This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

random voice ads playing

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Running XP SP3. I’ve started receiving voice ads through my speakers for about a week, ads for mustard, Lysol, dishwashing detergent, a random instrumental piece that sounds like a movie trailer, "Congratulations! You've Won!" etc. They may vary between 3-5 minutes apart to 20-30 minutes apart, totally random times. The same four ads or trailer have been playing over and over in no apparent sequence. Sometimes two or three of the same or different ads even play simultaneously superimposed on each other. I ran numerous antivirus and anti-malware programs multiple times but they found nothing (Kaspersky, Avira, Malwarebytes, Ad-aware, Spybot, Spysweeper, The Cleaner7.) I have observed task manager applications during the sound periods for any jump in usage; nothing. I’ve search all visible and hidden files for unusual mp3, wav, rar, and their variations files; nothing. I searched for all visible and hidden files created, modified or accessed the day the sounds began, and at the exact times the sounds occurred; nothing. The ads sometimes even begin immediately after start-up before icons load on the desktop or task bar. The ads occur even if browsers (IE and Firefox) have not been opened. Firefox has ad-blockers installed and I deselected ‘play sounds in web pages’ in IE; no change. I attempted to sys restore to a day before the ads began. I have several restore dates available but after each restore restart I get the message that computer was unable to sys restore, even when I restore from Safe Mode and attempted 8 different available restore points. Ran RegClean; no change. I attempted to do Windows installation repair thinking it might override a rogue file but Windows won’t let me repair because SP3 is a higher version than my retail disk. I hope you can help. Here’s the Hijack This, OTL, DDS logs:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:33:58 AM, on 8/31/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [PMBVolumeWatcher] "C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [tcactive] "C:\Program Files\The Cleaner7\tcap.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.0.0.0.0
O15 - Trusted Zone: http://support.microsoft.com
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: The Cleaner 2011 Helper Service (moohelp) - MooSoft Development LLC - C:\Program Files\The Cleaner7\mhelper.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe

–
End of file - 8551 bytes

OLT Logs:

OTL Extras logfile created on: 8/31/2010 11:02:01 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 28.64 Gb Free Space | 38.43% Space Free | Partition Type: NTFS
Drive D: | 1.99 Gb Total Space | 0.71 Gb Free Space | 35.81% Space Free | Partition Type: FAT32
Drive E: | 12.31 Gb Total Space | 1.47 Gb Free Space | 11.98% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RUSSELL
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe" = C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe:*:Enabled:IreIke – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe" = C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe" = C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe" = C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager – File not found
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Ltd Services – (Rosetta Stone Ltd. )
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone Version 3 Application – (Multidmedia Limited )

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater – ()
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – ()
"C:\Program Files\MEDITECH\Print\VMagicPPII.exe" = C:\Program Files\MEDITECH\Print\VMagicPPII.exe:*:Enabled:Document Spooling Service – (Medical Information Technology, Inc.)
"C:\Program Files\QuickTime\QuickTimePlayer.exe" = C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player – (Apple Inc.)
"C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe" = C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe:*:Enabled:IreIke – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe" = C:\Program Files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe" = C:\Program Files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp – File not found
"C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe" = C:\Program Files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager – File not found
"C:\Ed's stuff\config\mirc\mirc.exe" = C:\Ed's stuff\config\mirc\mirc.exe:*:Enabled:mIRC – File not found
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"C:\WINDOWS\LMI59.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI59.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – (LogMeIn, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\WINDOWS\LMID.tmp\lmi_rescue.exe" = C:\WINDOWS\LMID.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – File not found
"C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe" = C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy – (Juniper Networks)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\WINDOWS\LMI5.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI5.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – File not found
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Ltd Services – (Rosetta Stone Ltd. )
"C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone Version 3 Application – (Multidmedia Limited )
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\WINDOWS\LMI3.tmp\lmi_rescue.exe" = C:\WINDOWS\LMI3.tmp\lmi_rescue.exe:*:Enabled:LogMeIn Rescue – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1FCC574F-AFA2-4432-9EF1-79CA7BA73431}_is1" = Spy Sweeper
"{23C3F5C0-566B-478B-AAB6-197ADAD0C945}" = Uniblue SpeedUpMyPC 2009
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{3248F0A8-6813-11D6-A77B-00B0D0150120}" = J2SE Runtime Environment 5.0 Update 12
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{3819891A-030B-4a4e-98ED-B28A649E48AB}" = HP Deskjet 3900 series
"{38441BE7-79B0-42B8-8297-833704F949FE}" = HLPIndex
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{3F5B6210-0903-4DC6-8034-8F488AA3A782}" = Spy Sweeper Core
"{42F6BED9-41DD-40F1-85A8-8E0350493626}" = HPDeskjet3900Series
"{432C3720-37BF-4BD7-8E49-F38E090246D0}" = CR2
"{432DDCA6-5CF6-4F02-93D3-BD78E327DA66}" = RSA SecurID Software Token
"{4732D4A0-5A47-44D8-9B84-B3BD4906D30D}" = TaxCut Premium 2007
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{48C82F7A-F100-4DAB-A310-8E18BF2159E1}" = ESSvpot
"{49B43E4D-32DD-46CD-8EE0-214A947BAFA9}" = DJ_SF_03_D4300_Software_Min
"{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}" = Apple Mobile Device Support
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4F677FC7-7AA8-412B-A957-F13CBE1C7331}" = ESSSONIC
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{54C8FE84-89C4-40E8-976C-439EB0729BD6}" = CardRd81
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{79207BEE-6CD3-483C-824C-944663BACAC4}" = TaxCut Premium + Efile 2008
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F1B3341-A94E-4F5C-B587-CA0EB964221E}" = Microsoft Money Shared Libraries
"{8080E151-1FBF-400e-9497-29FDF9410AC6}" = HP Deskjet D4300 Printer Driver 11.0 Rel .3
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}" = ESSCT
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{911A0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Outlook 2002
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{92A0792A-E771-4C4A-9A4A-C2917AA19EEA}" = H&R; Block Basic + Efile 2009
"{99011A6E-5200-11DE-BDB8-7ACD56D89593}" = Rosetta Stone Version 3
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}" = Status
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}" = ESSvpaht
"{AADAC983-FDE9-42FA-8FD9-7BB324155593}" = HLPRFO
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}" = Safari
"{CA60320D-6A16-49C8-A34F-84EEF4799567}" = ESSTUTOR
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E69D6784-CAE4-4770-BBF8-A4E45304E749}" = TaxCut Missouri 2007
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F1BD306D-EC22-4739-AD87-0ECB5A907BAC}" = Eudora
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AdobeESD" = Adobe Download Manager 2.2 (Remove Only)
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BCWipe" = BCWipe 3.0
"CalcTime" = CalcTime
"CCleaner" = CCleaner (remove only)
"Coupon Printer for Windows2.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"GoZone iSync" = GoZone iSync
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"InstallShield_{432DDCA6-5CF6-4F02-93D3-BD78E327DA66}" = RSA SecurID Software Token
"InterCover_1.20" = InterCover 1.24
"Juniper_Setup_Client Activex Control" = Juniper Networks Setup Client Activex Control
"Legacy 5.0" = Legacy 5.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.5
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft.Net.Client.3.5" = Microsoft .NET Framework Client Profile - PREVIEW
"Money2008b" = Microsoft Money Plus
"Mozilla Firefox (3.0.3)" = Mozilla Firefox (3.0.3)
"Mozilla Firefox (3.5.11)" = Mozilla Firefox (3.5.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Neoteris_Secure_Application_Manager" = Juniper Networks Secure Application Manager
"New Folder Here" = New Folder Here
"NoAds" = NoAds
"Office8.0" = Microsoft Office 97, Professional Edition
"Pdf995" = Pdf995 (installed by TaxCut)
"PdfEdit995" = PdfEdit995 (installed by TaxCut)
"SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set
"The Cleaner_is1" = The Cleaner 2011
"The QI Macros for Excel" = The QI Macros for Excel
"Uniblue SpeedUpMyPC 2009" = Uniblue SpeedUpMyPC 2009
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Encoder 7" = Windows Media Encoder 7.1
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Juniper_Setup_Client" = Juniper Networks Setup Client
"Move Media Player" = Move Media Player
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 8/31/2010 9:40:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 8/31/2010 11:28:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 8/31/2010 11:28:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 8/31/2010 11:30:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 8/31/2010 11:30:11 AM | Computer Name = RUSSELL | Source = Userenv | ID = 1041
Description = Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
and it will not be loaded. This is most likely caused by a faulty registration.

Error - 8/31/2010 11:41:00 AM | Computer Name = RUSSELL | Source = Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 12.0.6541.5000, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/31/2010 12:00:48 PM | Computer Name = RUSSELL | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.11.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 8/28/2010 10:17:21 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 8/28/2010 10:17:21 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit

Error - 8/29/2010 10:11:45 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 8/29/2010 10:11:45 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit

Error - 8/30/2010 9:36:36 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 8/30/2010 9:36:36 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit

Error - 8/31/2010 9:37:15 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 8/31/2010 9:37:15 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit

Error - 8/31/2010 9:42:11 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 8/31/2010 9:42:11 AM | Computer Name = RUSSELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Exportit


< End of report >

OTL logfile created on: 8/31/2010 11:02:01 AM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 28.64 Gb Free Space | 38.43% Space Free | Partition Type: NTFS
Drive D: | 1.99 Gb Total Space | 0.71 Gb Free Space | 35.81% Space Free | Partition Type: FAT32
Drive E: | 12.31 Gb Total Space | 1.47 Gb Free Space | 11.98% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RUSSELL
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Webroot\WebrootSecurity\SSU.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\sndvol32.exe (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (WRConsumerService) – C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
SRV - (moohelp) – C:\Program Files\The Cleaner7\mhelper.exe (MooSoft Development LLC)
SRV - (WebrootSpySweeperService) – C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (PMBDeviceInfoProvider) – C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (KodakCCS) – C:\WINDOWS\SYSTEM32\DRIVERS\KodakCCS.exe (Eastman Kodak Company)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Driver Services (SafeList) ==========

DRV - (vsdatant) – C:\WINDOWS\System32\vsdatant.sys File not found
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (NEOFLTR_650_15507) Juniper Networks TDI Filter Driver (NEOFLTR_650_15507) – C:\WINDOWS\SYSTEM32\DRIVERS\NEOFLTR_650_15507.SYS (Juniper Networks)
DRV - (avgntflt) – C:\WINDOWS\SYSTEM32\DRIVERS\avgntflt.sys (Avira GmbH)
DRV - (ssidrv) – C:\WINDOWS\system32\DRIVERS\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (sshrmd) – C:\WINDOWS\system32\DRIVERS\sshrmd.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssfs0bbc) – C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssmdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – C:\WINDOWS\SYSTEM32\DRIVERS\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\USBAUDIO.sys (Microsoft Corporation)
DRV - (CVirtA) – C:\WINDOWS\SYSTEM32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (RTL8023) – C:\WINDOWS\SYSTEM32\DRIVERS\GA311ND5.SYS (Realtek Semiconductor Corporation )
DRV - (DcCam) – C:\WINDOWS\SYSTEM32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (Exportit) – C:\WINDOWS\SYSTEM32\DRIVERS\ExportIt.sys (Eastman Kodak Company)
DRV - (DcPTP) – C:\WINDOWS\SYSTEM32\DRIVERS\DcPtp.sys (Eastman Kodak Company)
DRV - (DcLps) – C:\WINDOWS\SYSTEM32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DCFS2K) – C:\WINDOWS\SYSTEM32\DRIVERS\DCFS2k.sys (Eastman Kodak Company)
DRV - (DcFpoint) – C:\WINDOWS\SYSTEM32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (BCSWAP) – C:\WINDOWS\System32\drivers\BCSwap.sys (Jetico, Inc.)
DRV - (USBFVNETR) – C:\WINDOWS\SYSTEM32\DRIVERS\ma101rnd.sys (ATMEL)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.cnn.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {57068FBE-1506-42ee-AB02-BD183E7999E4}:2.3.2
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.1.0521
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.2.3
FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.3\extensions\\Components: C:\Program Files\mozilla\components [2010/07/04 14:39:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.3\extensions\\Plugins: C:\Program Files\mozilla\plugins [2010/08/31 10:41:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Firefox2009\components [2010/08/24 13:45:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Firefox2009\plugins [2010/08/31 10:41:41 | 000,000,000 | —D | M]

[2008/10/22 09:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/08/30 09:15:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions
[2009/08/10 18:20:45 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/27 18:52:39 | 000,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009/09/27 18:37:04 | 000,000,000 | —D | M] (Compact Menu 2) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{57068FBE-1506-42ee-AB02-BD183E7999E4}
[2010/08/26 15:17:23 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/05/23 12:56:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/08/27 18:54:09 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\frolfaoz.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/05/25 12:11:37 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/07/06 11:29:23 | 000,000,815 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1ad.doubleclick.net
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [SpySweeper] C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\Wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [tcactive] C:\Program Files\The Cleaner7\tcap.exe (MooSoft Development Inc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: //@surf.mar@ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: 0.0.0.0 ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: christushealth.org ([my] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([oas.support] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([oas.support] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([support] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([support] https in Trusted sites)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Eudora\EuShlExt.dll (Qualcomm Inc.)
O30 - LSA: Authentication Packages - (OWS\S) - File not found
O30 - LSA: Security Packages - (SECURID SOFTWARE TOKEN) - File not found
O30 - LSA: Security Packages - (ecurity) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/02/02 22:35:40 | 000,000,194 | -HS- | M] () - C:\AUTOEXEC.BAK – [ NTFS ]
O32 - AutoRun File - [2007/10/07 21:36:40 | 000,000,218 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/02/02 22:35:40 | 000,000,218 | —- | M] () - C:\AUTOEXEC.MFD – [ NTFS ]
O32 - AutoRun File - [1998/05/02 13:12:24 | 000,000,497 | -HS- | M] () - D:\AUTOEXEC.DOS – [ FAT32 ]
O32 - AutoRun File - [2003/06/14 19:51:48 | 000,000,212 | -H– | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: MIDI1 - C:\WINDOWS\System32\Syncor11.dll (SoundMAX)
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DivXa32.acm (Packed With Joy !)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/08/31 10:54:53 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/31 10:40:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2010/08/26 15:21:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Sunbelt Software
[2010/08/26 15:20:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\1101 Leah Drive #415, San Marcos, TX 78666
[2010/08/26 15:20:31 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\HPAppData
[2010/08/25 17:37:19 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/08/25 17:37:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/08/24 21:06:26 | 000,095,024 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/08/24 16:58:20 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/08/24 16:33:03 | 000,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2010/08/24 08:41:45 | 000,000,000 | —D | C] – C:\Program Files\safeboot tools
[2010/08/23 09:26:22 | 000,000,000 | —D | C] – C:\Program Files\undelete safeboot fix
[2010/08/19 15:52:59 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\HPAppData
[2010/08/19 08:37:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/08/18 08:56:36 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2005/02/13 13:49:23 | 013,951,112 | —- | C] (Microsoft Corporation) – C:\Program Files\Win MEdia Player 9-Setup.exe
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/31 11:03:14 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Administrator\Desktop\~$nning XP SP3.docx
[2010/08/31 10:54:55 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/08/31 10:40:11 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Administrator\Desktop\~$x text.docx
[2010/08/31 08:46:42 | 211,976,192 | —- | M] () – C:\WINDOWS\outlook.pst
[2010/08/31 08:42:14 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/31 08:40:02 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/31 08:40:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/30 21:00:16 | 008,388,608 | —- | M] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/08/30 21:00:16 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini
[2010/08/30 20:30:49 | 000,262,144 | —- | M] () – C:\WINDOWS\outlook.bak
[2010/08/30 18:40:34 | 000,017,635 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Running XP SP3.docx
[2010/08/30 09:28:52 | 000,426,770 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\fix text.docx
[2010/08/30 09:00:05 | 000,001,684 | —- | M] () – C:\WINDOWS\tasks\wrSpySweeper_LE7D4CEAA61FD4F7B95DB007630A5B40D.job
[2010/08/29 09:10:55 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/27 21:33:59 | 000,011,753 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\online-scanner.html
[2010/08/27 21:32:08 | 000,001,550 | —- | M] () – C:\WINDOWS\winzip32.ini
[2010/08/27 21:32:08 | 000,000,938 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/25 17:37:24 | 000,000,977 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/24 21:06:26 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/08/24 16:58:18 | 000,000,895 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/24 12:04:03 | 000,015,027 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\system restore Instructions.docx
[2010/08/22 20:36:28 | 000,010,116 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\e1658500180dc0ae866241600d.docx
[2010/08/19 22:00:28 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/19 22:00:27 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/08/16 21:06:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/13 08:47:19 | 000,172,280 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/12 07:15:20 | 000,064,288 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/08/12 07:15:20 | 000,015,880 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2010/08/11 22:12:19 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/11 22:06:29 | 000,488,244 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/11 22:06:29 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/11 22:06:29 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/10 23:08:10 | 000,226,728 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/08/02 09:51:31 | 000,233,984 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]
[1 C:\Documents and Settings\Administrator\My Documents\*.tmp files -> C:\Documents and Settings\Administrator\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/31 11:03:14 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Administrator\Desktop\~$nning XP SP3.docx
[2010/08/31 10:40:11 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Administrator\Desktop\~$x text.docx
[2010/08/30 09:29:12 | 000,017,635 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Running XP SP3.docx
[2010/08/30 09:28:48 | 000,426,770 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\fix text.docx
[2010/08/27 21:33:56 | 000,011,753 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\online-scanner.html
[2010/08/25 17:37:24 | 000,000,977 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/08/24 16:58:18 | 000,000,895 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/24 12:04:03 | 000,015,027 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\system restore Instructions.docx
[2010/08/22 20:36:28 | 000,010,116 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\e1658500180dc0ae866241600d.docx
[2010/08/19 22:37:49 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/16 12:47:50 | 008,388,608 | —- | C] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/03/02 19:00:00 | 004,555,278 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/03/02 19:00:00 | 001,449,935 | —- | C] () – C:\WINDOWS\System32\ffmpegmt.dll
[2010/03/02 19:00:00 | 000,882,688 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/03/02 19:00:00 | 000,877,385 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2010/03/02 19:00:00 | 000,556,491 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/03/02 19:00:00 | 000,336,384 | —- | C] () – C:\WINDOWS\System32\ff_libfaad2.dll
[2010/03/02 19:00:00 | 000,324,096 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/03/02 19:00:00 | 000,248,320 | —- | C] () – C:\WINDOWS\System32\ff_kernelDeint.dll
[2010/03/02 19:00:00 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\ff_libdts.dll
[2010/03/02 19:00:00 | 000,169,984 | —- | C] () – C:\WINDOWS\System32\ff_samplerate.dll
[2010/03/02 19:00:00 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\ff_libmad.dll
[2010/03/02 19:00:00 | 000,145,408 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/03/02 19:00:00 | 000,121,856 | —- | C] () – C:\WINDOWS\System32\ff_liba52.dll
[2010/03/02 19:00:00 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\ff_tremor.dll
[2010/03/02 19:00:00 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2010/03/02 19:00:00 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\ff_unrar.dll
[2010/03/02 19:00:00 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/11/14 13:37:08 | 000,154,112 | —- | C] () – C:\WINDOWS\System32\ts.dll
[2009/11/14 13:33:38 | 000,249,856 | —- | C] () – C:\WINDOWS\System32\dxr.dll
[2009/11/14 13:11:50 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\avss.dll
[2009/11/14 13:11:42 | 000,150,016 | —- | C] () – C:\WINDOWS\System32\mkx.dll
[2009/11/14 13:11:42 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\mp4.dll
[2009/11/14 13:11:40 | 000,123,392 | —- | C] () – C:\WINDOWS\System32\ogm.dll
[2009/11/14 13:11:40 | 000,109,568 | —- | C] () – C:\WINDOWS\System32\avi.dll
[2009/11/14 13:11:38 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\avs.dll
[2009/11/14 13:11:32 | 000,080,384 | —- | C] () – C:\WINDOWS\System32\mkzlib.dll
[2009/11/14 13:11:32 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\mkunicode.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/07/20 15:53:05 | 000,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2009/06/07 11:24:04 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/01/31 16:55:37 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2009/01/10 17:15:44 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\mmfinfo.dll
[2008/11/06 11:37:32 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/10/31 03:02:23 | 000,001,550 | —- | C] () – C:\WINDOWS\winzip32.ini
[2008/10/24 15:15:57 | 000,002,528 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\$_hpcst$.hpc
[2008/02/02 17:30:32 | 000,000,142 | —- | C] () – C:\WINDOWS\wpd99.drv
[2008/02/02 17:30:31 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2008/01/04 16:57:22 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/01/04 16:56:24 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/11/21 22:37:14 | 000,000,000 | —- | C] () – C:\WINDOWS\PanelExe.INI
[2007/11/21 22:29:19 | 000,000,000 | —- | C] () – C:\WINDOWS\FileMgrExe.INI
[2007/11/16 16:55:40 | 000,000,031 | -H– | C] () – C:\WINDOWS\uccspecc.sys
[2007/10/13 04:30:20 | 000,000,137 | —- | C] () – C:\WINDOWS\System32\Registration.ini
[2007/10/03 22:09:29 | 000,029,696 | —- | C] () – C:\Program Files\4E90396851764FA59BAE4EFBBC94F08D.db
[2007/09/17 21:45:20 | 000,001,394 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/09/01 17:34:05 | 000,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/08/27 00:23:13 | 000,000,880 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\AdobeDLM.log
[2007/08/27 00:23:13 | 000,000,006 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\dm.ini
[2007/08/26 21:19:49 | 000,000,065 | —- | C] () – C:\WINDOWS\goldwave.ini
[2007/08/26 19:42:52 | 000,073,204 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2007/08/26 19:42:52 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2007/08/25 19:56:56 | 000,000,305 | —- | C] () – C:\Documents and Settings\All Users\Application Data\addr_file.html
[2007/08/25 19:32:36 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\msssc.dll
[2007/08/25 11:49:28 | 000,004,995 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/08/25 02:32:43 | 000,233,984 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/03/08 14:19:31 | 000,002,238 | -H– | C] () – C:\Program Files\Ikona1021944043.ico
[2003/12/27 08:00:34 | 000,023,357 | -H– | C] () – C:\Program Files\folder.htt
[2000/09/08 17:53:50 | 000,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1996/11/17 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1996/11/17 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1996/11/17 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL

========== LOP Check ==========

[2009/07/20 15:48:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2008/09/06 08:41:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ICAClient
[2010/01/17 12:11:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Juniper Networks
[2009/07/12 14:33:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\OpenOffice.org
[2009/01/31 16:55:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\pdf995
[2010/01/24 21:43:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\TaxCut
[2010/06/14 18:02:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\thecleaner
[2009/04/12 15:35:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\uniblue
[2007/10/13 11:47:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Viewpoint
[2008/06/27 22:24:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
[2009/10/08 08:17:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2009/08/17 17:15:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2010/07/21 15:28:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rosetta Stone
[2009/10/04 13:20:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdBackup
[2010/01/23 22:46:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2010/08/26 16:49:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/02 20:24:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/04/12 15:33:42 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{8AE45C14-3559-45A6-AF34-03CE304FA276}
[2010/08/26 15:21:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/08/30 09:00:05 | 000,001,684 | —- | M] () – C:\WINDOWS\Tasks\wrSpySweeper_LE7D4CEAA61FD4F7B95DB007630A5B40D.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2003/03/31 07:00:00 | 000,245,920 | R— | M] () – C:\$LDR$
[2010/08/31 08:39:57 | 000,173,310 | —- | M] () – C:\aaw7boot.log
[2007/02/02 22:35:40 | 000,000,194 | -HS- | M] () – C:\AUTOEXEC.BAK
[2007/10/07 21:36:40 | 000,000,218 | —- | M] () – C:\AUTOEXEC.BAT
[2007/02/02 22:35:40 | 000,000,218 | —- | M] () – C:\AUTOEXEC.MFD
[2010/08/19 22:00:28 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2006/04/16 17:03:32 | 000,084,210 | -HS- | M] () – C:\BOOTLOG.PRV
[2006/04/16 17:43:36 | 000,077,688 | -HS- | M] () – C:\BOOTLOG.TXT
[2007/08/24 16:35:00 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2004/10/24 08:18:40 | 000,001,173 | —- | M] () – C:\caavsetup.log
[2003/12/27 07:54:16 | 000,245,792 | RH– | M] () – C:\CLASSES.1ST
[1998/06/18 11:34:08 | 000,009,729 | —- | M] () – C:\CLOUDS.jpg
[2000/06/08 12:00:00 | 000,093,040 | -HS- | M] () – C:\COMMAND.COM
[2007/02/11 15:55:14 | 000,002,197 | —- | M] () – C:\COMPATID.TXT
[2007/02/02 22:35:40 | 000,000,000 | —- | M] () – C:\CONFIG.BAK
[2007/02/02 22:35:40 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2005/02/28 05:00:30 | 000,017,031 | —- | M] () – C:\DEL
[2007/01/21 10:41:08 | 000,050,405 | -HS- | M] () – C:\DETLOG.OLD
[2007/01/21 12:26:56 | 000,050,405 | -HS- | M] () – C:\DETLOG.TXT
[2009/08/11 08:53:05 | 000,000,182 | —- | M] () – C:\drwtsn32.log
[2009/07/20 08:57:38 | 003,594,989 | —- | M] () – C:\EasyShare.dmp
[2007/09/02 20:20:06 | 000,004,915 | -H– | M] () – C:\ffastun.ffa
[2007/09/02 20:20:03 | 001,474,560 | -H– | M] () – C:\ffastun.ffl
[2007/09/02 20:20:06 | 000,819,200 | -H– | M] () – C:\ffastun.ffo
[2007/09/02 20:20:03 | 013,987,840 | -H– | M] () – C:\ffastun0.ffx
[2008/02/13 17:48:02 | 000,019,456 | —- | M] () – C:\FORGETFUL.doc
[2008/03/26 17:18:15 | 000,022,528 | —- | M] () – C:\heim_tax_worksheet_2007.xls
[2007/08/24 10:46:58 | 000,499,132 | —- | M] () – C:\hpfr3900.log
[2000/06/08 12:00:00 | 000,110,080 | RHS- | M] () – C:\IO.SYS
[2005/09/22 15:30:14 | 000,000,207 | -H– | M] () – C:\IPH.PH
[2003/12/27 07:59:18 | 000,001,660 | RHS- | M] () – C:\MSDOS.SYS
[2003/12/27 08:01:42 | 000,008,076 | -HS- | M] () – C:\NETLOG.TXT
[2007/08/25 16:39:30 | 000,047,564 | RHS- | M] () – C:\ntdetect.com
[2008/08/18 20:56:31 | 000,250,048 | RHS- | M] () – C:\ntldr
[2004/02/20 13:04:56 | 000,022,016 | —- | M] () – C:\Optical.exe
[2010/08/31 08:39:57 | 1048,576,000 | -HS- | M] () – C:\pagefile.sys
[2010/04/21 10:40:07 | 000,000,028 | —- | M] () – C:\pending.un
[2010/08/18 10:41:04 | 000,000,441 | —- | M] () – C:\rkill.log
[2010/08/23 09:39:53 | 000,014,268 | —- | M] () – C:\SAFEBOOT_REPAIR.TXT
[2007/08/24 17:10:46 | 000,000,634 | -H– | M] () – C:\SCANDISK.LOG
[2007/03/24 14:30:30 | 000,226,091 | -HS- | M] () – C:\SETUPLOG.TXT
[2003/12/27 15:17:08 | 000,000,202 | —- | M] () – C:\SETUPXLG.TXT
[2003/12/27 07:54:16 | 000,005,166 | -HS- | M] () – C:\SUHDLOG.DAT
[2003/12/27 07:54:16 | 000,499,744 | -HS- | M] () – C:\SYSTEM.1ST
[2004/03/19 12:47:18 | 000,000,000 | —- | M] () – C:\temp.html
[2003/03/31 07:00:00 | 000,454,830 | R— | M] () – C:\txtsetup.sif
[2010/01/12 17:11:37 | 000,000,838 | —- | M] () – C:\updatedatfix.log
[2003/12/27 13:51:44 | 000,000,010 | RH– | M] () – C:\VIDC.ZFR
[2003/12/27 07:58:52 | 000,045,568 | -HS- | M] () – C:\VIDEOROM.BIN
[2004/03/05 16:33:46 | 000,000,063 | —- | M] () – C:\WINDOWSWinHlp32.BMK
[2007/08/24 11:31:54 | 000,005,464 | —- | M] () – C:\winzip.log
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2007/08/25 00:50:57 | 000,000,067 | -HS- | M] () – C:\WINDOWS\FONTS\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/04/08 21:43:36 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[1996/11/17 00:00:00 | 000,000,002 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\ArtGalry.cag
[2008/10/18 00:46:43 | 000,001,682 | -H– | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2007/10/03 22:06:53 | 000,029,696 | —- | M] () – C:\Program Files\4E90396851764FA59BAE4EFBBC94F08D.db
[2004/03/08 14:19:30 | 000,000,354 | -HS- | M] () – C:\Program Files\desktop.ini
[2003/12/27 08:00:36 | 000,023,357 | -H– | M] () – C:\Program Files\folder.htt
[2004/03/08 14:19:32 | 000,002,238 | -H– | M] () – C:\Program Files\Ikona1021944043.ico
[2005/02/11 21:00:58 | 013,951,112 | —- | M] (Microsoft Corporation) – C:\Program Files\Win MEdia Player 9-Setup.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2007/08/24 17:27:10 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\config\default.sav
[2007/08/24 17:27:10 | 000,626,688 | —- | M] () – C:\WINDOWS\SYSTEM32\config\software.sav
[2007/08/24 17:27:10 | 000,405,504 | —- | M] () – C:\WINDOWS\SYSTEM32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/18 21:08:42 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/08/18 21:32:01 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/08/25 00:56:47 | 000,000,079 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/08/31 10:54:55 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[6 C:\Documents and Settings\Administrator\Desktop\*.tmp files -> C:\Documents and Settings\Administrator\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-12 03:12:19

========== Alternate Data Streams ==========

@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >

DDS:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:22:10.85 on Tue 08/31/2010
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1354 [GMT -5:00]

AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
svchost.exe 4
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
svchost.exe 4
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Documents and Settings\Administrator\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.cnn.com/
uDefault_Page_URL = hxxp://www.msn.com
uInternet Settings,ProxyOverride = *.local
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot - search & destroy\SDHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe"
uRun: [tcactive] "c:\program files\the cleaner7\tcap.exe"
uRun: [SpybotSD TeaTimer] "c:\program files\spybot - search & destroy\TeaTimer.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [PMBVolumeWatcher] "c:\program files\sony\pmb\PMBVolumeWatcher.exe"
mRun: [SpySweeper] "c:\program files\webroot\webrootsecurity\SpySweeperUI.exe" /startintray
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRunOnce: [RunNarrator] Narrator.exe
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot - search & destroy\SDHelper.dll
Trusted Zone: 0.0.0.0
Trusted Zone: christushealth.org\my
Trusted Zone: microsoft.com\oas.support
Trusted Zone: microsoft.com \support
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6770.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - c:\program files\eudora\EuShlExt.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\frolfaoz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com/
FF - plugin: c:\documents and settings\administrator\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\firefox2009\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\firefox2009\plugins\npMozCouponPrinter.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\firefox2009\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\firefox2009\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\firefox2009\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\firefox2009\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\firefox2009\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\firefox2009\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\firefox2009\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\firefox2009\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\firefox2009\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\firefox2009\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\firefox2009\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\firefox2009\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\firefox2009\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\firefox2009\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\firefox2009\greprefs\all.js - pref("geo.enabled", true);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\firefox2009\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\firefox2009\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\firefox2009\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\firefox2009\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\firefox2009\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\firefox2009\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-11 64288]
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2009-4-21 29808]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-5-7 11608]
R1 NEOFLTR_650_15507;Juniper Networks TDI Filter Driver (NEOFLTR_650_15507);c:\windows\system32\drivers\NEOFLTR_650_15507.SYS [2010-4-21 85360]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-7 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-5-7 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-5-7 56816]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-8-12 1355416]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2009-10-24 360224]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-10-13 24652]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\webrootsecurity\SpySweeper.exe [2009-11-6 4048240]
R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\webrootsecurity\WRConsumerService.exe [2009-7-20 1201640]
S2 moohelp;The Cleaner 2011 Helper Service;c:\program files\the cleaner7\mhelper.exe [2010-6-14 813056]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15008]
S3 USBFVNETR;NETGEAR MA101 USB Adapter;c:\windows\system32\drivers\ma101rnd.sys [2007-8-25 80000]
S3 vsdatant;vsdatant;\??\c:\windows\system32\vsdatant.sys –> c:\windows\system32\vsdatant.sys [?]
S4 BCSWAP;BCSWAP;c:\windows\system32\drivers\BCSwap.sys [2002-8-16 83456]

=============== Created Last 30 ================

2010-08-26 17:48 –d—– c:\windows\system32\wbem\New Folder
2010-08-25 17:37 –d—– c:\program files\Spybot - Search & Destroy
2010-08-25 17:37 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-08-24 21:06 95,024 a——- c:\windows\system32\drivers\SBREDrv.sys
2010-08-24 16:58 -cd-h— c:\docume~1\alluse~1\applic~1\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-08-24 08:41 –d—– c:\program files\safeboot tools
2010-08-23 09:26 –d—– c:\program files\undelete safeboot fix
2010-08-19 22:37 664 a——- c:\windows\system32\d3d9caps.dat
2010-08-18 09:18 –d—– c:\windows\system32\wbem\Repository

==================== Find3M ====================

2010-08-12 07:15 15,880 ac—— c:\windows\system32\lsdelete.exe
2010-08-12 07:15 64,288 a——- c:\windows\system32\drivers\Lbd.sys
2010-06-30 07:31 149,504 a——- c:\windows\system32\schannel.dll
2010-06-24 07:10 667,136 a——- c:\windows\system32\wininet.dll
2010-06-24 07:10 81,920 a——- c:\windows\system32\ieencode.dll
2010-06-23 08:44 1,851,904 a——- c:\windows\system32\win32k.sys
2010-06-17 09:03 80,384 a——- c:\windows\system32\iccvid.dll
2010-06-14 09:31 744,448 a——- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 02:41 1,172,480 a——- c:\windows\system32\msxml3.dll
2007-10-03 22:06 29,696 ac—— c:\program files\4E90396851764FA59BAE4EFBBC94F08D.db
2005-02-11 21:00 13,951,112 ac—— c:\program files\Win MEdia Player 9-Setup.exe
2004-03-08 14:19 2,238 ac–h— c:\program files\Ikona1021944043.ico
2004-03-08 14:19 354 ac-sh— c:\program files\desktop.ini
2003-12-27 08:00 23,357 ac–h— c:\program files\folder.htt
2009-08-09 01:44 245,760 ac-sh— c:\windows\system32\config\systemprofile\ietldcache\index.dat

============= FINISH: 11:22:54.93 ===============
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.





[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.
MBR Check and GMER files below. For some reason each time I tried to open Word after running GMER to paste my computer crashed three times. I only selected ‘save’ and did not take any actions. I’ve never crashed like that before.

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000003d

Kernel Drivers (total 124):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806FF000 \WINDOWS\system32\hal.dll
0xF7987000 \WINDOWS\system32\KDCOM.DLL
0xF7897000 \WINDOWS\system32\BOOTVID.dll
0xF75A8000 ACPI.sys
0xF7989000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
0xF7597000 pci.sys
0xF75F7000 isapnp.sys
0xF7607000 sshrmd.sys
0xF7617000 ssfs0bbc.sys
0xF74C9000 ssidrv.sys
0xF749C000 \WINDOWS\system32\DRIVERS\NDIS.SYS
0xF7707000 \WINDOWS\system32\DRIVERS\TDI.SYS
0xF7A4F000 pciide.sys
0xF770F000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF798B000 intelide.sys
0xF7627000 MountMgr.sys
0xF747D000 ftdisk.sys
0xF798D000 dmload.sys
0xF7457000 dmio.sys
0xF7717000 PartMgr.sys
0xF7637000 VolSnap.sys
0xF743F000 atapi.sys
0xF7647000 disk.sys
0xF7657000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
0xF741F000 fltmgr.sys
0xF740D000 sr.sys
0xF7667000 Lbd.sys
0xF7677000 PxHelp20.sys
0xF7860000 KSecDD.sys
0xF7B52000 Ntfs.sys
0xF7846000 Mup.sys
0xF76C7000 \SystemRoot\System32\DRIVERS\intelppm.sys
0xB895E000 \SystemRoot\system32\DRIVERS\ialmnt5.sys
0xB894A000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF77D7000 \SystemRoot\System32\DRIVERS\usbuhci.sys
0xB8926000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
0xB8915000 \SystemRoot\System32\DRIVERS\GA311ND5.SYS
0xF77DF000 \SystemRoot\System32\DRIVERS\fdc.sys
0xF76D7000 \SystemRoot\System32\DRIVERS\serial.sys
0xF792B000 \SystemRoot\System32\DRIVERS\serenum.sys
0xB8901000 \SystemRoot\System32\DRIVERS\parport.sys
0xF76E7000 \SystemRoot\System32\DRIVERS\i8042prt.sys
0xF77E7000 \SystemRoot\System32\DRIVERS\kbdclass.sys
0xF77EF000 \SystemRoot\System32\DRIVERS\mouclass.sys
0xF76F7000 \SystemRoot\System32\DRIVERS\imapi.sys
0xF7587000 \SystemRoot\System32\DRIVERS\cdrom.sys
0xF7577000 \SystemRoot\System32\DRIVERS\redbook.sys
0xB88DE000 \SystemRoot\System32\DRIVERS\ks.sys
0xF792F000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xB885E000 \SystemRoot\system32\drivers\smwdm.sys
0xB883A000 \SystemRoot\system32\drivers\portcls.sys
0xF7567000 \SystemRoot\system32\drivers\drmk.sys
0xB8822000 \SystemRoot\system32\drivers\aeaudio.sys
0xF7A91000 \SystemRoot\System32\DRIVERS\audstub.sys
0xF7557000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
0xF7937000 \SystemRoot\System32\DRIVERS\ndistapi.sys
0xB880B000 \SystemRoot\System32\DRIVERS\ndiswan.sys
0xF7547000 \SystemRoot\System32\DRIVERS\raspppoe.sys
0xF7537000 \SystemRoot\System32\DRIVERS\raspptp.sys
0xB87FA000 \SystemRoot\System32\DRIVERS\psched.sys
0xF7527000 \SystemRoot\System32\DRIVERS\msgpc.sys
0xF77F7000 \SystemRoot\System32\DRIVERS\ptilink.sys
0xF77FF000 \SystemRoot\System32\DRIVERS\raspti.sys
0xB87CA000 \SystemRoot\System32\DRIVERS\rdpdr.sys
0xF7517000 \SystemRoot\System32\DRIVERS\termdd.sys
0xF79D7000 \SystemRoot\System32\DRIVERS\swenum.sys
0xB876C000 \SystemRoot\System32\DRIVERS\update.sys
0xBA7FC000 \SystemRoot\System32\DRIVERS\mssmbios.sys
0xF7507000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF7887000 \SystemRoot\System32\DRIVERS\usbhub.sys
0xF79D9000 \SystemRoot\System32\DRIVERS\USBD.SYS
0xF7747000 \SystemRoot\System32\DRIVERS\flpydisk.sys
0xF79EF000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xB8A75000 \SystemRoot\system32\DRIVERS\DcCam.sys
0xB0466000 \SystemRoot\system32\DRIVERS\EXPORTIT.SYS
0xBA19E000 \SystemRoot\System32\Drivers\Null.SYS
0xF79F1000 \SystemRoot\System32\Drivers\Beep.SYS
0xF776F000 \SystemRoot\System32\drivers\vga.sys
0xF79F3000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF79F5000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF7777000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF777F000 \SystemRoot\System32\Drivers\Npfs.SYS
0xBA7B4000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xB0433000 \SystemRoot\System32\DRIVERS\ipsec.sys
0xB03DA000 \SystemRoot\System32\DRIVERS\tcpip.sys
0xB03C2000 \??\C:\WINDOWS\system32\Drivers\NEOFLTR_650_15507.SYS
0xB039C000 \SystemRoot\System32\DRIVERS\ipnat.sys
0xB0374000 \SystemRoot\System32\DRIVERS\netbt.sys
0xB8A65000 \SystemRoot\System32\DRIVERS\wanarp.sys
0xB032A000 \SystemRoot\System32\drivers\afd.sys
0xB8A55000 \SystemRoot\System32\DRIVERS\netbios.sys
0xB96B1000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0xB02FF000 \SystemRoot\System32\DRIVERS\rdbss.sys
0xB028F000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
0xB8A35000 \SystemRoot\System32\Drivers\Fips.SYS
0xB025E000 \SystemRoot\system32\DRIVERS\avipbb.sys
0xF79F9000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0xB9681000 \SystemRoot\System32\DRIVERS\usbprint.sys
0xAAD77000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xAAD5F000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xAF9D7000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xAB5E3000 \SystemRoot\System32\drivers\Dxapi.sys
0xAAE32000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA2D4000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF020000 \SystemRoot\System32\ialmdnt5.dll
0xBF012000 \SystemRoot\System32\ialmrnt5.dll
0xBF03F000 \SystemRoot\System32\ialmdev5.DLL
0xBF05E000 \SystemRoot\System32\ialmdd5.DLL
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xAAD4B000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0xBA720000 \SystemRoot\system32\drivers\dcfs2k.sys
0xAF44D000 \SystemRoot\System32\DRIVERS\ndisuio.sys
0xAAC06000 \SystemRoot\System32\DRIVERS\mrxdav.sys
0xAABA1000 \SystemRoot\system32\drivers\wdmaud.sys
0xAE820000 \SystemRoot\system32\drivers\sysaudio.sys
0xF79EB000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xAA9E4000 \SystemRoot\System32\DRIVERS\srv.sys
0xAE840000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xAAA57000 \SystemRoot\System32\DRIVERS\asyncmac.sys
0xA9DE1000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\SYSTEM32\ntdll.dll

Processes (total 39):
0 System Idle Process
4 System
588 C:\WINDOWS\SYSTEM32\smss.exe
652 csrss.exe
676 C:\WINDOWS\SYSTEM32\winlogon.exe
720 C:\WINDOWS\SYSTEM32\services.exe
732 C:\WINDOWS\SYSTEM32\lsass.exe
924 C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
948 C:\WINDOWS\SYSTEM32\svchost.exe
1016 svchost.exe
1112 C:\WINDOWS\SYSTEM32\svchost.exe
1232 svchost.exe
1528 C:\WINDOWS\SYSTEM32\spoolsv.exe
1576 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1640 svchost.exe
1928 C:\WINDOWS\explorer.exe
164 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
176 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
188 C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
204 C:\Program Files\Microsoft ActiveSync\wcescomm.exe
240 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
268 C:\PROGRA~1\MICROS~3\rapimgr.exe
424 C:\WINDOWS\SYSTEM32\svchost.exe
484 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
496 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
508 C:\Program Files\Bonjour\mDNSResponder.exe
612 C:\WINDOWS\SYSTEM32\svchost.exe
1088 C:\Program Files\Java\jre6\bin\jqs.exe
1240 C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
1752 C:\WINDOWS\SYSTEM32\svchost.exe
1772 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
1840 C:\Program Files\Viewpoint\Common\ViewpointService.exe
1992 C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
3068 C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
456 alg.exe
1688 C:\Program Files\Internet Explorer\iexplore.exe
3436 C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
704 C:\WINDOWS\SYSTEM32\wscntfy.exe
2540 C:\Documents and Settings\Administrator\Desktop\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (FAT32)
\\.\E: –> \\.\PhysicalDrive1 at offset 0x00000000`7f788600 (FAT32)

PhysicalDrive0 Model Number: WDCWD800BB-75CAA0, Rev: 16.06V16
PhysicalDrive1 Model Number: Maxtor51536H2, Rev: JAC61HU0

Size Device Name MBR Status
——————————————–
74 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)!
SHA1: 4ECC3C3B1681F21372ABA4F582251838559E85CD
14 GB \\.\PhysicalDrive1 Known-bad MBR code detected (Whistler / Black Internet)!
SHA1: 4ECC3C3B1681F21372ABA4F582251838559E85CD


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-31 17:11:53
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\uxtdrpod.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs ssfs0bbc.sys (Spy Sweeper FileSystem Filter Driver/Webroot Software, Inc. (www.webroot.com))
AttachedDevice \FileSystem\Fastfat \Fat ssfs0bbc.sys (Spy Sweeper FileSystem Filter Driver/Webroot Software, Inc. (www.webroot.com))
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \Driver\Tcpip \Device\Ip 89F3DA08

AttachedDevice \Driver\Tcpip \Device\Ip NEOFLTR_650_15507.SYS (NetBIOS Redirector/Juniper Networks)

Device \Driver\Tcpip \Device\Tcp 89F3DA08

AttachedDevice \Driver\Tcpip \Device\Tcp NEOFLTR_650_15507.SYS (NetBIOS Redirector/Juniper Networks)

Device \Driver\Tcpip \Device\Udp 89F3DA08

AttachedDevice \Driver\Tcpip \Device\Udp NEOFLTR_650_15507.SYS (NetBIOS Redirector/Juniper Networks)

Device \Driver\Tcpip \Device\RawIp 89F3DA08

AttachedDevice \Driver\Tcpip \Device\RawIp NEOFLTR_650_15507.SYS (NetBIOS Redirector/Juniper Networks)

—- Processes - GMER 1.0.15 —-

Process C:\Program Files\Internet Explorer\iexplore.exe (*** hidden *** ) 2708

—- EOF - GMER 1.0.15 —-
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
I'm on a second computer. The problematic computer shows the Combofix blue screen "Preparing Log Report. Do not run any programs until Combofix has finished.," but a Windows Red X window popped up: Windows - No Disk Exception Processing Message C0000013 Parameter 75b6bf7c 4 75b6bf7c 75b6bf7c Cancel - Try Again - Continue Please advise
Sorry about the problems you are having,i need to get advice on this from my teacher.I will reply as soon as possible but please be aware that this may take a while
Is it safe to leave the Combofix process and Windows X error 'hanging' without inititating either 'Cancel -Try Again - Continue' command? I can leave it all night and we can resume tomorrow, if that is safe.
I attempted 'Try Again' but got the same error window: Windows - No Disk Exception Processing Message C0000013 Parameter 75b6bf7c 4 75b6bf7c 75b6bf7c Cancel - Try Again - Continue
Hi,can you please give as much detail on what is happening with your computer.

Reboot the computer.
Delete the copy of Combofix you have and download a fresh one from one of the links below,follow the instructions to rename it.Don't run it yet


Download Combofix from either of the links below. You must rename it to combo.com before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.
  • Double click on the renamed ComboFix.exe & follow the prompts. When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.


Next boot into safe mode

To get into the Windows 2000 / XP Safe mode, as the computer is booting press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu". Use your arrow keys to move to "Safe Mode" and press your Enter key.


Now run Combofix
I just want to make sure I have this correct because your text seems to be telling me to run Combofix twice:

Download and rename the Combofix (done)

Double click on the renamed ComboFix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the C:\ComboFix.txt so we can continue cleaning the system.

Do I wait for your reply re: this first posted text before proceeding to the following?

Next boot into safe mode

To get into the Windows 2000 / XP Safe mode, as the computer is booting press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu". Use your arrow keys to move to "Safe Mode" and press your Enter key.


Now run Combofix Do I post a second text after this second combofix run?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI