This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't udapte anti-malware apps or download from microsoft sites

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Running Winxp, sp3.

Unable to update Microsoft Security Essentials, Malwarebyte's Anti-malware, Spybot Search and Destroy or Lavasoft Adaware.

Error messages indicate internet connection is not working, but I can browse using Firefox.

One of the programs above gave me an error message of cannot connect to 127.0.0.1, so maybe this is a hosts file problem?




___________________________
OTL logfile created on: 9/12/2010 3:28:44 fme - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\fme\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 3.62 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
Drive D: | 10.24 Gb Total Space | 1.27 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LATITUDE505
Current User Name: fme
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\fme\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\sndvol32.exe (Microsoft Corporation)
PRC - C:\Program Files\Ativa\Cardbus AWGNA54\Wireless Utility\Ativawcui.exe (Belkin)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Apoint\hidfind.exe (Alps Electric Co., Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\fme\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5705_x-ww_36cfed49\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
MOD - C:\WINDOWS\system32\rsaenh.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - c:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.21006_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\mscorsvw.exe (Microsoft Corporation)
SRV - (WinDefend) – c:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()


========== Driver Services (SafeList) ==========

DRV - (UIUSys) – C:\WINDOWS\System32\drivers\UIUSys.sys File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MpFilter) – C:\WINDOWS\system32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (PTDCWWAN) – C:\WINDOWS\system32\drivers\PTDCWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDCVsp) PANTECH PC Card Diagnostic Serial Port (UDP) – C:\WINDOWS\system32\drivers\PTDCVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDCMdm) PANTECH PC Card Drivers (UDP) – C:\WINDOWS\system32\drivers\PTDCMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDCBus) PANTECH PC Card Composite Device Driver (UDP) – C:\WINDOWS\system32\drivers\PTDCBus.sys (DEVGURU Co,LTD.)
DRV - (DigimHID) – C:\WINDOWS\system32\drivers\DigimHID.SYS (ACE CAD Enterprise Co., Ltd.)
DRV - (AWGNA54) – C:\WINDOWS\system32\drivers\AWGNA54.sys (Ativa)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (wlanndi5) – C:\WINDOWS\system32\wlanndi5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SMNDIS5) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.google.com/toolbar/ie8/done.html
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.8.6
FF - prefs.js..extensions.enabledItems: [removed]:1.94.20100904
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 00:28:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/09 00:28:11 | 000,000,000 | —D | M]

[2009/12/27 19:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Extensions
[2010/09/12 10:30:48 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions
[2010/04/28 21:29:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/12 10:30:45 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]
[2010/09/12 10:30:37 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]
[2009/12/27 19:29:03 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/12/27 23:04:47 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

O1 HOSTS File: ([2010/08/22 17:22:36 | 000,000,024 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: $Temporary GISTS fuke
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [ilhxujgi] C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu\aimumxcuqiw.exe File not found
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] c:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [ilhxujgi] C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu\aimumxcuqiw.exe File not found
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ativa Wireless Utility.lnk = C:\Program Files\Ativa\Cardbus AWGNA54\Wireless Utility\Ativawcui.exe (Belkin)
O4 - Startup: C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk = C:\Program Files\BatteryBar\BatteryBar.exe File not found
O4 - Startup: C:\Documents and Settings\fme\Start Menu\Programs\Startup\VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1256571913274 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.100.1 [removed]
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-861567501-789336058-1343024091-1005 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - c:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/26 01:13:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell - "" = AutoRun
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell - "" = AutoRun
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell - "" = AutoRun
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 60 Days ==========

[2010/09/12 15:10:02 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
[2010/09/11 21:16:04 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu
[2010/09/06 22:35:50 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\taifypqtu
[2010/09/05 14:54:01 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\mfxgosviv
[2010/09/03 20:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\BatteryBar
[2010/09/03 20:08:29 | 000,000,000 | —D | C] – C:\Program Files\BatteryBar
[2010/09/02 08:29:50 | 000,227,840 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzFlRdr.dll
[2010/09/02 08:29:50 | 000,126,976 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdfc.dll
[2010/09/02 08:29:50 | 000,103,424 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzDCT.dll
[2010/09/02 08:29:46 | 000,194,560 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdf.dll
[2010/09/02 08:29:44 | 000,000,000 | —D | C] – C:\Program Files\Bullzip
[2010/09/02 08:26:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Bullzip
[2010/09/02 08:24:46 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comdlg32.OCX
[2010/09/01 17:09:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2010/09/01 17:09:56 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Office Genuine Advantage
[2010/08/29 21:48:40 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/08/29 21:48:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/08/29 21:48:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/08/29 21:47:58 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Apple
[2010/08/29 21:47:53 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/08/29 21:47:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/08/29 21:47:32 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Apple Computer
[2010/08/29 19:11:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA
[2010/08/26 12:51:26 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\POST Notes for xx Sep 2010
[2010/08/26 09:57:13 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\POST Notes for 24 Aug 2010
[2010/08/22 22:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Opera
[2010/08/22 22:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Opera
[2010/08/22 22:14:37 | 000,000,000 | —D | C] – C:\Program Files\Opera
[2010/08/22 19:17:58 | 000,000,000 | —D | C] – C:\Program Files\Emsisoft Anti-Malware
[2010/08/22 19:17:58 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\My Documents\Anti-Malware
[2010/08/22 15:42:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Malwarebytes
[2010/08/22 15:42:50 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/22 15:42:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/22 15:42:46 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/22 15:42:46 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/20 18:31:51 | 000,000,000 | –SD | C] – C:\Documents and Settings\fme\My Documents\My Data Sources
[2010/08/16 06:48:49 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/08/16 06:48:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2010/08/16 06:48:15 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/08/16 06:47:27 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/08/16 06:47:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/08/15 23:00:48 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Google
[2010/08/14 21:56:41 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/08/10 05:15:58 | 000,094,208 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2010/07/18 20:19:38 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\Flash Drive Backup
[2010/07/17 13:03:50 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\DSL
[2010/07/17 12:28:02 | 000,000,000 | -H-D | C] – C:\Program Files\InstallJammer Registry
[2010/07/17 12:27:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Thinstation-2.2.2
[2010/07/14 22:02:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 60 Days ==========

[2010/09/12 15:09:54 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
[2010/09/12 15:02:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/12 14:34:28 | 000,099,840 | —- | M] () – C:\Documents and Settings\fme\My Documents\Fire & Police taxes.ppt
[2010/09/12 09:57:31 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/12 09:53:04 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/09/12 09:52:15 | 000,001,893 | —- | M] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\VZAccess Manager.lnk
[2010/09/12 09:52:07 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/09/12 09:52:05 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/12 09:52:02 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/12 09:51:45 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/12 09:51:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/12 09:50:55 | 008,126,464 | -H– | M] () – C:\Documents and Settings\fme\NTUSER.DAT
[2010/09/12 09:50:32 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\fme\ntuser.ini
[2010/09/12 09:50:21 | 005,890,164 | -H– | M] () – C:\Documents and Settings\fme\Local Settings\Application Data\IconCache.db
[2010/09/11 21:53:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/11 06:41:29 | 000,025,088 | —- | M] () – C:\Documents and Settings\fme\My Documents\Tracy Thurman.doc
[2010/09/09 00:27:44 | 000,024,576 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Voter Letter v1.doc
[2010/09/08 22:25:54 | 000,154,112 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub
[2010/09/08 22:23:03 | 000,154,112 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16d.pub
[2010/09/08 22:22:08 | 000,126,796 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub.pdf
[2010/09/07 23:53:03 | 000,047,616 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv2.pub
[2010/09/07 23:44:44 | 000,443,904 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv1.pub
[2010/09/07 23:41:12 | 000,252,902 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub.pdf
[2010/09/07 23:39:25 | 000,443,904 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub
[2010/09/04 09:57:18 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Daily Star Election Issues v5.doc
[2010/09/04 09:54:03 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v4.doc
[2010/09/04 00:24:12 | 000,028,160 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v3.doc
[2010/09/03 23:09:09 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v2.doc
[2010/09/03 20:11:24 | 000,001,415 | —- | M] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk
[2010/09/03 15:37:32 | 000,154,624 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16b.pub
[2010/09/03 02:19:12 | 000,148,480 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16a.pub
[2010/09/03 01:47:05 | 000,131,584 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16.pub
[2010/09/03 01:06:42 | 000,077,760 | —- | M] () – C:\Documents and Settings\fme\Desktop\Edwards.jpg
[2010/09/02 13:14:31 | 000,135,168 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v15.pub
[2010/09/02 13:11:22 | 000,134,656 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v14.pub
[2010/09/02 11:51:40 | 000,135,168 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v12.pub
[2010/09/02 11:25:36 | 000,134,144 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v10.pub
[2010/09/02 10:43:59 | 000,132,608 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v9.pub
[2010/09/02 08:29:50 | 000,000,698 | —- | M] () – C:\Documents and Settings\fme\Desktop\Bullzip PDF Printer.lnk
[2010/09/01 23:31:46 | 000,453,632 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v8.pub
[2010/09/01 22:53:04 | 000,453,632 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v7.pub
[2010/09/01 22:14:03 | 000,450,048 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v6.pub
[2010/09/01 17:39:31 | 001,007,616 | —- | M] () – C:\Documents and Settings\fme\My Documents\IndyVotersJul2010.mdb
[2010/08/29 21:49:08 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/26 02:01:50 | 000,450,048 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.pub
[2010/08/26 01:39:00 | 000,155,319 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.jpg
[2010/08/26 01:38:04 | 000,450,560 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v4.pub
[2010/08/26 00:58:45 | 000,447,488 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v3.pub
[2010/08/25 23:30:10 | 000,446,464 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v2.pub
[2010/08/25 22:40:40 | 000,446,464 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v1.pub
[2010/08/24 21:49:58 | 000,394,997 | —- | M] () – C:\Documents and Settings\fme\Desktop\Edwards - Chief Aug 2010.jpg
[2010/08/23 10:16:07 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/22 22:14:42 | 000,000,610 | —- | M] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/22 22:14:42 | 000,000,592 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/08/22 17:22:36 | 000,000,024 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/22 15:42:54 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/16 06:48:14 | 000,000,885 | —- | M] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/16 06:48:14 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/15 12:21:37 | 000,243,128 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/15 11:55:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/15 11:52:32 | 000,000,603 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/15 11:49:28 | 000,540,530 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/15 11:49:28 | 000,472,704 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/15 11:49:28 | 000,077,870 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/14 00:30:01 | 000,000,820 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/08/12 16:16:07 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 1.doc
[2010/08/12 16:13:00 | 000,028,160 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 2.doc
[2010/08/12 16:01:28 | 000,027,136 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 3.doc
[2010/08/10 05:15:58 | 000,094,208 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2010/07/27 01:28:54 | 008,463,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/12 10:44:41 | 000,099,840 | —- | C] () – C:\Documents and Settings\fme\My Documents\Fire & Police taxes.ppt
[2010/09/11 06:36:18 | 000,025,088 | —- | C] () – C:\Documents and Settings\fme\My Documents\Tracy Thurman.doc
[2010/09/09 00:15:27 | 000,024,576 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Voter Letter v1.doc
[2010/09/08 22:25:54 | 000,154,112 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub
[2010/09/08 22:22:07 | 000,126,796 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub.pdf
[2010/09/07 23:45:07 | 000,047,616 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv2.pub
[2010/09/07 23:44:44 | 000,443,904 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv1.pub
[2010/09/07 23:41:11 | 000,252,902 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub.pdf
[2010/09/07 23:34:52 | 000,443,904 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub
[2010/09/04 09:57:18 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Daily Star Election Issues v5.doc
[2010/09/04 00:24:21 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v4.doc
[2010/09/03 23:09:31 | 000,028,160 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v3.doc
[2010/09/03 20:24:34 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v2.doc
[2010/09/03 20:08:30 | 000,001,415 | —- | C] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk
[2010/09/03 15:39:28 | 000,154,112 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16d.pub
[2010/09/03 02:34:28 | 000,154,624 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16b.pub
[2010/09/03 01:47:41 | 000,148,480 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16a.pub
[2010/09/03 01:06:41 | 000,077,760 | —- | C] () – C:\Documents and Settings\fme\Desktop\Edwards.jpg
[2010/09/02 23:41:52 | 000,131,584 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16.pub
[2010/09/02 13:14:31 | 000,135,168 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v15.pub
[2010/09/02 11:55:17 | 000,134,656 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v14.pub
[2010/09/02 11:27:23 | 000,135,168 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v12.pub
[2010/09/02 10:45:31 | 000,134,144 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v10.pub
[2010/09/02 08:29:50 | 000,000,698 | —- | C] () – C:\Documents and Settings\fme\Desktop\Bullzip PDF Printer.lnk
[2010/09/01 23:33:19 | 000,132,608 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v9.pub
[2010/09/01 22:56:21 | 000,453,632 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v8.pub
[2010/09/01 22:22:46 | 000,453,632 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v7.pub
[2010/08/29 21:49:08 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/29 21:47:59 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/29 19:11:16 | 000,000,236 | —- | C] () – C:\WINDOWS\tasks\OGALogon.job
[2010/08/26 02:02:05 | 000,450,048 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v6.pub
[2010/08/26 01:38:59 | 000,155,319 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.jpg
[2010/08/26 01:38:14 | 000,450,048 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.pub
[2010/08/26 00:58:56 | 000,450,560 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v4.pub
[2010/08/25 23:30:24 | 000,447,488 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v3.pub
[2010/08/25 22:44:33 | 000,446,464 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v2.pub
[2010/08/25 22:20:39 | 000,446,464 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v1.pub
[2010/08/25 13:52:25 | 000,394,997 | —- | C] () – C:\Documents and Settings\fme\Desktop\Edwards - Chief Aug 2010.jpg
[2010/08/23 10:11:03 | 000,006,296 | —- | C] () – C:\Documents and Settings\fme\reset.log
[2010/08/22 22:14:42 | 000,000,610 | —- | C] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/22 22:14:42 | 000,000,592 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/08/22 15:42:54 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/16 08:45:31 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/08/16 06:49:53 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/08/16 06:48:14 | 000,000,885 | —- | C] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/16 06:48:14 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/14 11:08:52 | 001,007,616 | —- | C] () – C:\Documents and Settings\fme\My Documents\IndyVotersJul2010.mdb
[2010/08/14 00:35:53 | 000,000,408 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/08/12 15:44:17 | 000,027,136 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 3.doc
[2010/08/12 15:18:20 | 000,028,160 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 2.doc
[2010/08/12 14:31:25 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 1.doc
[2010/05/31 18:26:46 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/29 12:08:25 | 000,000,126 | —- | C] () – C:\Documents and Settings\fme\Local Settings\Application Data\fusioncache.dat
[2009/12/28 11:38:15 | 000,073,414 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2009/12/27 23:24:51 | 000,076,407 | —- | C] () – C:\Documents and Settings\fme\Application Data\Smiley.ico
[2009/10/26 02:01:52 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2009/10/26 01:51:33 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2009/10/26 01:46:37 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2009/10/26 01:09:30 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2009/10/26 01:09:30 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2009/10/26 01:09:30 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/12/29 11:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CodeGear
[2009/12/29 12:34:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Embarcadero
[2009/12/29 12:43:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7A0BDD12-2C4E-4120-BFFF-7B14DA13BE27}
[2010/08/16 06:48:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2009/12/31 14:06:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~1
[2010/09/11 17:06:22 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\BatteryBar
[2010/09/02 08:26:59 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Bullzip
[2009/12/29 12:34:53 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\CodeGear
[2009/12/27 23:05:07 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Foxit
[2010/05/06 11:23:24 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Foxit Software
[2010/04/02 23:19:55 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\kompozer.net
[2010/08/22 22:14:46 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Opera
[2010/03/30 19:45:23 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Smith Micro
[2010/05/16 18:17:02 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Thinstall
[2010/09/12 15:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\uTorrent
[2010/09/12 09:53:04 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/09/12 09:57:31 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/09/12 09:52:07 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/09/12 09:51:33 | 000,005,162 | —- | M] () – C:\aaw7boot.log
[2009/10/26 01:13:44 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/10/26 01:06:09 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/10/26 01:13:44 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/10/26 01:13:44 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/10/26 01:13:44 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 10:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 10:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/12 09:51:33 | 402,653,184 | -HS- | M] () – C:\pagefile.sys
[2010/08/22 18:45:46 | 000,000,383 | —- | M] () – C:\rkill.log
[2010/08/22 19:14:31 | 000,034,250 | —- | M] () – C:\TDSSKiller.2.4.1.2_22.08.2010_19.14.06_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/10/26 01:13:09 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/10/24 19:29:16 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/10/24 19:29:15 | 001,073,152 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/10/24 19:29:15 | 000,823,296 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/10/26 01:13:50 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >
[2010/09/12 15:09:54 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-03 12:13:08
< End of report >
________________________
OTL Extras logfile created on: 9/12/2010 3:28:44 fme - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\fme\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 3.62 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
Drive D: | 10.24 Gb Total Space | 1.27 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LATITUDE505
Current User Name: fme
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_USERS\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1

========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{20aa4150-b5f4-11de-8a39-0800200c9a66}_is1" = KompoZer 0.8b3
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{50EF6812-7B51-4459-A52D-B4776DAAA415}" = ACECAD DigiMemo Manager
"{57EC5BFE-7CB7-3057-8385-C9D72918511C}" = Microsoft .NET Framework 4 Client Profile Beta 2
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E405B40-3879-3C9B-9286-8D5E71258C35}" = Microsoft .NET Framework 4 Extended Beta 2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7ED5371F-F4EA-48F9-B8F7-C8777AD9DF69}" = Borland Turbo Delphi
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AA74ED37-681C-4AE8-8D1D-5485EBB3ED3D}" = SQL Server System CLR Types
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE65493C-EA18-3458-AA58-EEDB9D671528}" = Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)
"{D95AA4F4-9FCF-4BD8-AC07-AB1912A202E2}_is1" = Home Plan Pro version 5.2.18.17
"{DB6F07FF-A436-453a-B685-F6C1F4F09D22}" = PANTECH PC Card Software
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E69974C9-ECDC-4B02-97EB-FB1CE638CECB}" = Web Deployment Tool
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}" = Microsoft .NET Framework SDK (English) 1.1
"{ED53D5EC-5D31-4A94-83F9-69FE057510C6}" = Ativa Wireless Utility
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F07737AC-C218-4272-A678-26CA5F6CD8DF}" = Opera 10.61
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"ABC Amber Photoshop Converter" = ABC Amber Photoshop Converter
"Ad-Aware" = Ad-Aware
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ask Toolbar_is1" = Foxit Toolbar
"BatteryBar" = BatteryBar (remove only)
"Belarc Advisor" = Belarc Advisor 8.1
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 6.0.0.865
"CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1" = Conexant D480 MDC V.92 Modem
"DynoPlex eOffice" = DynoPlex eOffice
"Foxit Reader" = Foxit Reader
"GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.70
"ie8" = Windows Internet Explorer 8
"InstallShield_{ED53D5EC-5D31-4A94-83F9-69FE057510C6}" = Ativa Wireless Utility
"jZip" = jZip
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile Beta 2" = Microsoft .NET Framework 4 Client Profile Beta 2
"Microsoft .NET Framework 4 Extended Beta 2" = Microsoft .NET Framework 4 Extended Beta 2
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft Security Essentials" = Microsoft Security Essentials
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"PROSet" = Intel® PRO Network Adapters and Drivers
"Punch! Home Design - Platinum" = Punch! Home Design - Platinum
"RealVNC_is1" = VNC Free Edition 4.1.3
"uTorrent" = µTorrent
"Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)" = Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)
"VZAccess Manager" = VZAccess Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/12/2010 10:45:59 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 10:51:48 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 10:52:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 11:47:51 fme | Computer Name = LATITUDE505 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3888, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/12/2010 12:39:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 12:44:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 2:25:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 2:29:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 4:06:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 4:23:02 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

[ System Events ]
Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/12/2010 12:16:07 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6103.0 Error
code: 0x80072efd Error description: A connection with the server could not be established


Error - 9/12/2010 2:52:52 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6103.0 Error
code: 0x80072efd Error description: A connection with the server could not be established


Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/12/2010 4:27:22 fme | Computer Name = LATITUDE505 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.


< End of report >
Hello fmedwards3 and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:
• Please do not install/uninstall any programs unless asked to.
• Please do not run any scans other than those requested
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.


I am looking through your log now and will reply as soon as possible.

Satchfan
Hello again fmedwards3

You do have some infections on your computer. We will do our best to clean it up but there are some things I need to find out which might help with this.

I see you have rkill and TDSSKiller on your computer: have you asked for help at another forum and if not, what is the reason for their presence?

Do you know why these are on your computer as they seem unrelated to any program:

[2010/08/29 19:11:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA



Also. Do you know what this is?:

[2009/12/31 14:06:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~1


A couple of points I would like to bring this to your attention:

The ASK toolbar comes bundled with many third-party applications, is considered as Spyware and also comes with vulnerabilities.

See the following links and decide whether or not you wish to keep them:

http://secunia.com/advisories/product/15810/
http://www.benedelman.org/spyware/ask-toolbars/


P2P - I see you still have P2P software, (BitTorrent/uTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we have previously warned you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection.

This page will give you further information.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel >> Add or Remove Programs.

Should you decide to keep it, please don’t use it until we have finished up here.


Check for Java update and remove old versions.

Your version of Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please follow these steps to update Java components and remove older versions.
1. Click Start, Settings and then click Control Panel
2. Double-click on the Java
3. Click on the ‘Update’ tab and then on Update now.
4. Still in the Java Control Panel, click on the General tab
5..Under Temporary Internet Files, click the Settings button.
6. Click on the Delete Files button. There are two options in the window to clear the cache – Leave BOTH of the following checked:
Applications and Applets
Trace and Log Files
7 Click OK on Delete Temporary Files Window
8 Click OK to leave the Temporary Files Window
9 Click OK to leave the Java Control Panel.
Still in the Control Panel, double-click on Add or Remove programs. (it may take time to produce the list of programs, so please be patient). Now remove all earlier versions of Java.


Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092
    O4 - HKLM..\Run: [ilhxujgi] C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu\aimumxcuqiw.exe File not found
    O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [ilhxujgi] C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu\aimumxcuqiw.exe File not found
    O4 - Startup: C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk = C:\Program Files\BatteryBar\BatteryBar.exe File not found
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.100.1 [removed]
    O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell - "" = AutoRun
    O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
    O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell - "" = AutoRun
    O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell - "" = AutoRun
    O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
    [2010/09/11 21:16:04 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu
    [2010/09/06 22:35:50 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\taifypqtu
    [2010/09/05 14:54:01 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\mfxgosviv
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • All drives/partitions except C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Logs to include with next post:

OTL.txt
Gmer.txt


Thanks

Satchfan
1. If rkill and TDSSKiller are on my computer, that would be from following instructions to clean a previous infection.

2. I don't know what the following are:
2010/08/29 19:11:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK

or what the following is:
[2009/12/31 14:06:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~1


3. I don't use the ASK toolbar and would remove it, but there is not uninstall that I can find.

4. I removed utorrent and update Java, and ran OTL.

5. The log files follow:
OTL logfile created on: 9/12/2010 3:28:44 fme - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\fme\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 3.62 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
Drive D: | 10.24 Gb Total Space | 1.27 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LATITUDE505
Current User Name: fme
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\fme\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\sndvol32.exe (Microsoft Corporation)
PRC - C:\Program Files\Ativa\Cardbus AWGNA54\Wireless Utility\Ativawcui.exe (Belkin)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Apoint\hidfind.exe (Alps Electric Co., Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\fme\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5705_x-ww_36cfed49\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
MOD - C:\WINDOWS\system32\rsaenh.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - c:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.21006_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\mscorsvw.exe (Microsoft Corporation)
SRV - (WinDefend) – c:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()


========== Driver Services (SafeList) ==========

DRV - (UIUSys) – C:\WINDOWS\System32\drivers\UIUSys.sys File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MpFilter) – C:\WINDOWS\system32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (PTDCWWAN) – C:\WINDOWS\system32\drivers\PTDCWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDCVsp) PANTECH PC Card Diagnostic Serial Port (UDP) – C:\WINDOWS\system32\drivers\PTDCVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDCMdm) PANTECH PC Card Drivers (UDP) – C:\WINDOWS\system32\drivers\PTDCMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDCBus) PANTECH PC Card Composite Device Driver (UDP) – C:\WINDOWS\system32\drivers\PTDCBus.sys (DEVGURU Co,LTD.)
DRV - (DigimHID) – C:\WINDOWS\system32\drivers\DigimHID.SYS (ACE CAD Enterprise Co., Ltd.)
DRV - (AWGNA54) – C:\WINDOWS\system32\drivers\AWGNA54.sys (Ativa)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (wlanndi5) – C:\WINDOWS\system32\wlanndi5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SMNDIS5) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.google.com/toolbar/ie8/done.html
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-21-861567501-789336058-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.8.6
FF - prefs.js..extensions.enabledItems: [removed]:1.94.20100904
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 00:28:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/09 00:28:11 | 000,000,000 | —D | M]

[2009/12/27 19:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Extensions
[2010/09/12 10:30:48 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions
[2010/04/28 21:29:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/12 10:30:45 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]
[2010/09/12 10:30:37 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]
[2009/12/27 19:29:03 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/12/27 23:04:47 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

O1 HOSTS File: ([2010/08/22 17:22:36 | 000,000,024 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: $Temporary GISTS fuke
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [ilhxujgi] C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu\aimumxcuqiw.exe File not found
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] c:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [ilhxujgi] C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu\aimumxcuqiw.exe File not found
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-861567501-789336058-1343024091-1005..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ativa Wireless Utility.lnk = C:\Program Files\Ativa\Cardbus AWGNA54\Wireless Utility\Ativawcui.exe (Belkin)
O4 - Startup: C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk = C:\Program Files\BatteryBar\BatteryBar.exe File not found
O4 - Startup: C:\Documents and Settings\fme\Start Menu\Programs\Startup\VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1256571913274 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.100.1 [removed]
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-21-861567501-789336058-1343024091-1005 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - c:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/26 01:13:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell - "" = AutoRun
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{22e0016f-f430-11de-ad65-000f1fa14238}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell - "" = AutoRun
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{5f251104-6094-11df-ad87-000f1fa14238}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell - "" = AutoRun
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ca5c13a0-701f-11df-ad89-00173f1ec479}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 60 Days ==========

[2010/09/12 15:10:02 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
[2010/09/11 21:16:04 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\imqwfaywu
[2010/09/06 22:35:50 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\taifypqtu
[2010/09/05 14:54:01 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\mfxgosviv
[2010/09/03 20:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\BatteryBar
[2010/09/03 20:08:29 | 000,000,000 | —D | C] – C:\Program Files\BatteryBar
[2010/09/02 08:29:50 | 000,227,840 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzFlRdr.dll
[2010/09/02 08:29:50 | 000,126,976 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdfc.dll
[2010/09/02 08:29:50 | 000,103,424 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzDCT.dll
[2010/09/02 08:29:46 | 000,194,560 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdf.dll
[2010/09/02 08:29:44 | 000,000,000 | —D | C] – C:\Program Files\Bullzip
[2010/09/02 08:26:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Bullzip
[2010/09/02 08:24:46 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comdlg32.OCX
[2010/09/01 17:09:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2010/09/01 17:09:56 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Office Genuine Advantage
[2010/08/29 21:48:40 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/08/29 21:48:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/08/29 21:48:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/08/29 21:47:58 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Apple
[2010/08/29 21:47:53 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/08/29 21:47:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/08/29 21:47:32 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Apple Computer
[2010/08/29 19:11:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA
[2010/08/26 12:51:26 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\POST Notes for xx Sep 2010
[2010/08/26 09:57:13 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\POST Notes for 24 Aug 2010
[2010/08/22 22:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Opera
[2010/08/22 22:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Opera
[2010/08/22 22:14:37 | 000,000,000 | —D | C] – C:\Program Files\Opera
[2010/08/22 19:17:58 | 000,000,000 | —D | C] – C:\Program Files\Emsisoft Anti-Malware
[2010/08/22 19:17:58 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\My Documents\Anti-Malware
[2010/08/22 15:42:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Malwarebytes
[2010/08/22 15:42:50 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/22 15:42:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/22 15:42:46 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/22 15:42:46 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/20 18:31:51 | 000,000,000 | –SD | C] – C:\Documents and Settings\fme\My Documents\My Data Sources
[2010/08/16 06:48:49 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/08/16 06:48:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2010/08/16 06:48:15 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/08/16 06:47:27 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/08/16 06:47:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/08/15 23:00:48 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Google
[2010/08/14 21:56:41 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/08/10 05:15:58 | 000,094,208 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | C] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2010/07/18 20:19:38 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\Flash Drive Backup
[2010/07/17 13:03:50 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\DSL
[2010/07/17 12:28:02 | 000,000,000 | -H-D | C] – C:\Program Files\InstallJammer Registry
[2010/07/17 12:27:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Thinstation-2.2.2
[2010/07/14 22:02:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 60 Days ==========

[2010/09/12 15:09:54 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
[2010/09/12 15:02:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/12 14:34:28 | 000,099,840 | —- | M] () – C:\Documents and Settings\fme\My Documents\Fire & Police taxes.ppt
[2010/09/12 09:57:31 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/12 09:53:04 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/09/12 09:52:15 | 000,001,893 | —- | M] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\VZAccess Manager.lnk
[2010/09/12 09:52:07 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/09/12 09:52:05 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/12 09:52:02 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/12 09:51:45 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/12 09:51:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/12 09:50:55 | 008,126,464 | -H– | M] () – C:\Documents and Settings\fme\NTUSER.DAT
[2010/09/12 09:50:32 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\fme\ntuser.ini
[2010/09/12 09:50:21 | 005,890,164 | -H– | M] () – C:\Documents and Settings\fme\Local Settings\Application Data\IconCache.db
[2010/09/11 21:53:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/11 06:41:29 | 000,025,088 | —- | M] () – C:\Documents and Settings\fme\My Documents\Tracy Thurman.doc
[2010/09/09 00:27:44 | 000,024,576 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Voter Letter v1.doc
[2010/09/08 22:25:54 | 000,154,112 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub
[2010/09/08 22:23:03 | 000,154,112 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16d.pub
[2010/09/08 22:22:08 | 000,126,796 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub.pdf
[2010/09/07 23:53:03 | 000,047,616 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv2.pub
[2010/09/07 23:44:44 | 000,443,904 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv1.pub
[2010/09/07 23:41:12 | 000,252,902 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub.pdf
[2010/09/07 23:39:25 | 000,443,904 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub
[2010/09/04 09:57:18 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Daily Star Election Issues v5.doc
[2010/09/04 09:54:03 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v4.doc
[2010/09/04 00:24:12 | 000,028,160 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v3.doc
[2010/09/03 23:09:09 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v2.doc
[2010/09/03 20:11:24 | 000,001,415 | —- | M] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk
[2010/09/03 15:37:32 | 000,154,624 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16b.pub
[2010/09/03 02:19:12 | 000,148,480 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16a.pub
[2010/09/03 01:47:05 | 000,131,584 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16.pub
[2010/09/03 01:06:42 | 000,077,760 | —- | M] () – C:\Documents and Settings\fme\Desktop\Edwards.jpg
[2010/09/02 13:14:31 | 000,135,168 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v15.pub
[2010/09/02 13:11:22 | 000,134,656 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v14.pub
[2010/09/02 11:51:40 | 000,135,168 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v12.pub
[2010/09/02 11:25:36 | 000,134,144 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v10.pub
[2010/09/02 10:43:59 | 000,132,608 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v9.pub
[2010/09/02 08:29:50 | 000,000,698 | —- | M] () – C:\Documents and Settings\fme\Desktop\Bullzip PDF Printer.lnk
[2010/09/01 23:31:46 | 000,453,632 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v8.pub
[2010/09/01 22:53:04 | 000,453,632 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v7.pub
[2010/09/01 22:14:03 | 000,450,048 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v6.pub
[2010/09/01 17:39:31 | 001,007,616 | —- | M] () – C:\Documents and Settings\fme\My Documents\IndyVotersJul2010.mdb
[2010/08/29 21:49:08 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/26 02:01:50 | 000,450,048 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.pub
[2010/08/26 01:39:00 | 000,155,319 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.jpg
[2010/08/26 01:38:04 | 000,450,560 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v4.pub
[2010/08/26 00:58:45 | 000,447,488 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v3.pub
[2010/08/25 23:30:10 | 000,446,464 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v2.pub
[2010/08/25 22:40:40 | 000,446,464 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v1.pub
[2010/08/24 21:49:58 | 000,394,997 | —- | M] () – C:\Documents and Settings\fme\Desktop\Edwards - Chief Aug 2010.jpg
[2010/08/23 10:16:07 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/22 22:14:42 | 000,000,610 | —- | M] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/22 22:14:42 | 000,000,592 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/08/22 17:22:36 | 000,000,024 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/22 15:42:54 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/16 06:48:14 | 000,000,885 | —- | M] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/16 06:48:14 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/15 12:21:37 | 000,243,128 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/15 11:55:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/15 11:52:32 | 000,000,603 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/15 11:49:28 | 000,540,530 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/15 11:49:28 | 000,472,704 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/15 11:49:28 | 000,077,870 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/14 00:30:01 | 000,000,820 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/08/12 16:16:07 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 1.doc
[2010/08/12 16:13:00 | 000,028,160 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 2.doc
[2010/08/12 16:01:28 | 000,027,136 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 3.doc
[2010/08/10 05:15:58 | 000,094,208 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTimeVR.qtx
[2010/08/10 05:15:58 | 000,069,632 | —- | M] (Apple Inc.) – C:\WINDOWS\System32\QuickTime.qts
[2010/07/27 01:28:54 | 008,463,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/12 10:44:41 | 000,099,840 | —- | C] () – C:\Documents and Settings\fme\My Documents\Fire & Police taxes.ppt
[2010/09/11 06:36:18 | 000,025,088 | —- | C] () – C:\Documents and Settings\fme\My Documents\Tracy Thurman.doc
[2010/09/09 00:15:27 | 000,024,576 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Voter Letter v1.doc
[2010/09/08 22:25:54 | 000,154,112 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub
[2010/09/08 22:22:07 | 000,126,796 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub.pdf
[2010/09/07 23:45:07 | 000,047,616 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv2.pub
[2010/09/07 23:44:44 | 000,443,904 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv1.pub
[2010/09/07 23:41:11 | 000,252,902 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub.pdf
[2010/09/07 23:34:52 | 000,443,904 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub
[2010/09/04 09:57:18 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Daily Star Election Issues v5.doc
[2010/09/04 00:24:21 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v4.doc
[2010/09/03 23:09:31 | 000,028,160 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v3.doc
[2010/09/03 20:24:34 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v2.doc
[2010/09/03 20:08:30 | 000,001,415 | —- | C] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\BatteryBar.lnk
[2010/09/03 15:39:28 | 000,154,112 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16d.pub
[2010/09/03 02:34:28 | 000,154,624 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16b.pub
[2010/09/03 01:47:41 | 000,148,480 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16a.pub
[2010/09/03 01:06:41 | 000,077,760 | —- | C] () – C:\Documents and Settings\fme\Desktop\Edwards.jpg
[2010/09/02 23:41:52 | 000,131,584 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16.pub
[2010/09/02 13:14:31 | 000,135,168 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v15.pub
[2010/09/02 11:55:17 | 000,134,656 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v14.pub
[2010/09/02 11:27:23 | 000,135,168 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v12.pub
[2010/09/02 10:45:31 | 000,134,144 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v10.pub
[2010/09/02 08:29:50 | 000,000,698 | —- | C] () – C:\Documents and Settings\fme\Desktop\Bullzip PDF Printer.lnk
[2010/09/01 23:33:19 | 000,132,608 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v9.pub
[2010/09/01 22:56:21 | 000,453,632 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v8.pub
[2010/09/01 22:22:46 | 000,453,632 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v7.pub
[2010/08/29 21:49:08 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/29 21:47:59 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/29 19:11:16 | 000,000,236 | —- | C] () – C:\WINDOWS\tasks\OGALogon.job
[2010/08/26 02:02:05 | 000,450,048 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v6.pub
[2010/08/26 01:38:59 | 000,155,319 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.jpg
[2010/08/26 01:38:14 | 000,450,048 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.pub
[2010/08/26 00:58:56 | 000,450,560 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v4.pub
[2010/08/25 23:30:24 | 000,447,488 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v3.pub
[2010/08/25 22:44:33 | 000,446,464 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v2.pub
[2010/08/25 22:20:39 | 000,446,464 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v1.pub
[2010/08/25 13:52:25 | 000,394,997 | —- | C] () – C:\Documents and Settings\fme\Desktop\Edwards - Chief Aug 2010.jpg
[2010/08/23 10:11:03 | 000,006,296 | —- | C] () – C:\Documents and Settings\fme\reset.log
[2010/08/22 22:14:42 | 000,000,610 | —- | C] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/22 22:14:42 | 000,000,592 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/08/22 15:42:54 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/16 08:45:31 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/08/16 06:49:53 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/08/16 06:48:14 | 000,000,885 | —- | C] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/16 06:48:14 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/14 11:08:52 | 001,007,616 | —- | C] () – C:\Documents and Settings\fme\My Documents\IndyVotersJul2010.mdb
[2010/08/14 00:35:53 | 000,000,408 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/08/12 15:44:17 | 000,027,136 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 3.doc
[2010/08/12 15:18:20 | 000,028,160 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 2.doc
[2010/08/12 14:31:25 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 1.doc
[2010/05/31 18:26:46 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/29 12:08:25 | 000,000,126 | —- | C] () – C:\Documents and Settings\fme\Local Settings\Application Data\fusioncache.dat
[2009/12/28 11:38:15 | 000,073,414 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2009/12/27 23:24:51 | 000,076,407 | —- | C] () – C:\Documents and Settings\fme\Application Data\Smiley.ico
[2009/10/26 02:01:52 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2009/10/26 01:51:33 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2009/10/26 01:46:37 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2009/10/26 01:09:30 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2009/10/26 01:09:30 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2009/10/26 01:09:30 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/12/29 11:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CodeGear
[2009/12/29 12:34:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Embarcadero
[2009/12/29 12:43:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7A0BDD12-2C4E-4120-BFFF-7B14DA13BE27}
[2010/08/16 06:48:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2009/12/31 14:06:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~1
[2010/09/11 17:06:22 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\BatteryBar
[2010/09/02 08:26:59 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Bullzip
[2009/12/29 12:34:53 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\CodeGear
[2009/12/27 23:05:07 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Foxit
[2010/05/06 11:23:24 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Foxit Software
[2010/04/02 23:19:55 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\kompozer.net
[2010/08/22 22:14:46 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Opera
[2010/03/30 19:45:23 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Smith Micro
[2010/05/16 18:17:02 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Thinstall
[2010/09/12 15:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\uTorrent
[2010/09/12 09:53:04 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/09/12 09:57:31 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/09/12 09:52:07 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/09/12 09:51:33 | 000,005,162 | —- | M] () – C:\aaw7boot.log
[2009/10/26 01:13:44 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/10/26 01:06:09 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/10/26 01:13:44 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/10/26 01:13:44 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/10/26 01:13:44 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 10:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 10:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/12 09:51:33 | 402,653,184 | -HS- | M] () – C:\pagefile.sys
[2010/08/22 18:45:46 | 000,000,383 | —- | M] () – C:\rkill.log
[2010/08/22 19:14:31 | 000,034,250 | —- | M] () – C:\TDSSKiller.2.4.1.2_22.08.2010_19.14.06_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/10/26 01:13:09 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/10/24 19:29:16 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/10/24 19:29:15 | 001,073,152 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/10/24 19:29:15 | 000,823,296 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/10/26 01:13:50 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >
[2010/09/12 15:09:54 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-03 12:13:08
< End of report >
___________________

OTL Extras logfile created on: 9/12/2010 3:28:44 fme - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\fme\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 3.62 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
Drive D: | 10.24 Gb Total Space | 1.27 Gb Free Space | 12.36% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LATITUDE505
Current User Name: fme
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 60 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_USERS\S-1-5-21-861567501-789336058-1343024091-1005\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1

========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{20aa4150-b5f4-11de-8a39-0800200c9a66}_is1" = KompoZer 0.8b3
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{50EF6812-7B51-4459-A52D-B4776DAAA415}" = ACECAD DigiMemo Manager
"{57EC5BFE-7CB7-3057-8385-C9D72918511C}" = Microsoft .NET Framework 4 Client Profile Beta 2
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E405B40-3879-3C9B-9286-8D5E71258C35}" = Microsoft .NET Framework 4 Extended Beta 2
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7ED5371F-F4EA-48F9-B8F7-C8777AD9DF69}" = Borland Turbo Delphi
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AA74ED37-681C-4AE8-8D1D-5485EBB3ED3D}" = SQL Server System CLR Types
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE65493C-EA18-3458-AA58-EEDB9D671528}" = Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)
"{D95AA4F4-9FCF-4BD8-AC07-AB1912A202E2}_is1" = Home Plan Pro version 5.2.18.17
"{DB6F07FF-A436-453a-B685-F6C1F4F09D22}" = PANTECH PC Card Software
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E69974C9-ECDC-4B02-97EB-FB1CE638CECB}" = Web Deployment Tool
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{EB9BD1D5-8DFB-48C4-927B-10BB47CA59B3}" = Microsoft .NET Framework SDK (English) 1.1
"{ED53D5EC-5D31-4A94-83F9-69FE057510C6}" = Ativa Wireless Utility
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F07737AC-C218-4272-A678-26CA5F6CD8DF}" = Opera 10.61
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"ABC Amber Photoshop Converter" = ABC Amber Photoshop Converter
"Ad-Aware" = Ad-Aware
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ask Toolbar_is1" = Foxit Toolbar
"BatteryBar" = BatteryBar (remove only)
"Belarc Advisor" = Belarc Advisor 8.1
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 6.0.0.865
"CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1" = Conexant D480 MDC V.92 Modem
"DynoPlex eOffice" = DynoPlex eOffice
"Foxit Reader" = Foxit Reader
"GPL Ghostscript Lite_is1" = GPL Ghostscript Lite 8.70
"ie8" = Windows Internet Explorer 8
"InstallShield_{ED53D5EC-5D31-4A94-83F9-69FE057510C6}" = Ativa Wireless Utility
"jZip" = jZip
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile Beta 2" = Microsoft .NET Framework 4 Client Profile Beta 2
"Microsoft .NET Framework 4 Extended Beta 2" = Microsoft .NET Framework 4 Extended Beta 2
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft Security Essentials" = Microsoft Security Essentials
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"PROSet" = Intel® PRO Network Adapters and Drivers
"Punch! Home Design - Platinum" = Punch! Home Design - Platinum
"RealVNC_is1" = VNC Free Edition 4.1.3
"uTorrent" = µTorrent
"Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)" = Visual Studio 2010 Tools for Office Runtime Beta 2 (x86)
"VZAccess Manager" = VZAccess Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/12/2010 10:45:59 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 10:51:48 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 10:52:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 11:47:51 fme | Computer Name = LATITUDE505 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3888, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/12/2010 12:39:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 12:44:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 2:25:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 2:29:01 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 4:06:52 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

Error - 9/12/2010 4:23:02 fme | Computer Name = LATITUDE505 | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.

[ System Events ]
Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/11/2010 6:59:13 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/12/2010 12:16:07 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6103.0 Error
code: 0x80072efd Error description: A connection with the server could not be established


Error - 9/12/2010 2:52:52 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6103.0 Error
code: 0x80072efd Error description: A connection with the server could not be established


Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/12/2010 2:52:58 fme | Computer Name = LATITUDE505 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.89.148.0 Update Source: %%851 Update Stage:
%%852 Source Path: http://go.microsoft.com/fwlink/?LinkID=121…DE-D861FCBCFCDE

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 1.1.6103.0 Error code: 0x80072efd Error description: A connection
with the server could not be established

Error - 9/12/2010 4:27:22 fme | Computer Name = LATITUDE505 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.


< End of report >
________________________

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-13 22:22:57
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\fme\LOCALS~1\Temp\ffryqfod.sys


—- System - GMER 1.0.15 —-

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF74F787E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF74F7BFE]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[3312] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

—- EOF - GMER 1.0.15 —-
Hi fmedwards3

If rkill and TDSSKiller are on my computer, that would be from following instructions to clean a previous infection

Could you tell me when was this and at which forum as it could be helpful if it is related to what is happening now.


I removed utorrent and update Java, and ran OTL

Good work and a wise move regarding uTorrent.


Thank you for the Gmer log but the OTL log was the old one, (Run 1).

After you had run the “fix”, you should have seen a message box saying "Fix complete! Click OK to open the fix log." If you clicked the OK button a log would have opened in Notepad..

A copy of the OTL fix log is saved in the same place as OTL, ie your desktop.

When you’ve located the fix log:• Open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
• Post the OTL.txt log it produces in your next reply.
Please post back with both logs:

Thanks

Satchfan
OK. I'll try again.

—————————
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-13 22:22:57
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\fme\LOCALS~1\Temp\ffryqfod.sys


—- System - GMER 1.0.15 —-

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF74F787E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF74F7BFE]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[3312] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

—- EOF - GMER 1.0.15 —-

———————————-

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-13 22:22:57
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\fme\LOCALS~1\Temp\ffryqfod.sys


—- System - GMER 1.0.15 —-

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF74F787E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF74F7BFE]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[3312] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

—- EOF - GMER 1.0.15 —-
Hi fmedwards3

That was the Gmer log you sent. Please do the following:

Run OTL
• Open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
• Post the OTL.txt log it produces in your next reply.
Thanks

Satchfan
OTL logfile created on: 9/15/2010 6:47:34 fme - Run 3
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\fme\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 41.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 57.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 4.17 Gb Free Space | 14.24% Space Free | Partition Type: NTFS
Drive D: | 10.24 Gb Total Space | 1.28 Gb Free Space | 12.50% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LATITUDE505
Current User Name: fme
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\fme\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Ativa\Cardbus AWGNA54\Wireless Utility\Ativawcui.exe (Belkin)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Apoint\hidfind.exe (Alps Electric Co., Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\fme\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5705_x-ww_36cfed49\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.21006_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.21006\mscorsvw.exe (Microsoft Corporation)
SRV - (WinDefend) – c:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()


========== Driver Services (SafeList) ==========

DRV - (UIUSys) – C:\WINDOWS\System32\drivers\UIUSys.sys File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MpFilter) – C:\WINDOWS\system32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (PTDCWWAN) – C:\WINDOWS\system32\drivers\PTDCWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDCVsp) PANTECH PC Card Diagnostic Serial Port (UDP) – C:\WINDOWS\system32\drivers\PTDCVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDCMdm) PANTECH PC Card Drivers (UDP) – C:\WINDOWS\system32\drivers\PTDCMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDCBus) PANTECH PC Card Composite Device Driver (UDP) – C:\WINDOWS\system32\drivers\PTDCBus.sys (DEVGURU Co,LTD.)
DRV - (DigimHID) – C:\WINDOWS\system32\drivers\DigimHID.SYS (ACE CAD Enterprise Co., Ltd.)
DRV - (AWGNA54) – C:\WINDOWS\system32\drivers\AWGNA54.sys (Ativa)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STAC97) Audio Driver (WDM) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (wlanndi5) – C:\WINDOWS\system32\wlanndi5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SMNDIS5) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.google.com/toolbar/ie8/done.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.8.6
FF - prefs.js..extensions.enabledItems: [removed]:1.94.20100904
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 00:28:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/13 11:20:50 | 000,000,000 | —D | M]

[2009/12/27 19:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Extensions
[2010/09/14 16:24:56 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions
[2010/04/28 21:29:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/12 10:30:45 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]
[2010/09/12 10:30:37 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]
[2010/09/14 16:24:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/09/13 11:20:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/12/27 23:04:47 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

O1 HOSTS File: ([2010/08/22 17:22:36 | 000,000,024 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: $Temporary GISTS fuke
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] c:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ativa Wireless Utility.lnk = C:\Program Files\Ativa\Cardbus AWGNA54\Wireless Utility\Ativawcui.exe (Belkin)
O4 - Startup: C:\Documents and Settings\fme\Start Menu\Programs\Startup\VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1256571913274 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.100.1 [removed]
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - c:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/26 01:13:44 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/09/13 11:21:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/09/13 11:21:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/09/13 11:12:00 | 000,000,000 | —D | C] – C:\_OTL
[2010/09/12 15:10:02 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
[2010/09/03 20:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\BatteryBar
[2010/09/03 20:08:29 | 000,000,000 | —D | C] – C:\Program Files\BatteryBar
[2010/09/02 08:29:50 | 000,227,840 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzFlRdr.dll
[2010/09/02 08:29:50 | 000,126,976 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdfc.dll
[2010/09/02 08:29:50 | 000,103,424 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzDCT.dll
[2010/09/02 08:29:46 | 000,194,560 | —- | C] (Bullzip) – C:\WINDOWS\System32\bzpdf.dll
[2010/09/02 08:29:44 | 000,000,000 | —D | C] – C:\Program Files\Bullzip
[2010/09/02 08:26:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Bullzip
[2010/09/01 17:09:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2010/09/01 17:09:56 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Office Genuine Advantage
[2010/08/29 21:48:40 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/08/29 21:48:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/08/29 21:48:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/08/29 21:47:58 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Apple
[2010/08/29 21:47:53 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/08/29 21:47:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/08/29 21:47:32 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Apple Computer
[2010/08/29 19:11:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/08/29 19:11:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA
[2010/08/26 12:51:26 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\POST Notes for xx Sep 2010
[2010/08/26 09:57:13 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\POST Notes for 24 Aug 2010
[2010/08/22 22:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Opera
[2010/08/22 22:14:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Opera
[2010/08/22 22:14:37 | 000,000,000 | —D | C] – C:\Program Files\Opera
[2010/08/22 19:17:58 | 000,000,000 | —D | C] – C:\Program Files\Emsisoft Anti-Malware
[2010/08/22 19:17:58 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\My Documents\Anti-Malware
[2010/08/22 15:42:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Malwarebytes
[2010/08/22 15:42:50 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/22 15:42:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/22 15:42:46 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/22 15:42:46 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/20 18:31:51 | 000,000,000 | –SD | C] – C:\Documents and Settings\fme\My Documents\My Data Sources
[2010/08/16 06:48:49 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/08/16 06:48:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2010/08/16 06:48:15 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/08/16 06:47:27 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/08/16 06:47:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/08/15 23:00:48 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Application Data\Google
[2010/07/18 20:19:38 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Desktop\Flash Drive Backup
[2010/07/17 13:03:50 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\DSL
[2010/07/17 12:28:02 | 000,000,000 | -H-D | C] – C:\Program Files\InstallJammer Registry
[2010/07/17 12:27:59 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Thinstation-2.2.2
[2010/07/14 22:02:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2010/07/05 22:06:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\My Documents\Desktop Budget
[2010/07/05 22:06:46 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Desktop Budget
[2010/06/30 19:59:23 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/06/30 19:57:40 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/06/30 19:57:27 | 000,000,000 | —D | C] – C:\Documents and Settings\fme\Local Settings\Application Data\Google
[2010/06/30 19:48:43 | 000,000,000 | —D | C] – C:\Program Files\Google
[2010/06/30 19:48:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2010/06/23 19:46:52 | 000,000,000 | —D | C] – C:\Program Files\ABC Amber Photoshop Converter

========== Files - Modified Within 90 Days ==========

[2010/09/14 23:02:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/14 16:27:22 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/14 16:22:56 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/09/14 16:22:04 | 000,001,893 | —- | M] () – C:\Documents and Settings\fme\Start Menu\Programs\Startup\VZAccess Manager.lnk
[2010/09/14 16:21:58 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/14 16:21:58 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/09/14 16:21:52 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/14 16:21:40 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/14 16:21:30 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/14 16:05:22 | 008,126,464 | -H– | M] () – C:\Documents and Settings\fme\NTUSER.DAT
[2010/09/14 16:05:22 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\fme\ntuser.ini
[2010/09/14 16:05:16 | 005,892,482 | -H– | M] () – C:\Documents and Settings\fme\Local Settings\Application Data\IconCache.db
[2010/09/13 06:47:21 | 000,025,088 | —- | M] () – C:\Documents and Settings\fme\My Documents\Tracy Thurman.doc
[2010/09/12 20:22:43 | 000,153,600 | —- | M] () – C:\Documents and Settings\fme\My Documents\Fire & Police taxes.ppt
[2010/09/12 15:09:54 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\fme\Desktop\OTL.exe
[2010/09/11 21:53:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/09 00:27:44 | 000,024,576 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Voter Letter v1.doc
[2010/09/08 22:25:54 | 000,154,112 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub
[2010/09/08 22:23:03 | 000,154,112 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16d.pub
[2010/09/08 22:22:08 | 000,126,796 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub.pdf
[2010/09/07 23:53:03 | 000,047,616 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv2.pub
[2010/09/07 23:44:44 | 000,443,904 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv1.pub
[2010/09/07 23:41:12 | 000,252,902 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub.pdf
[2010/09/07 23:39:25 | 000,443,904 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub
[2010/09/04 09:57:18 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Daily Star Election Issues v5.doc
[2010/09/04 09:54:03 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v4.doc
[2010/09/04 00:24:12 | 000,028,160 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v3.doc
[2010/09/03 23:09:09 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v2.doc
[2010/09/03 15:37:32 | 000,154,624 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16b.pub
[2010/09/03 02:19:12 | 000,148,480 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16a.pub
[2010/09/03 01:47:05 | 000,131,584 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16.pub
[2010/09/03 01:06:42 | 000,077,760 | —- | M] () – C:\Documents and Settings\fme\Desktop\Edwards.jpg
[2010/09/02 13:14:31 | 000,135,168 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v15.pub
[2010/09/02 13:11:22 | 000,134,656 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v14.pub
[2010/09/02 11:51:40 | 000,135,168 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v12.pub
[2010/09/02 11:25:36 | 000,134,144 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v10.pub
[2010/09/02 10:43:59 | 000,132,608 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v9.pub
[2010/09/02 08:29:50 | 000,000,698 | —- | M] () – C:\Documents and Settings\fme\Desktop\Bullzip PDF Printer.lnk
[2010/09/01 23:31:46 | 000,453,632 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v8.pub
[2010/09/01 22:53:04 | 000,453,632 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v7.pub
[2010/09/01 22:14:03 | 000,450,048 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v6.pub
[2010/09/01 17:39:31 | 001,007,616 | —- | M] () – C:\Documents and Settings\fme\My Documents\IndyVotersJul2010.mdb
[2010/08/29 21:49:08 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/26 02:01:50 | 000,450,048 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.pub
[2010/08/26 01:39:00 | 000,155,319 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.jpg
[2010/08/26 01:38:04 | 000,450,560 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v4.pub
[2010/08/26 00:58:45 | 000,447,488 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v3.pub
[2010/08/25 23:30:10 | 000,446,464 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v2.pub
[2010/08/25 22:40:40 | 000,446,464 | —- | M] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v1.pub
[2010/08/24 21:49:58 | 000,394,997 | —- | M] () – C:\Documents and Settings\fme\Desktop\Edwards - Chief Aug 2010.jpg
[2010/08/23 10:16:07 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/08/22 22:14:42 | 000,000,610 | —- | M] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/22 22:14:42 | 000,000,592 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/08/22 17:22:36 | 000,000,024 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/22 15:42:54 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/16 06:48:14 | 000,000,885 | —- | M] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/16 06:48:14 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/15 12:21:37 | 000,243,128 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/15 11:55:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/15 11:52:32 | 000,000,603 | —- | M] () – C:\WINDOWS\win.ini
[2010/08/15 11:49:28 | 000,540,530 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/15 11:49:28 | 000,472,704 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/15 11:49:28 | 000,077,870 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/14 00:30:01 | 000,000,820 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/08/12 16:16:07 | 000,028,672 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 1.doc
[2010/08/12 16:13:00 | 000,028,160 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 2.doc
[2010/08/12 16:01:28 | 000,027,136 | —- | M] () – C:\Documents and Settings\fme\Desktop\Aucion report 3.doc
[2010/07/12 03:55:39 | 000,064,288 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/07/12 03:55:38 | 000,015,880 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2010/06/23 19:47:32 | 000,000,765 | —- | M] () – C:\Documents and Settings\fme\Desktop\ABC Amber Photoshop Converter.lnk

========== Files Created - No Company Name ==========

[2010/09/12 21:17:03 | 000,012,142 | —- | C] () – C:\Documents and Settings\fme\hs_err_pid1352.log
[2010/09/12 10:44:41 | 000,153,600 | —- | C] () – C:\Documents and Settings\fme\My Documents\Fire & Police taxes.ppt
[2010/09/11 06:36:18 | 000,025,088 | —- | C] () – C:\Documents and Settings\fme\My Documents\Tracy Thurman.doc
[2010/09/09 00:15:27 | 000,024,576 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Voter Letter v1.doc
[2010/09/08 22:25:54 | 000,154,112 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub
[2010/09/08 22:22:07 | 000,126,796 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v17a.pub.pdf
[2010/09/07 23:45:07 | 000,047,616 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv2.pub
[2010/09/07 23:44:44 | 000,443,904 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cardsv1.pub
[2010/09/07 23:41:11 | 000,252,902 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub.pdf
[2010/09/07 23:34:52 | 000,443,904 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME blank cards.pub
[2010/09/04 09:57:18 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Daily Star Election Issues v5.doc
[2010/09/04 00:24:21 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v4.doc
[2010/09/03 23:09:31 | 000,028,160 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v3.doc
[2010/09/03 20:24:34 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\My Documents\Daily Star - Election Issues v2.doc
[2010/09/03 15:39:28 | 000,154,112 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16d.pub
[2010/09/03 02:34:28 | 000,154,624 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16b.pub
[2010/09/03 01:47:41 | 000,148,480 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16a.pub
[2010/09/03 01:06:41 | 000,077,760 | —- | C] () – C:\Documents and Settings\fme\Desktop\Edwards.jpg
[2010/09/02 23:41:52 | 000,131,584 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v16.pub
[2010/09/02 13:14:31 | 000,135,168 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v15.pub
[2010/09/02 11:55:17 | 000,134,656 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v14.pub
[2010/09/02 11:27:23 | 000,135,168 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v12.pub
[2010/09/02 10:45:31 | 000,134,144 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v10.pub
[2010/09/02 08:29:50 | 000,000,698 | —- | C] () – C:\Documents and Settings\fme\Desktop\Bullzip PDF Printer.lnk
[2010/09/01 23:33:19 | 000,132,608 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v9.pub
[2010/09/01 22:56:21 | 000,453,632 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v8.pub
[2010/09/01 22:22:46 | 000,453,632 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v7.pub
[2010/08/29 21:49:08 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/08/29 21:47:59 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/29 19:11:16 | 000,000,236 | —- | C] () – C:\WINDOWS\tasks\OGALogon.job
[2010/08/26 02:02:05 | 000,450,048 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v6.pub
[2010/08/26 01:38:59 | 000,155,319 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.jpg
[2010/08/26 01:38:14 | 000,450,048 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v5.pub
[2010/08/26 00:58:56 | 000,450,560 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v4.pub
[2010/08/25 23:30:24 | 000,447,488 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v3.pub
[2010/08/25 22:44:33 | 000,446,464 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v2.pub
[2010/08/25 22:20:39 | 000,446,464 | —- | C] () – C:\Documents and Settings\fme\My Documents\FME Pushcard v1.pub
[2010/08/25 13:52:25 | 000,394,997 | —- | C] () – C:\Documents and Settings\fme\Desktop\Edwards - Chief Aug 2010.jpg
[2010/08/23 10:11:03 | 000,006,296 | —- | C] () – C:\Documents and Settings\fme\reset.log
[2010/08/22 22:14:42 | 000,000,610 | —- | C] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/22 22:14:42 | 000,000,592 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/08/22 15:42:54 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/16 08:45:31 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/08/16 06:49:53 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/08/16 06:48:14 | 000,000,885 | —- | C] () – C:\Documents and Settings\fme\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/16 06:48:14 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/14 11:08:52 | 001,007,616 | —- | C] () – C:\Documents and Settings\fme\My Documents\IndyVotersJul2010.mdb
[2010/08/14 00:35:53 | 000,000,408 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/08/12 15:44:17 | 000,027,136 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 3.doc
[2010/08/12 15:18:20 | 000,028,160 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 2.doc
[2010/08/12 14:31:25 | 000,028,672 | —- | C] () – C:\Documents and Settings\fme\Desktop\Aucion report 1.doc
[2010/06/30 19:57:35 | 000,000,880 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/30 19:57:34 | 000,000,876 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/23 19:47:32 | 000,000,765 | —- | C] () – C:\Documents and Settings\fme\Desktop\ABC Amber Photoshop Converter.lnk
[2010/05/31 18:26:46 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/29 12:08:25 | 000,000,126 | —- | C] () – C:\Documents and Settings\fme\Local Settings\Application Data\fusioncache.dat
[2009/12/28 11:38:15 | 000,073,414 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2009/12/27 23:24:51 | 000,076,407 | —- | C] () – C:\Documents and Settings\fme\Application Data\Smiley.ico
[2009/10/26 02:01:52 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2009/10/26 01:51:33 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2009/10/26 01:46:37 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2009/10/26 01:09:30 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2009/10/26 01:09:30 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2009/10/26 01:09:30 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/12/29 11:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CodeGear
[2009/12/29 12:34:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Embarcadero
[2009/12/29 12:43:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7A0BDD12-2C4E-4120-BFFF-7B14DA13BE27}
[2010/08/16 06:48:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2009/12/31 14:06:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~1
[2010/09/11 17:06:22 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\BatteryBar
[2010/09/02 08:26:59 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Bullzip
[2009/12/29 12:34:53 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\CodeGear
[2009/12/27 23:05:07 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Foxit
[2010/05/06 11:23:24 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Foxit Software
[2010/04/02 23:19:55 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\kompozer.net
[2010/08/22 22:14:46 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Opera
[2010/03/30 19:45:23 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Smith Micro
[2010/05/16 18:17:02 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\Thinstall
[2010/09/13 11:05:12 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\uTorrent
[2010/09/14 16:22:56 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/09/14 16:27:22 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/09/14 16:21:58 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========


< End of report >
Hi fmedwards3

Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    :Files
    [2010/09/13 11:05:12 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\uTorrent
    O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O3 - HKCU\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
     [2010/09/13 11:05:12 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\uTorrent
    
    :Commands
    [purity]
    [emptytemp]
    [resethosts]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :file
    C:\Documents and Settings\fme\hs_err_pid1352.log
    
    :contents
    C:\Documents and Settings\fme\hs_err_pid1352.log
    
    :dir
    C:\Documents and Settings\All Users\Application Data

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Logs to include in next post

Fix.txt
OTL.txt
SystemLook.txt


Thanks

Satchfan
I did not find a new OTL log. The other two files are below. THANKS!!!!

All processes killed
========== OTL ==========
========== FILES ==========
Invalid Switch: 13 11:05:12 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\uTorrent
File\Folder O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com) not found.
File\Folder O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com) not found.
File\Folder O3 - HKCU\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com) not found.
Invalid Switch: 13 11:05:12 | 000,000,000 | —D | M] – C:\Documents and Settings\fme\Application Data\uTorrent
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: fme
->Temp folder emptied: 1258102 bytes
->Temporary Internet Files folder emptied: 225236 bytes
->Java cache emptied: 33653 bytes
->FireFox cache emptied: 90924118 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 1369 bytes

User: fmeadmin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: fmeadmin2

User: fme_2
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 12524 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 13217 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 2513 bytes

Total Files Cleaned = 88.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.12.0 log created on 09162010_221610

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…


********************************************************************************
*******************

SystemLook 04.09.10 by jpshortstuff
Log created at 22:32 on 16/09/2010 by fme
Administrator - Elevation successful

========== file ==========

C:\Documents and Settings\fme\hs_err_pid1352.log - File found and opened.
MD5: D24F4DCAE3D030C837CA1E67492777CC
Created at 02:17 on 13/09/2010
Modified at 02:17 on 13/09/2010
Size: 12142 bytes
Attributes: –a—-
No version information available.

========== contents ==========

C:\Documents and Settings\fme\hs_err_pid1352.log - Opened succesfully.

#
# An unexpected error has been detected by Java Runtime Environment:
#
# EXCEPTION_ACCESS_VIOLATION (0xc0000005) at pc=0x255a255a, pid=1352, tid=612
#
# Java VM: Java HotSpot™ Client VM (11.3-b02 mixed mode windows-x86)
# Problematic frame:
# C 0x255a255a
#
# If you would like to submit a bug report, please visit:
# http://java.sun.com/webapps/bugreport/crash.jsp
# The crash happened outside the Java Virtual Machine in native code.
# See problematic frame for where to report the bug.
#

————— T H R E A D —————

Current thread (0x0ab24400): JavaThread "thread applet-dev.s.AdgredY-2" [_thread_in_native, id=612, stack(0x0b7f0000,0x0b840000)]

siginfo: ExceptionCode=0xc0000005, reading address 0x255a255a

Registers:
EAX=0x00000000, EBX=0x0731e0b0, ECX=0x0b159e68, EDX=0x00000000
ESP=0x0b83f8bc, EBP=0x255a255a, ESI=0x0731e0b0, EDI=0x0ab24400
EIP=0x255a255a, EFLAGS=0x00210246

Top of Stack: (sp=0x0b83f8bc)
0x0b83f8bc: 0b83f8c8 0b83f8f4 00912da1 0b83f8c8
0x0b83f8cc: 00000000 0b83f8fc 0731e778 00000000
0x0b83f8dc: 0731e0b0 00000000 0b83f8f8 0b83f924
0x0b83f8ec: 00912e83 00000000 00918179 02b90e98
0x0b83f8fc: 02c54dc0 02c54dc0 0b83f904 0731e00f
0x0b83f90c: 0b83f934 0731e778 00000000 0731e030
0x0b83f91c: 0b83f8f8 0b83f930 0b83f958 00912da1
0x0b83f92c: 02c21930 02b90e98 02c54dc0 0b83f938

Instructions: (pc=0x255a255a)
0x255a254a:
[error occurred during error reporting (printing registers, top of stack, instructions near pc), id 0xc0000005]

Stack: [0x0b7f0000,0x0b840000], sp=0x0b83f8bc, free space=318k
Native frames: (J=compiled Java code, j=interpreted, Vv=VM code, C=native code)
C 0x255a255a

Java frames: (J=compiled Java code, j=interpreted, Vv=VM code)
j com.sun.media.sound.HeadspaceSoundbank.nOpenResource(Ljava/lang/String;)J+0
j com.sun.media.sound.HeadspaceSoundbank.initialize(Ljava/lang/String;)V+7
j com.sun.media.sound.HeadspaceSoundbank.(Ljava/net/URL;)V+89
j com.sun.media.sound.HsbParser.getSoundbank(Ljava/net/URL;)Ljavax/sound/midi/Soundbank;+5
j javax.sound.midi.MidiSystem.getSoundbank(Ljava/net/URL;)Ljavax/sound/midi/Soundbank;+36
j dev.s.AdgredY.variant1()V+359
j dev.s.AdgredY.init()V+1
j sun.plugin2.applet.Plugin2Manager$AppletExecutionRunnable.run()V+837
j java.lang.Thread.run()V+11
v ~StubRoutines::call_stub

————— P R O C E S S —————

Java Threads: ( => current thread )
0x0b06ec00 JavaThread "Headspace mixer frame proc thread" daemon [_thread_blocked, id=3932, stack(0x0c080000,0x0c0d0000)]
0x0aaf6400 JavaThread "Java Sound Event Dispatcher" daemon [_thread_blocked, id=2700, stack(0x0c030000,0x0c080000)]
0x0ab1e800 JavaThread "Java Sound Event Dispatcher" daemon [_thread_blocked, id=1528, stack(0x0bfe0000,0x0c030000)]
0x0aadc800 JavaThread "Thread-13" [_thread_in_native, id=1132, stack(0x0bf90000,0x0bfe0000)]
0x0b0ba400 JavaThread "Thread-12" [_thread_blocked, id=3912, stack(0x0bd40000,0x0bd90000)]
=>0x0ab24400 JavaThread "thread applet-dev.s.AdgredY-2" [_thread_in_native, id=612, stack(0x0b7f0000,0x0b840000)]
0x0af70400 JavaThread "AWT-EventQueue-3" [_thread_blocked, id=292, stack(0x0b890000,0x0b8e0000)]
0x0b0e7400 JavaThread "Applet 2 LiveConnect Worker Thread" [_thread_blocked, id=196, stack(0x0b840000,0x0b890000)]
0x0aa96c00 JavaThread "JMX server connection timeout 35" daemon [_thread_blocked, id=3904, stack(0x0b740000,0x0b790000)]
0x0b0d7000 JavaThread "AWT-EventQueue-1" [_thread_blocked, id=3012, stack(0x0b790000,0x0b7e0000)]
0x0b0d0c00 JavaThread "TimerQueue" daemon [_thread_blocked, id=3328, stack(0x0b6a0000,0x0b6f0000)]
0x0b001c00 JavaThread "thread applet-Applet.class-1" [_thread_blocked, id=3984, stack(0x0b440000,0x0b490000)]
0x0afec400 JavaThread "AWT-EventQueue-2" [_thread_blocked, id=3208, stack(0x0b650000,0x0b6a0000)]
0x0afeb400 JavaThread "Applet 1 LiveConnect Worker Thread" [_thread_blocked, id=1756, stack(0x0b600000,0x0b650000)]
0x0afde000 JavaThread "Browser Side Object Cleanup Thread" [_thread_blocked, id=300, stack(0x0b4e0000,0x0b530000)]
0x0afda400 JavaThread "CacheCleanUpThread" daemon [_thread_blocked, id=2848, stack(0x0b580000,0x0b5d0000)]
0x0afce400 JavaThread "CacheMemoryCleanUpThread" daemon [_thread_blocked, id=3604, stack(0x0b200000,0x0b250000)]
0x0afc1400 JavaThread "AWT-EventQueue-0" [_thread_blocked, id=4064, stack(0x0b530000,0x0b580000)]
0x0afb9c00 JavaThread "Java Plug-In Heartbeat Thread" [_thread_blocked, id=644, stack(0x0b490000,0x0b4e0000)]
0x0afb7000 JavaThread "AWT-Windows" daemon [_thread_in_native, id=2024, stack(0x0b3a0000,0x0b3f0000)]
0x0afb5c00 JavaThread "AWT-Shutdown" [_thread_blocked, id=3700, stack(0x0b350000,0x0b3a0000)]
0x0afae400 JavaThread "Java2D Disposer" daemon [_thread_blocked, id=1892, stack(0x0b300000,0x0b350000)]
0x0af9a800 JavaThread "Java Plug-In Pipe Worker Thread (Client-Side)" daemon [_thread_in_native, id=3088, stack(0x0b250000,0x0b2a0000)]
0x0ab2fc00 JavaThread "traceMsgQueueThread" daemon [_thread_blocked, id=2788, stack(0x0b1b0000,0x0b200000)]
0x0ab01000 JavaThread "Timer-0" [_thread_blocked, id=2260, stack(0x0b160000,0x0b1b0000)]
0x0aac5400 JavaThread "Low Memory Detector" daemon [_thread_blocked, id=3112, stack(0x0ad10000,0x0ad60000)]
0x0aabf000 JavaThread "CompilerThread0" daemon [_thread_blocked, id=312, stack(0x0acc0000,0x0ad10000)]
0x0aabd800 JavaThread "Attach Listener" daemon [_thread_blocked, id=184, stack(0x0ac70000,0x0acc0000)]
0x0aabc400 JavaThread "Signal Dispatcher" daemon [_thread_blocked, id=2320, stack(0x0ac20000,0x0ac70000)]
0x0aaac800 JavaThread "Finalizer" daemon [_thread_blocked, id=2312, stack(0x0abd0000,0x0ac20000)]
0x0aaa7c00 JavaThread "Reference Handler" daemon [_thread_blocked, id=1204, stack(0x0ab80000,0x0abd0000)]
0x002b7000 JavaThread "main" [_thread_blocked, id=2752, stack(0x008c0000,0x00910000)]

Other Threads:
0x0aaa3000 VMThread [stack: 0x0ab30000,0x0ab80000] [id=3092]
0x0aac6c00 WatcherThread [stack: 0x0ad60000,0x0adb0000] [id=1744]

VM state:not at safepoint (normal execution)

VM Mutex/Monitor currently owned by a thread: None

Heap
def new generation total 4544K, used 2837K [0x02990000, 0x02e70000, 0x02e70000)
eden space 4096K, 69% used [0x02990000, 0x02c55540, 0x02d90000)
from space 448K, 0% used [0x02d90000, 0x02d90120, 0x02e00000)
to space 448K, 0% used [0x02e00000, 0x02e00000, 0x02e70000)
tenured generation total 60544K, used 49843K [0x02e70000, 0x06990000, 0x06990000)
the space 60544K, 82% used [0x02e70000, 0x05f1cc18, 0x05f1ce00, 0x06990000)
compacting perm gen total 12288K, used 9808K [0x06990000, 0x07590000, 0x0a990000)
the space 12288K, 79% used [0x06990000, 0x07324168, 0x07324200, 0x07590000)
No shared spaces configured.

Dynamic libraries:
0x00400000 - 0x00424000 C:\Program Files\Java\jre6\bin\java.exe
0x7c900000 - 0x7c9b2000 C:\WINDOWS\system32\ntdll.dll
0x7c800000 - 0x7c8f6000 C:\WINDOWS\system32\kernel32.dll
0x77dd0000 - 0x77e6b000 C:\WINDOWS\system32\ADVAPI32.dll
0x77e70000 - 0x77f02000 C:\WINDOWS\system32\RPCRT4.dll
0x77fe0000 - 0x77ff1000 C:\WINDOWS\system32\Secur32.dll
0x7c340000 - 0x7c396000 C:\Program Files\Java\jre6\bin\msvcr71.dll
0x6d800000 - 0x6da56000 C:\Program Files\Java\jre6\bin\client\jvm.dll
0x7e410000 - 0x7e4a1000 C:\WINDOWS\system32\USER32.dll
0x77f10000 - 0x77f59000 C:\WINDOWS\system32\GDI32.dll
0x76b40000 - 0x76b6d000 C:\WINDOWS\system32\WINMM.dll
0x76390000 - 0x763ad000 C:\WINDOWS\system32\IMM32.DLL
0x6d290000 - 0x6d298000 C:\Program Files\Java\jre6\bin\hpi.dll
0x76bf0000 - 0x76bfb000 C:\WINDOWS\system32\PSAPI.DLL
0x6d7b0000 - 0x6d7bc000 C:\Program Files\Java\jre6\bin\verify.dll
0x6d330000 - 0x6d34f000 C:\Program Files\Java\jre6\bin\java.dll
0x6d7f0000 - 0x6d7ff000 C:\Program Files\Java\jre6\bin\zip.dll
0x6d430000 - 0x6d436000 C:\Program Files\Java\jre6\bin\jp2native.dll
0x6d1d0000 - 0x6d1e3000 C:\Program Files\Java\jre6\bin\deploy.dll
0x77a80000 - 0x77b15000 C:\WINDOWS\system32\CRYPT32.dll
0x77b20000 - 0x77b32000 C:\WINDOWS\system32\MSASN1.dll
0x77c10000 - 0x77c68000 C:\WINDOWS\system32\msvcrt.dll
0x7c9c0000 - 0x7d1d8000 C:\WINDOWS\system32\SHELL32.dll
0x77f60000 - 0x77fd6000 C:\WINDOWS\system32\SHLWAPI.dll
0x774e0000 - 0x7761e000 C:\WINDOWS\system32\ole32.dll
0x77120000 - 0x771ab000 C:\WINDOWS\system32\OLEAUT32.dll
0x3d930000 - 0x3da16000 C:\WINDOWS\system32\WININET.dll
0x0adb0000 - 0x0adb9000 C:\WINDOWS\system32\Normaliz.dll
0x78130000 - 0x78263000 C:\WINDOWS\system32\urlmon.dll
0x3dfd0000 - 0x3e1b8000 C:\WINDOWS\system32\iertutil.dll
0x773d0000 - 0x774d3000 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5705_x-ww_36cfed49\comctl32.dll
0x6d6b0000 - 0x6d6f2000 C:\Program Files\Java\jre6\bin\regutils.dll
0x77c00000 - 0x77c08000 C:\WINDOWS\system32\VERSION.dll
0x3fde0000 - 0x40220000 C:\WINDOWS\system32\msi.dll
0x6d610000 - 0x6d623000 C:\Program Files\Java\jre6\bin\net.dll
0x71ab0000 - 0x71ac7000 C:\WINDOWS\system32\WS2_32.dll
0x71aa0000 - 0x71aa8000 C:\WINDOWS\system32\WS2HELP.dll
0x6d630000 - 0x6d639000 C:\Program Files\Java\jre6\bin\nio.dll
0x6d000000 - 0x6d14a000 C:\Program Files\Java\jre6\bin\awt.dll
0x73000000 - 0x73026000 C:\WINDOWS\system32\WINSPOOL.DRV
0x5ad70000 - 0x5ada8000 C:\WINDOWS\system32\UxTheme.dll
0x74720000 - 0x7476c000 C:\WINDOWS\system32\MSCTF.dll
0x755c0000 - 0x755ee000 C:\WINDOWS\system32\msctfime.ime
0x6d230000 - 0x6d284000 C:\Program Files\Java\jre6\bin\fontmanager.dll
0x71a50000 - 0x71a8f000 C:\WINDOWS\System32\mswsock.dll
0x76f20000 - 0x76f47000 C:\WINDOWS\system32\DNSAPI.dll
0x76fb0000 - 0x76fb8000 C:\WINDOWS\System32\winrnr.dll
0x76f60000 - 0x76f8c000 C:\WINDOWS\system32\WLDAP32.dll
0x76fc0000 - 0x76fc6000 C:\WINDOWS\system32\rasadhlp.dll
0x662b0000 - 0x66308000 C:\WINDOWS\system32\hnetcfg.dll
0x71a90000 - 0x71a98000 C:\WINDOWS\System32\wshtcpip.dll
0x68000000 - 0x68036000 C:\WINDOWS\system32\rsaenh.dll
0x769c0000 - 0x76a74000 C:\WINDOWS\system32\USERENV.dll
0x5b860000 - 0x5b8b6000 C:\WINDOWS\system32\netapi32.dll
0x6d700000 - 0x6d706000 C:\Program Files\Java\jre6\bin\rmi.dll
0x6d520000 - 0x6d544000 C:\Program Files\Java\jre6\bin\jsound.dll
0x6d550000 - 0x6d558000 C:\Program Files\Java\jre6\bin\jsoundds.dll
0x73f10000 - 0x73f6c000 C:\WINDOWS\system32\DSOUND.dll
0x76c30000 - 0x76c5e000 C:\WINDOWS\system32\WINTRUST.dll
0x76c90000 - 0x76cb8000 C:\WINDOWS\system32\IMAGEHLP.dll
0x72d20000 - 0x72d29000 C:\WINDOWS\system32\wdmaud.drv
0x72d10000 - 0x72d18000 C:\WINDOWS\system32\msacm32.drv
0x77be0000 - 0x77bf5000 C:\WINDOWS\system32\MSACM32.dll
0x77bd0000 - 0x77bd7000 C:\WINDOWS\system32\midimap.dll

VM Arguments:
jvm_args: -D__jvm_launched=41143267730 -Xbootclasspath/a:C:\PROGRA~1\Java\jre6\lib\deploy.jar;C:\PROGRA~1\Java\jre6\lib\javaws.jar;C:\PROGRA~1\Java\jre6\lib\plugin.jar
java_command: sun.plugin2.main.client.PluginMain write_pipe_name=jpi2_pid2244_pipe2,read_pipe_name=jpi2_pid2244_pipe1
Launcher Type: SUN_STANDARD

Environment Variables:
PATH=C:\Program Files\Mozilla Firefox;C:\Program Files\Microsoft Office\OFFICE11\;C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\;C:\Program Files\Borland\BDS\4.0\Bin;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\jZip;C:\Program Files\QuickTime\QTSystem\;C:\Documents and Settings\fme\My Documents\Borland Studio Projects\Bpl
USERNAME=fme
OS=Windows_NT
PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 6, GenuineIntel



————— S Y S T E M —————

OS: Windows XP Build 2600 Service Pack 3

CPU:total 1 (1 cores per cpu, 1 threads per core) family 6 model 13 stepping 6, cmov, cx8, fxsr, mmx, sse, sse2

Memory: 4k page, physical 1308888k(429620k free), swap 1553460k(792224k free)

vm_info: Java HotSpot™ Client VM (11.3-b02) for windows-x86 JRE (1.6.0_13-b03), built on Mar 9 2009 01:15:24 by "java_re" with MS VC++ 7.1

time: Sun Sep 12 21:17:03 2010
elapsed time: 12 seconds



========== dir ==========

C:\Documents and Settings\All Users\Application Data - Parameters: "(none)"

—Files—
desktop.ini –ahs– 62 bytes [00:30 25/10/2009] [00:30 25/10/2009]
QSLLPSVCShare –ah-c- 4 bytes [07:01 26/10/2009] [07:01 26/10/2009]

—Folders—
Apple d—— [02:47 30/08/2010]
Apple Computer d—— [02:48 30/08/2010]
CodeGear d—— [16:36 29/12/2009]
Embarcadero d—— [16:33 29/12/2009]
Google d—— [00:48 01/07/2010]
Lavasoft d—— [11:47 16/08/2010]
Malwarebytes d—— [20:42 22/08/2010]
Microsoft d—s– [00:30 25/10/2009]
Microsoft Help d—— [17:44 29/12/2009]
Office Genuine Advantage d—— [22:09 01/09/2010]
Sun d—— [16:21 13/09/2010]
SUPERAntiSpyware.com d—— [03:58 31/12/2009]
Windows Genuine Advantage d—— [15:47 26/10/2009]
{7A0BDD12-2C4E-4120-BFFF-7B14DA13BE27} d–h-c- [17:43 29/12/2009]
{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E} d–h-c- [11:48 16/08/2010]
~1 d–h-c- [17:09 29/12/2009]

-= EOF =-
fmedwards3

Download ComboFix from the following location:

Link


* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.


When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Thanks

Satchfan
ComboFix 10-09-17.04 - fme 09/17/2010 21:36:54.1.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2010-08-18 to 2010-09-18 )))))))))))))))))))))))))))))))
.

2010-09-13 16:21 . 2010-09-13 16:21 503808 —-a-w- c:\documents and settings\fme\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-2df0c9d9-n\msvcp71.dll
2010-09-13 16:21 . 2010-09-13 16:21 499712 —-a-w- c:\documents and settings\fme\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-2df0c9d9-n\jmc.dll
2010-09-13 16:21 . 2010-09-13 16:21 348160 —-a-w- c:\documents and settings\fme\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-2df0c9d9-n\msvcr71.dll
2010-09-13 16:21 . 2010-09-13 16:21 ——– d—–w- c:\program files\Common Files\Java
2010-09-13 16:21 . 2010-09-13 16:21 61440 —-a-w- c:\documents and settings\fme\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1f9f226f-n\decora-sse.dll
2010-09-13 16:21 . 2010-09-13 16:21 12800 —-a-w- c:\documents and settings\fme\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1f9f226f-n\decora-d3d.dll
2010-09-13 16:20 . 2010-07-17 10:00 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-09-13 16:12 . 2010-09-13 16:12 ——– d—–w- C:\_OTL
2010-09-12 15:30 . 2010-07-25 02:24 344064 —-a-w- c:\documents and settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]\plugins\npCoralIETab.dll
2010-09-04 01:11 . 2010-09-11 22:06 ——– d—–w- c:\documents and settings\fme\Application Data\BatteryBar
2010-09-04 01:08 . 2010-09-04 01:11 ——– d—–w- c:\program files\BatteryBar
2010-09-02 13:29 . 2008-10-31 04:15 227840 —-a-w- c:\windows\system32\bzFlRdr.dll
2010-09-02 13:29 . 2008-09-27 01:44 126976 —-a-w- c:\windows\system32\bzpdfc.dll
2010-09-02 13:29 . 2008-07-10 05:19 103424 —-a-w- c:\windows\system32\bzDCT.dll
2010-09-02 13:29 . 2009-04-23 00:53 194560 —-a-w- c:\windows\system32\bzpdf.dll
2010-09-02 13:29 . 2010-09-02 13:29 ——– d—–w- c:\program files\Bullzip
2010-09-02 13:26 . 2010-09-02 13:26 ——– d—–w- c:\documents and settings\fme\Application Data\Bullzip
2010-09-01 22:09 . 2010-09-01 22:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-09-01 22:09 . 2010-09-01 22:09 ——– d—–w- c:\documents and settings\fme\Application Data\Office Genuine Advantage
2010-08-30 02:48 . 2010-08-30 02:49 ——– d—–w- c:\program files\QuickTime
2010-08-30 02:48 . 2010-08-30 02:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-08-30 02:48 . 2010-08-30 02:48 ——– d—–w- c:\program files\Common Files\Apple
2010-08-30 02:47 . 2010-08-30 02:47 ——– d—–w- c:\documents and settings\fme\Local Settings\Application Data\Apple
2010-08-30 02:47 . 2010-08-30 02:47 ——– d—–w- c:\program files\Apple Software Update
2010-08-30 02:47 . 2010-08-30 02:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-08-30 02:47 . 2010-08-30 02:47 ——– d—–w- c:\documents and settings\fme\Local Settings\Application Data\Apple Computer
2010-08-23 15:27 . 2010-08-23 15:24 55259024 —-a-w- c:\temp\mpam-fe.exe
2010-08-23 03:14 . 2010-08-23 03:14 ——– d—–w- c:\documents and settings\fme\Local Settings\Application Data\Opera
2010-08-23 03:14 . 2010-08-23 03:14 ——– d—–w- c:\program files\Opera
2010-08-23 00:17 . 2010-09-12 14:51 ——– d—–w- c:\program files\Emsisoft Anti-Malware
2010-08-22 20:42 . 2010-08-22 20:42 ——– d—–w- c:\documents and settings\fme\Application Data\Malwarebytes
2010-08-22 20:42 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-22 20:42 . 2010-08-22 20:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-22 20:42 . 2010-08-22 20:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-22 20:42 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-13 16:20 . 2009-10-26 06:21 ——– d—–w- c:\program files\Java
2010-09-13 16:05 . 2009-12-28 01:56 ——– d—–w- c:\documents and settings\fme\Application Data\uTorrent
2010-09-04 19:58 . 2009-10-26 06:08 ——– d—–w- c:\program files\Microsoft Silverlight
2010-08-25 01:23 . 2010-04-03 04:19 ——– d—–w- c:\program files\KompoZer
2010-08-23 15:10 . 2009-12-31 03:57 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-08-16 11:48 . 2010-08-16 11:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-08-16 11:48 . 2010-08-16 11:48 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
2010-08-16 11:47 . 2010-08-16 11:47 ——– d—–w- c:\program files\Lavasoft
2010-08-14 05:30 . 2009-12-28 01:43 ——– d—–w- c:\program files\Microsoft Security Essentials
2010-08-12 21:17 . 2010-05-16 22:37 ——– d—–w- c:\documents and settings\fme\Application Data\U3
2010-07-12 08:56 . 2010-08-16 11:48 2979280 -c–a-w- c:\documents and settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
2010-07-12 08:55 . 2010-08-16 11:48 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-07-12 08:55 . 2010-08-16 13:45 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-06-30 12:23 . 2008-12-05 09:58 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2009-03-08 06:34 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-24 02:14 . 2009-02-09 14:08 1861120 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 14:18 . 2008-12-11 15:33 354304 —-a-w- c:\windows\system32\drivers\srv.sys
.

——- Sigcheck ——-

[-] 2009-04-18 . 25A740D70E8007814A48D3FA1B34FA34 . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys

[-] 2009-10-26 . EF8B1281743A6B083B48711425E5AA6E . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 18:58 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-07-01 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1032192]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-06-01 1093208]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\documents and settings\fme\Start Menu\Programs\Startup\
VZAccess Manager.lnk - c:\program files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe [2010-3-30 1790056]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Ativa Wireless Utility.lnk - c:\program files\Ativa\Cardbus AWGNA54\Wireless Utility\Ativawcui.exe [2006-7-6 1556480]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R2 clr_optimization_v4.0.21006_32;Microsoft .NET Framework NGEN v4.0.21006_X86;c:\windows\Microsoft.NET\Framework\v4.0.21006\mscorsvw.exe [2009-10-07 129856]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-01 135664]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-04 13592]
R3 DigimHID;DigimHID;c:\windows\system32\DRIVERS\DigimHID.sys [2006-12-17 5248]
R3 PTDCWWAN;PANTECH PC Card WWAN Controller device driver;c:\windows\system32\DRIVERS\PTDCWWAN.sys [2007-05-01 58240]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-08-15 12872]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe [2009-10-07 752984]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-07-12 64288]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-08-15 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2010-08-15 67656]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-07-12 1352832]
S3 AWGNA54;Ativa Wireless G Notebook Card Service;c:\windows\system32\DRIVERS\AWGNA54.sys [2006-07-07 470528]
S3 wlanndi5;wlanndi5 NDIS Protocol Driver;c:\windows\system32\wlanndi5.SYS [2004-04-21 16384]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
DcomLaunch REG_MULTI_SZ DcomLaunch
.
Contents of the 'Scheduled Tasks' folder

2010-09-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-12 08:55]

2010-09-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-09-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-01 00:57]

2010-09-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-01 00:57]

2010-09-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2010-03-26 02:40]

2010-09-17 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\fme\Application Data\Mozilla\Firefox\Profiles\0hvdyws5.default\extensions\[removed]\plugins\npCoralIETab.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-17 21:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(492)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\igfxdev.dll

- - - - - - - > 'explorer.exe'(552)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-09-17 21:44:58
ComboFix-quarantined-files.txt 2010-09-18 02:44

Pre-Run: 4,316,176,384 bytes free
Post-Run: 4,392,062,976 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 0EABC6655D25456E254AE773492D59B1
Hello fmedwards3
Before we continue, the ability to change your control panel display mode has been disabled: can you tell me if you have done this deliberately.

Also, can you tell me how your computer is running, ie are there any changes and if so, what is the current situation.

Thanks

Satchfan
Still unable to update Microsoft Security Essentials, Malwarebyte's Anti-malware or Lavasoft Adaware, and still can't download Spybot Search and Destroy. Other than the above, computer seems to be running OK. I have no idea about the control panel display. Thanks for your perseverance!
Fmedwards3
Click on Start, Run and type in services.msc
Scroll down to “Windows Management Instrumentation”.
Under “Startup Type” it should say Automatic
If it doesn’t, right-click on it and choose Properties
Click on the downward-pointing arrow at the right of “Startup Type” and change it to Automatic

Uninstall Emisoft Antimalware

This has an AntiVirus component so shouldn’t be run with Microsoft Security Essentials.

To uninstall it:• Click on Start, Settings, Control Panel
• Double-click Add or Remove Programs (it may take time for the list to appear, so be patient)
• Scroll down the list and look for any of the above entries:
• If they are present, click on the program name and then on Remove.

Open ComboFix

Please do the following:
• Close any open browsers.
• Close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
• Open notepad and copy/paste the text in the codebox below into it:
SRPeek::
c:\windows\system32\sfcfiles.dll

Folder::
c:\program files\AskBarDis

Registry::
[-HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[-HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"=-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"=-
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"=-

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

Don’t bother trying to update Ad-Aware and Spybot as there are more improved programs available which I’ll tell you about when your computer is clean but please try updating Microsoft Security Essentials the following way:

• Open up Microsoft Security Essential user interface
• Go to the "Update" tab, and click on Update to check for updates
If that doesn’t work, tell me the error message you receive.

Thanks

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI