472-1593893423-1007.job
[2010/08/14 13:32:33 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3866278144-2575844472-1593893423-1008.job
[2010/08/14 13:32:27 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/14 13:32:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/08/14 13:32:18 | 1071,714,304 | -HS- | M] () – C:\hiberfil.sys
[2010/08/10 12:16:49 | 006,815,744 | —- | M] () – C:\Documents and Settings\marty\ntuser.dat
[2010/08/10 12:16:49 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\marty\NTUSER.INI
[2010/08/10 12:06:37 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/08/10 11:25:06 | 000,000,390 | —- | M] () – C:\WINDOWS\tasks\RegCure Program Check.job
[2010/08/10 11:24:57 | 000,000,738 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RegCure.lnk
[2010/08/10 11:07:08 | 000,000,372 | —- | M] () – C:\WINDOWS\tasks\RegCure.job
[2010/08/10 10:20:34 | 000,000,815 | —- | M] () – C:\Documents and Settings\marty\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/10 10:17:44 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/09 05:48:36 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3866278144-2575844472-1593893423-1007.job
[2010/08/09 05:46:50 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/08/09 05:34:26 | 000,524,016 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/09 05:34:26 | 000,442,466 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2010/08/09 05:34:26 | 000,071,732 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2010/08/09 05:33:01 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2010/08/09 05:30:40 | 000,161,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/09 00:28:41 | 003,129,400 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\marty\My Documents\WindowsXP-KB936929-SP3-x86-ENU.exe
[2010/08/09 00:11:25 | 000,002,447 | —- | M] () – C:\Documents and Settings\marty\Desktop\HiJackThis.lnk
[2010/08/08 22:24:47 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2010/08/08 15:39:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3866278144-2575844472-1593893423-1008.job
[2010/07/26 23:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/10 11:07:08 | 000,000,390 | —- | C] () – C:\WINDOWS\tasks\RegCure Program Check.job
[2010/08/10 11:07:06 | 000,000,372 | —- | C] () – C:\WINDOWS\tasks\RegCure.job
[2010/08/10 11:06:59 | 000,000,738 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RegCure.lnk
[2010/08/08 22:23:14 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/08/08 21:21:01 | 000,000,278 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3866278144-2575844472-1593893423-1007.job
[2010/08/08 16:28:45 | 000,002,447 | —- | C] () – C:\Documents and Settings\marty\Desktop\HiJackThis.lnk
[2009/11/14 09:24:48 | 000,307,200 | —- | C] () – C:\WINDOWS\System32\AscSQLite.dll
[2008/05/07 14:09:52 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdvvs.dll
[2008/05/07 14:09:42 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\lxdvcoin.dll
[2008/05/07 14:07:39 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\lxdvcaps.dll
[2008/05/07 14:07:38 | 000,692,224 | —- | C] () – C:\WINDOWS\System32\lxdvdrs.dll
[2008/05/07 14:07:37 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdvcnv4.dll
[2008/05/07 14:06:15 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\LXDVPMON.DLL
[2008/05/07 14:06:15 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\LXDVFXPU.DLL
[2008/05/07 14:05:55 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdvoem.dll
[2008/05/07 13:58:48 | 000,000,060 | —- | C] () – C:\WINDOWS\System32\lxdvrwrd.ini
[2008/05/07 13:57:35 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\LXDVinst.dll
[2008/05/07 13:57:15 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdvgrd.dll
[2008/02/06 23:09:13 | 000,003,120 | —- | C] () – C:\WINDOWS\BCDSS08.ini
[2007/03/28 16:58:05 | 000,000,066 | —- | C] () – C:\WINDOWS\LAKESC~1.ini
[2007/03/01 10:47:50 | 000,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2006/07/02 10:23:13 | 000,000,051 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2006/07/02 10:23:12 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_2460.ini
[2006/02/25 14:06:27 | 000,002,697 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2006/02/25 09:39:55 | 000,000,000 | —- | C] () – C:\WINDOWS\Brownie.ini
[2006/02/20 18:33:36 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2006/02/20 18:31:52 | 000,001,163 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2006/02/20 18:31:52 | 000,000,147 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2006/02/20 18:31:51 | 000,000,462 | —- | C] () – C:\WINDOWS\brwmark.ini
[2006/02/20 18:31:51 | 000,000,079 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2006/02/20 18:27:24 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2005/11/12 20:32:17 | 000,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2004/12/03 20:17:38 | 000,000,021 | —- | C] () – C:\WINDOWS\PI_setup.ini
[2004/12/03 20:16:05 | 000,000,022 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2004/12/03 20:03:37 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2004/12/03 20:01:32 | 000,000,227 | —- | C] () – C:\WINDOWS\EPSON CX6600 Installer.ini
[2004/05/31 16:43:13 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2004/02/23 20:59:29 | 000,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004/02/23 20:59:29 | 000,000,823 | —- | C] () – C:\WINDOWS\TSC.ini
[2004/02/23 20:58:23 | 000,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004/02/11 12:53:16 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/02/03 07:05:00 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\EPSPTDV.DLL
[2004/01/24 19:23:47 | 000,000,037 | —- | C] () – C:\WINDOWS\ImgView.INI
[2004/01/24 12:21:46 | 000,000,000 | —- | C] () – C:\WINDOWS\Mailmark.ini
[2004/01/24 12:19:26 | 000,026,112 | —- | C] () – C:\WINDOWS\System32\PIXTHK32.DLL
[2004/01/24 12:19:26 | 000,012,126 | —- | C] () – C:\WINDOWS\System32\PIXPCZ.DLL
[2004/01/24 12:19:26 | 000,011,934 | —- | C] () – C:\WINDOWS\System32\PIXPNR.DLL
[2004/01/24 12:18:45 | 000,001,901 | —- | C] () – C:\WINDOWS\ATM.INI
[2004/01/24 12:18:45 | 000,001,716 | —- | C] () – C:\WINDOWS\ACROREAD.INI
[2004/01/24 12:18:45 | 000,000,027 | —- | C] () – C:\WINDOWS\ACROGRAF.INI
[2004/01/24 12:18:33 | 000,000,298 | —- | C] () – C:\WINDOWS\moffice.ini
[2004/01/24 12:18:22 | 000,000,131 | —- | C] () – C:\WINDOWS\CusDlg.INI
[2004/01/21 11:17:41 | 000,000,048 | —- | C] () – C:\WINDOWS\PerWin.ini
[2003/12/25 13:52:27 | 000,000,000 | —- | C] () – C:\WINDOWS\SpecCheck.INI
[2003/12/25 12:27:48 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/12/18 09:26:38 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/12/18 09:12:39 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2003/12/18 09:08:54 | 000,000,788 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/12/18 08:51:44 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/12/18 08:51:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/12/18 08:37:52 | 000,000,549 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/08/13 21:54:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2002/11/01 17:17:50 | 000,000,256 | —- | C] () – C:\WINDOWS\aucfg.ini
[2002/08/29 04:00:00 | 000,823,296 | —- | C] () – C:\WINDOWS\System32\socknt.dll
[2002/08/29 04:00:00 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\cerdat.dll
[2002/08/29 04:00:00 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\confbin.dll
[2002/08/29 04:00:00 | 000,144,371 | —- | C] () – C:\WINDOWS\System32\usbdel32.dll
[2002/07/04 16:05:34 | 000,000,269 | —- | C] () – C:\WINDOWS\tmupdate.ini
[2002/03/04 11:16:34 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Jpeg32.dll
[2001/12/14 13:34:46 | 000,164,864 | —- | C] () – C:\WINDOWS\patchw32.dll
[2001/07/25 13:00:10 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\HWINV.DLL
[2001/07/25 13:00:10 | 000,026,572 | —- | C] () – C:\WINDOWS\System32\INV16.DLL
[2000/09/08 18:53:50 | 000,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1999/08/02 16:50:48 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1999/07/23 13:46:48 | 000,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 10:53:20 | 000,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1999/03/01 12:03:28 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\webzone.dll
[1999/02/23 19:00:28 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\oline.dll

========== LOP Check ==========

[2008/12/24 15:41:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ascentive
[2010/08/10 11:00:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/08/10 12:02:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/08/10 11:36:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegCure
[2006/02/20 18:26:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2003/12/18 09:15:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/05/07 14:05:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\X5400 Series
[2008/12/24 15:49:57 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\Ascentive
[2005/01/20 13:57:53 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\Broderbund Software
[2010/08/10 10:32:53 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\ElevatedDiagnostics
[2005/11/16 12:25:07 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\EPSON
[2007/05/24 16:54:59 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\Erickson
[2010/06/03 03:20:44 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\JonDo
[2004/12/03 20:21:23 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\Leadertech
[2008/05/07 14:21:25 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\Lexmark Productivity Studio
[2006/03/18 12:19:58 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\Musicmatch
[2006/04/13 15:07:39 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\PlayFirst
[2008/05/07 21:05:57 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\ScanSoft
[2008/07/21 19:31:24 | 000,000,000 | —D | M] – C:\Documents and Settings\marty\Application Data\X5400 Series
[2003/12/23 21:22:07 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job
[2010/08/10 11:25:06 | 000,000,390 | —- | M] () – C:\WINDOWS\Tasks\RegCure Program Check.job
[2010/08/10 11:07:08 | 000,000,372 | —- | M] () – C:\WINDOWS\Tasks\RegCure.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2002/09/03 07:59:58 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2005/01/29 03:52:26 | 005,876,980 | RHS- | M] () – C:\AVG6DB_F.DAT
[2009/10/10 20:53:16 | 000,000,211 | RHS- | M] () – C:\BOOT.INI
[2002/09/03 07:38:46 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2002/09/03 07:59:58 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2004/01/24 19:28:18 | 000,000,278 | —- | M] () – C:\default.set
[2003/12/18 08:42:30 | 000,005,370 | RH– | M] () – C:\DELL.SDR
[2009/01/27 14:03:37 | 000,000,000 | —- | M] () – C:\faxendPdoc.log
[2010/08/14 13:32:18 | 1071,714,304 | -HS- | M] () – C:\hiberfil.sys
[2005/04/27 14:05:32 | 000,000,179 | —- | M] () – C:\INSTALL.LOG
[2002/09/03 07:59:58 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2003/12/18 09:15:24 | 000,000,869 | -H– | M] () – C:\IPH.PH
[2002/09/03 07:59:58 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/09/09 08:10:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/08 22:24:47 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2010/08/14 13:32:17 | 402,653,184 | -HS- | M] () – C:\pagefile.sys
[2006/08/27 19:29:11 | 000,004,004 | —- | M] () – C:\Rescued document.txt

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2002/09/03 07:59:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/02/09 01:00:00 | 000,026,285 | —- | M] (Brother Industries ,Ltd ) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\brmfpp1.dll
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
[2007/05/02 16:38:35 | 000,113,664 | —- | M] () – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\lxdvdrpp.dll
[2001/11/20 15:37:28 | 000,047,616 | R— | M] (Black Ice Software) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\ppbiPr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >
[2003/07/24 09:43:40 | 001,712,063 | —- | M] (Rhode Island Soft Systems, Inc.) – C:\WINDOWS\Lake Scenes.scr
[2003/09/19 16:14:14 | 000,167,936 | —- | M] () – C:\WINDOWS\Living Marine Aquarium.scr
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2004/08/04 00:56:42 | 000,757,760 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\cerdat.dll
[2004/08/04 00:56:42 | 000,180,224 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\confbin.dll
[2009/03/08 04:31:44 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\dxtrans.dll
[2004/08/04 00:56:42 | 000,823,296 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\socknt.dll
[2009/03/21 07:06:58 | 000,144,371 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\usbdel32.dll
[7 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2002/09/03 07:47:18 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2002/09/03 07:47:18 | 000,602,112 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2002/09/03 07:47:18 | 000,380,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %systemroot%\system32\user32.dll /md5 >
[2008/04/14 05:42:10 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B – C:\WINDOWS\SYSTEM32\user32.dll
[7 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/14 05:42:12 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A – C:\WINDOWS\SYSTEM32\ws2_32.dll
[7 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/14 05:42:12 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 – C:\WINDOWS\SYSTEM32\ws2help.dll
[7 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-10 19:20:30
< End of report >
OTL Extras logfile created on: 8/14/2010 2:41:16 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\marty\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 363.00 Mb Available Physical Memory | 36.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 51.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 19.75 Gb Free Space | 53.07% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D22SP141
Current User Name: marty
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater – ()
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealOne Player – (RealNetworks, Inc.)
"C:\Program Files\Yahoo! Games\Alien Shooter\AlienShooter.exe" = C:\Program Files\Yahoo! Games\Alien Shooter\AlienShooter.exe:*:Disabled:AlienShooter Application – File not found
"C:\Program Files\Yahoo! Games\Yahoo! Ten Pin Championship Bowling\Yahoo Ten Pin Championship Bowling.exe" = C:\Program Files\Yahoo! Games\Yahoo! Ten Pin Championship Bowling\Yahoo Ten Pin Championship Bowling.exe:*:Enabled:Skyworks Ten Pin Championship Bowling – File not found
"C:\Program Files\Yahoo! Games\Rock N Rockets\RocksAndRockets.exe" = C:\Program Files\Yahoo! Games\Rock N Rockets\RocksAndRockets.exe:*:Enabled:TikGames Game Executable – File not found
"C:\Program Files\Yahoo! Games\Tradewinds\tradewinds.exe" = C:\Program Files\Yahoo! Games\Tradewinds\tradewinds.exe:*:Enabled:tradewinds – ()
"C:\Program Files\Yahoo! Games\Hamsterball\Hamsterball.exe" = C:\Program Files\Yahoo! Games\Hamsterball\Hamsterball.exe:*:Enabled:Hamsterball – (Raptisoft, LLC)
"C:\Program Files\WildTangent\Blasterball 2\BB2.exe" = C:\Program Files\WildTangent\Blasterball 2\BB2.exe:*:Enabled:BB2 – File not found
"C:\Program Files\Yahoo! Games\Final Drive Nitro\Racing.exe" = C:\Program Files\Yahoo! Games\Final Drive Nitro\Racing.exe:*:Enabled:Racing – File not found
"C:\Program Files\Yahoo! Games\Blackhawk Striker 2\Blackhawk2.exe" = C:\Program Files\Yahoo! Games\Blackhawk Striker 2\Blackhawk2.exe:*:Enabled:Black Hawk Striker 2 – File not found
"C:\Program Files\Yahoo! Games\JEOPARDY!\JEOPARDY!.exe" = C:\Program Files\Yahoo! Games\JEOPARDY!\JEOPARDY!.exe:*:Enabled:JEOPARDY! – (Sony Pictures Digital Networks Inc.)
"C:\Program Files\Marble Blast Gold\MarbleBlast.exe" = C:\Program Files\Marble Blast Gold\MarbleBlast.exe:*:Enabled:MarbleBlast – File not found
"C:\Program Files\Alphaqueue\alphaqueue.exe" = C:\Program Files\Alphaqueue\alphaqueue.exe:*:Enabled:Macromedia Projector – File not found
"C:\Program Files\Yahoo! Games\Blasterball 2 Remix\bb2remix.exe" = C:\Program Files\Yahoo! Games\Blasterball 2 Remix\bb2remix.exe:*:Enabled:bb2remix – File not found
"C:\Program Files\Yahoo! Games\Magic Ball\MagicBall.exe" = C:\Program Files\Yahoo! Games\Magic Ball\MagicBall.exe:*:Enabled:MagicBall – File not found
"C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\Program Files\TurboTax\Deluxe 2006\32bit\ttax.exe" = C:\Program Files\TurboTax\Deluxe 2006\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"C:\Program Files\TurboTax\Deluxe 2006\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Deluxe 2006\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – ()
"C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)
"C:\Program Files\Lexmark X5400 Series\lxdvamon.exe" = C:\Program Files\Lexmark X5400 Series\lxdvamon.exe:*:Enabled:Lexmark Device Monitor – ()
"C:\Program Files\Lexmark X5400 Series\frun.exe" = C:\Program Files\Lexmark X5400 Series\frun.exe:*:Enabled:Lexmark Productivity Studio – ()
"C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe" = C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:*:Enabled:ABBYY FineReader – (ABBYY (BIT Software))
"C:\Program Files\Lexmark X5400 Series\lxdvmon.exe" = C:\Program Files\Lexmark X5400 Series\lxdvmon.exe:*:Enabled:Printer Device Monitor – ()
"C:\WINDOWS\SYSTEM32\lxdvcoms.exe" = C:\WINDOWS\SYSTEM32\lxdvcoms.exe:*:Enabled:Lexmark Communications System – ( )
"C:\Program Files\Lexmark X5400 Series\LXDVFax.exe" = C:\Program Files\Lexmark X5400 Series\LXDVFax.exe:*:Enabled:Fax Solutions Software – ()
"C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\lxdvpswx.exe" = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\lxdvpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\lxdvjswx.exe" = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\lxdvjswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\lxdvtime.exe" = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\lxdvtime.exe:*:Enabled:Lexmark Connect Time Executable – (Lexmark International, Inc.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{04410044-9149-45C6-A806-F2BF9CFCE762}" = Microsoft Encarta Encyclopedia Standard 2004
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{2266312B-3502-41EE-82CD-8DC62276D87B}" = Vz In Home Agent
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}" = TurboTax ItsDeductible 2005
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{360EDFB0-EAA2-012B-AD16-000000000000}" = TurboTax 2009 wcaiper
"{36495C59-089C-49D1-BD15-9E5BD86DC9A1}" = ItsDeductible Express
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{432C3720-37BF-4BD7-8E49-F38E090246D0}" = CR2
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{54C8FE84-89C4-40E8-976C-439EB0729BD6}" = CardRd81
"{5B30AA25-BF39-4BE4-8FEE-51938BAB214D}" = TurboTax 2008 wcaiper
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{66C8BE35-8BBB-472B-96C7-C7C9A499F988}" = ArcSoft Software Suite
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{95C2FBF3-4462-41E3-89DC-0F784387BD53}" = Family Lawyer 2004
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9B79DCB0-AAD7-456B-8D07-433C936FA24B}" = DS21Patch
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = iSEEK AnswerWorks English Runtime
"{A0AF08BA-3630-4505-BFB2-A41F3837B0D0}" = SFR2
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1973749-F5E7-40EB-B528-F2B78685B9FF}" = essvcpt
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FAF7F1D7-C0E7-47EA-8AAA-84E4F9EA3C94}" = Works Suite OS Pack
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"{FF0D5234-E7D8-41DA-9287-C89C3B045ADC}" = Vz In Home Agent
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG8Uninstall" = AVG Free 8.5
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"CCleaner" = CCleaner (remove only)
"CSRS-FERS BenCalc-RetPlan832_is1" = Federal Retirement 2008
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"EPSON Printer and Utilities" = EPSON Printer Software
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"IE5WA" = Microsoft Internet Explorer 5 PowerTweaks Web Accessory
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"JEOPARDY!" = JEOPARDY! (remove only)
"Lake Scenes Screen Saver" = Lake Scenes Screen Saver
"Lexmark X5400 Series" = Lexmark X5400 Series
"Living Marine Aquarium Screen Saver" = Living Marine Aquarium Screen Saver
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSN Music Assistant" = MSN Music Assistant
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"QuickTime" = QuickTime
"RadialpointClientGateway_is1" = Verizon Servicepoint 1.3.21
"RealPlayer 12.0" = RealPlayer
"RegCure" = RegCure
"Shockwave" = Shockwave
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Tradewinds for Yahoo" = Tradewinds (remove only)
"TurboTax 2008" = TurboTax 2008
"TurboTax 2009" = TurboTax 2009
"TurboTax Deluxe 2003" = TurboTax Deluxe 2003
"TurboTax Deluxe 2004" = TurboTax Deluxe 2004
"TurboTax Deluxe 2005" = TurboTax Deluxe 2005
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"TurboTax Deluxe Deduction Maximizer 2006" = TurboTax Deluxe Deduction Maximizer 2006
"Verizon Help and Support" = Verizon Help and Support Tool
"Verizon Online DSL_is1" = Verizon Online DSL
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ System Events ]
Error - 8/10/2010 12:51:16 PM | Computer Name = D22SP141 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdvCATSCustConnectService
service to connect.

Error - 8/10/2010 12:51:16 PM | Computer Name = D22SP141 | Source = Service Control Manager | ID = 7000
Description = The lxdvCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 8/10/2010 1:20:18 PM | Computer Name = D22SP141 | Source = Service Control Manager | ID = 7000
Description = The A4SII300 service failed to start due to the following error: %%2

Error - 8/10/2010 1:20:18 PM | Computer Name = D22SP141 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdvCATSCustConnectService
service to connect.

Error - 8/10/2010 1:20:18 PM | Computer Name = D22SP141 | Source = Service Control Manager | ID = 7000
Description = The lxdvCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 8/10/2010 2:19:08 PM | Computer Name = D22SP141 | Source = Print | ID = 6161
Description = The document http://safecart.com/paretologic/regcure/re…?session_id=3L4
owned by marty failed to print on printer Lexmark X5400 Series. Data type: LEMF.
Size of the spool file in bytes: 1522548. Number of bytes printed: 0. Total number
of pages in the document: 4. Number of pages printed: 1. Client machine: \\D22SP141.
Win32 error code returned by the print processor: 0 (0x0).

Error - 8/10/2010 2:27:21 PM | Computer Name = D22SP141 | Source = Print | ID = 6161
Description = The document http://safecart.com/paretologic/regcure/re…?session_id=3L4
owned by marty failed to print on printer Lexmark X5400 Series. Data type: LEMF.
Size of the spool file in bytes: 1522548. Number of bytes printed: 0. Total number
of pages in the document: 4. Number of pages printed: 1. Client machine: \\D22SP141.
Win32 error code returned by the print processor: 0 (0x0).

Error - 8/14/2010 4:33:05 PM | Computer Name = D22SP141 | Source = Service Control Manager | ID = 7000
Description = The A4SII300 service failed to start due to the following error: %%2

Error - 8/14/2010 4:33:05 PM | Computer Name = D22SP141 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdvCATSCustConnectService
service to connect.

Error - 8/14/2010 4:33:05 PM | Computer Name = D22SP141 | Source = Service Control Manager | ID = 7000
Description = The lxdvCATSCustConnectService service failed to start due to the
following error: %%1053


< End of report >
during the middle of running GMER I got a windows virtual memory msg and arror msg saying it could not continue to run. I will try it again and then try in safe mode.
after several attempts and getting the windows virtual memory error it went thru. Here is the log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-14 21:00:17
Windows 5.1.2600 Service Pack 3
Running: 8yzwio94.exe; Driver: C:\DOCUME~1\marty\LOCALS~1\Temp\uwtoapog.sys


—- User code sections - GMER 1.0.15 —-

.text C:\Documents and Settings\marty\Desktop\8yzwio94.exe[1952] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BCB900 C:\WINDOWS\system32\cerdat.dll
.text C:\Documents and Settings\marty\Desktop\8yzwio94.exe[1952] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BCB9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\WINDOWS\system32\dla\tfswctrl.exe[2116] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00EBB900 C:\WINDOWS\system32\cerdat.dll
.text C:\WINDOWS\system32\dla\tfswctrl.exe[2116] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00EBB9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Dell\Media Experience\PCMService.exe[2124] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Dell\Media Experience\PCMService.exe[2124] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe[2188] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe[2188] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe[2220] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe[2220] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Verizon\McciTrayApp.exe[2256] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Verizon\McciTrayApp.exe[2256] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Lexmark X5400 Series\lxdvmon.exe[2268] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00AEB900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Lexmark X5400 Series\lxdvmon.exe[2268] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00AEB9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Lexmark X5400 Series\lxdvamon.exe[2284] KERNEL32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Lexmark X5400 Series\lxdvamon.exe[2284] KERNEL32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe[2416] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe[2416] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2480] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2480] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\QuickTime\qttask.exe[2504] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\QuickTime\qttask.exe[2504] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2552] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[2552] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Microsoft Money\System\mnyexpr.exe[2676] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Microsoft Money\System\mnyexpr.exe[2676] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\DellSupport\DSAgnt.exe[2716] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\DellSupport\DSAgnt.exe[2716] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\WINDOWS\system32\ctfmon.exe[2752] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\WINDOWS\system32\ctfmon.exe[2752] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2764] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2764] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe[2956] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002B900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe[2956] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002B9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe[2968] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FCB900 C:\WINDOWS\system32\cerdat.dll
.text C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe[2968] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FCB9D0 C:\WINDOWS\system32\cerdat.dll
.text C:\WINDOWS\system32\wuauclt.exe[3384] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B2B900 C:\WINDOWS\system32\cerdat.dll
.text C:\WINDOWS\system32\wuauclt.exe[3384] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B2B9D0 C:\WINDOWS\system32\cerdat.dll

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-
Hi there, thanks for the logs.


How´s the computer running now?
Please do the folloing:


Go to VirSCAN.org FREE on-line scan service

  • When the page has finished loading, click the "Browse" button and navigate to the following files and click open:

    C:\WINDOWS\System32\socknt.dll
    C:\WINDOWS\System32\cerdat.dll
    C:\WINDOWS\System32\confbin.dll
    C:\WINDOWS\System32\usbdel32.dll
    C:\WINDOWS\System32\AscSQLite.dll

  • Click on the "Upload" button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Note: You will not be able to upload and scan all files at once. You will have to upload and scan each file separately.
Blottedisk:

I took my PC in to the shop. I had a wire wrapped around the fan that they fixed. They wanted 400 to buy & install RAM, buy & install another HD, buy & install another OS and backup my documents and photos. I declined and picked up the unit. It makes as much (or as little) noise as before, it is just so slow at everything. Anyway, I tried the VirSCAN.org FREE thing. I saw the first 4 files, but when I tried to upload I got the error msg ERROR CANT FIND UPLOAD FILE! Here is the report for the fifth file:

VirSCAN.org Scanned Report :
Scanned time : 2010/08/17 00:48:19 (CST)
Scanner results: Scanners did not find malware!
File Name : AscSQLite.dll
File Size : 307200 byte
File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
MD5 : f1978648d1d04d84cac8c2f8fb32ec70
SHA1 : 69ecfb4a721e99b087c0e936a3d72a7da4ff846a
Online report : http://virscan.org/report/1dfa5ed19918f69d…caf97d3af2.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.0.0.18 20100815000844 2010-08-15 0.08 -
AhnLab V3 2010.08.07.00 2010.08.07 2010-08-07 0.08 -
AntiVir 8.2.4.34 7.10.10.186 2010-08-16 0.28 -
Antiy 2.0.18 20100815.4936744 2010-08-15 0.02 -
Arcavir 2009 201006281601 2010-06-28 0.00 -
Authentium 5.1.1 201008161316 2010-08-16 2.13 -
AVAST! 4.7.4 100816-0 2010-08-16 0.02 -
AVG 8.5.793 271.1.1/3075 2010-08-16 0.27 -
BitDefender 7.90123.6150634 7.33387 2010-08-17 4.45 -
ClamAV 0.96.1 11563 2010-08-16 0.07 -
Comodo 4.0 5761 2010-08-16 0.11 -
CP Secure 1.3.0.5 2010.08.17 2010-08-17 0.09 -
Dr.Web 5.0.2.3300 2010.08.17 2010-08-17 9.02 -
F-Prot 4.4.4.56 20100816 2010-08-16 2.61 -
F-Secure 7.02.73807 2010.08.16.01 2010-08-16 0.20 -
Fortinet 4.1.143 12.254 2010-08-16 0.08 -
GData 21.681/21.261 20100816 2010-08-16 0.08 -
ViRobot 20100814 2010.08.14 2010-08-14 0.09 -
Ikarus T3. 2010.08.16.76519 2010-08-16 4.97 -
JiangMin 13.0.900 2010.08.16 2010-08-16 0.08 -
Kaspersky 5.5.10 2010.08.16 2010-08-16 0.14 -
KingSoft 2009.2.5.15 2010.8.15.7 2010-08-15 0.08 -
McAfee 5400.1158 6075 2010-08-15 17.57 -
Microsoft 1.6004 2010.08.16 2010-08-16 0.08 -
Norman 6.05.11 6.05.00 2010-08-16 6.01 -
Panda 9.05.01 2010.08.15 2010-08-15 0.08 -
Trend Micro 9.120-1004 7.388.11 2010-08-16 0.00 -
Quick Heal 11.00 2010.08.16 2010-08-16 0.08 -
Rising 20.0 22.61.00.04 2010-08-16 0.08 -
Sophos 3.10.0 4.56 2010-08-17 4.22 -
Sunbelt 3.9.2432.2 6741 2010-08-16 0.08 -
Symantec 1.3.0.24 20100814.002 2010-08-14 0.06 -
nProtect 20100816.02 8811137 2010-08-16 0.08 -
The Hacker 6.5.2.1 v00349 2010-08-16 0.08 -
VBA32 3.12.14.0 20100813.0808 2010-08-13 3.63 -
VirusBuster 4.5.11.10 10.127.57/2035057 2010-08-16 2.48 -

thanks for taking the time to help me…
Hi,


That´s ok. AscSQLite.dll is clean. Please do the following:


Step 1 | Please go here and have a look how you can disable your security software (AVG and Spybot S&D).

Download Combofix from any of the links below:

Link 1
Link 2

——————————————————————–

  • Double click on Combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


  • Click on Yes, to continue scanning for malware.
  • When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper.


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
BLOTTEDISK: I TRIED THE FIRST LINK AND GOT THE ERROR MSG " YOU CANNOT RENAME COMBOFIX AN COMBOFIX[1] PLEASE USE ANOTHER NAME, PREFERABLY MADE UP OF ALPHANUMERIC CHARACTORS". I TRIED THE 2ND LINK AND IT IS WAS IN SPANISH…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI