This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow system

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sony Vaio laptop several years old; original battery. Running slowly; locking up. Never able to download SP3 from Microsoft. Travel and use different wireless internet connections which could be a big issue. Deleted some files to free up space hoping to help. Not helping. Below is HiJack This list:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:13:30 AM, on 9/30/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\Iomega\AutoDisk\ActivityDisk.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\AOL\122037~1\EE\AOLHOS~1.EXE
C:\Program Files\MozyHome\mozystat.exe
C:\PROGRA~1\COMMON~1\AOL\122037~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\program files\aol toolbar\AolTbServer.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll
O4 - HKLM\..\Run: [REGSHAVE] "C:\Program Files\REGSHAVE\REGSHAVE.EXE" /AUTORUN
O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1220374803\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKCU\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1196962825921
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1196962813609
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate1c9e07b8033179c) (gupdate1c9e07b8033179c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Iomega Activity Disk - Iomega Corporation - C:\PROGRA~1\Iomega\AutoDisk\ActivityDisk.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: ZipToA - Unknown owner - C:\WINDOWS\system32\ZipToA.exe (file missing)
O24 - Desktop Component 0: (no name) - http://healthnews.uc.edu/images/global/external.gif
O24 - Desktop Component 1: (no name) - http://kidney.niddk.nih.gov/images/skip.gif

–
End of file - 12973 bytes
My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message to me on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________

Please download MBRCheck.exe to your Desktop. Run the application.

If no infection is found, it will produce a report on the desktop. Post that report in your next reply.

If an infection is found, you will be presented with the following dialog:

Enter 'Y' and hit ENTER for more options, or 'N' to exit:


Type N and press Enter. A report will be produced on the desktop. Post that report in your next reply.



NEXT:



Rootkit UnHooker (RkU)
Please download Rootkit Unhooker … Save it to your Desktop.
Note: The log can be very long, you may need to post it separately.
  • Double-click on RKUnhookerLE.exe to execute it.
    Vista - W7 users: Right click RKUnhookerLE.exe, choose "Run As Administrator" to execute it. If UAC prompts, please allow it.
  • Click the Report tab, then click Scan.
  • Check Drivers, Stealth Code, Files and Code Hooks. Uncheck the rest. then Click OK. (See image below…)
    🖼Click to load external image (Posted Image)
    The scanning will toggle through the checked items "tabs" … it will take a while, so please be patient.
  • When the scanner is finished… click File, Save Report.
  • Save the file "Report.txt" to your Desktop… Press Close… then press Yes
  • Copy the entire contents of the Report.txt file in you're next reply.

Please Note:
You may get this warning, it is ok, just ignore it:
"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"




NEXT:



OTL Custom Scan

Please download OTL to your Desktop, if you have not done so already.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
Hello SweetTech: Thank you for replying. I was not able to get past the second step involving RKUnhooker. The first step MBR went through with the following: Version: Windows XP Professional Windows Information: Service Pack 2 Logical Drives Mask: 0x0000007c 93GB\\.\Physical Drive 0 Windows XP MBR code detected SHA1: DA38B874B7713D1351CBC449F4EF809B0DEC644A Then said "done" and press Enter. When I tried to save RKUnhooker, I received the message box "cannot copy; access is denied" and the Trend Micro box appeared and said RKUnhooker LE(1).EXE PAK Generic 001 "untreatable virus has infected one of your files. Try deleting file or running scan again later to prevent spreading virus". So I "x-ed" out of it. I will await your instructions…thank you!
MBRCheck, version 1.2.3 SORRY…FORGOT TO COPY/PASTE HERE IT IS…. © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x0000007c Kernel Drivers (total 169): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806E3000 \WINDOWS\system32\hal.dll 0xF7A7E000 \WINDOWS\system32\KDCOM.DLL 0xF798E000 \WINDOWS\system32\BOOTVID.dll 0xF744F000 ACPI.sys 0xF7A80000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF743E000 pci.sys 0xF757E000 isapnp.sys 0xF758E000 ohci1394.sys 0xF759E000 \WINDOWS\system32\DRIVERS\1394BUS.SYS 0xF7992000 compbatt.sys 0xF7996000 \WINDOWS\system32\DRIVERS\BATTC.SYS 0xF7B46000 pciide.sys 0xF77FE000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7420000 pcmcia.sys 0xF75AE000 MountMgr.sys 0xF7401000 ftdisk.sys 0xF799A000 ACPIEC.sys 0xF7B47000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 0xF7806000 PartMgr.sys 0xF75BE000 VolSnap.sys 0xF73E9000 atapi.sys 0xF73D8000 SI3132.sys 0xF73C0000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS 0xF75CE000 disk.sys 0xF75DE000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF73A0000 fltMgr.sys 0xF738E000 sr.sys 0xF799E000 SiWinAcc.sys 0xF780E000 PxHelp20.sys 0xF7377000 KSecDD.sys 0xF72EA000 Ntfs.sys 0xF72BD000 NDIS.sys 0xF7A82000 SiRemFil.sys 0xF75EE000 sbp2port.sys 0xF72A2000 Mup.sys 0xF79A2000 iomdisk.sys 0xF7266000 \SystemRoot\system32\DRIVERS\tunmp.sys 0xF76AE000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF7262000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0xF691D000 \SystemRoot\system32\DRIVERS\ialmnt5.sys 0xF6909000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF68E3000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF6786000 \SystemRoot\system32\DRIVERS\w39n51.sys 0xF790E000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF6763000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF7916000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF672D000 \SystemRoot\system32\drivers\ti21sony.sys 0xF6705000 \SystemRoot\system32\DRIVERS\e100b325.sys 0xF791E000 \SystemRoot\System32\Drivers\SonyNC.sys 0xF76BE000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF7926000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF66EB000 \SystemRoot\system32\DRIVERS\Apfiltr.sys 0xF792E000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF76CE000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF76DE000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF76EE000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF66C8000 \SystemRoot\system32\DRIVERS\ks.sys 0xF7936000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys 0xF76FE000 \SystemRoot\System32\Drivers\tosrfcom.sys 0xF668E000 \SystemRoot\system32\DRIVERS\TdxVgaMini.sys 0xF6654000 \SystemRoot\system32\DRIVERS\TdxMrMini.sys 0xF7C59000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF770E000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF717B000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF663D000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF771E000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF772E000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF793E000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF662C000 \SystemRoot\system32\DRIVERS\psched.sys 0xF773E000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF7946000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF794E000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF7956000 \SystemRoot\system32\DRIVERS\wanatw4.sys 0xF65FB000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xF774E000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7AA6000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF65A2000 \SystemRoot\system32\DRIVERS\update.sys 0xF715F000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF653D000 \SystemRoot\system32\DRIVERS\NWADIenum.sys 0xF6385000 \SystemRoot\system32\DRIVERS\TM_CFW.sys 0xF775E000 \SystemRoot\system32\DRIVERS\tosporte.sys 0xF776E000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xAA624000 \SystemRoot\system32\drivers\sthda.sys 0xAA602000 \SystemRoot\system32\drivers\portcls.sys 0xF778E000 \SystemRoot\system32\drivers\drmk.sys 0xAA5D0000 \SystemRoot\system32\DRIVERS\HSFHWAZL.sys 0xAA4DC000 \SystemRoot\system32\DRIVERS\HSF_DPV.sys 0xAA42B000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys 0xF7966000 \SystemRoot\System32\Drivers\Modem.SYS 0xF77DE000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7AAE000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xAA418000 \SystemRoot\system32\DRIVERS\mozy.sys 0xF7AB0000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7CC5000 \SystemRoot\System32\Drivers\Null.SYS 0xF7AB2000 \SystemRoot\System32\Drivers\Beep.SYS 0xF7986000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF781E000 \SystemRoot\System32\drivers\vga.sys 0xF7AB4000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7AB6000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF7846000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF784E000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF7A6A000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xAA3E5000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xAA38D000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xAA33D000 \SystemRoot\system32\DRIVERS\netbt.sys 0xAA31C000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xAA2E4000 \SystemRoot\system32\DRIVERS\tcpip6.sys 0xAA2C2000 \SystemRoot\System32\drivers\afd.sys 0xF7856000 \SystemRoot\system32\DRIVERS\Ip6Fw.sys 0xF77EE000 \SystemRoot\system32\DRIVERS\netbios.sys 0xAA2AD000 \SystemRoot\system32\DRIVERS\tmtdi.sys 0xAA282000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xAA213000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF760E000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xF6AF8000 \SystemRoot\System32\Drivers\Fips.SYS 0xF7CD4000 \SystemRoot\system32\DRIVERS\DMICall.sys 0xAA0A8000 \SystemRoot\System32\Drivers\usbvm321.sys 0xF6AC8000 \SystemRoot\System32\Drivers\STREAM.SYS 0xF787E000 \SystemRoot\System32\Drivers\USBCAMD2.SYS 0xF7886000 \SystemRoot\system32\DRIVERS\SonyImgF.sys 0xF789E000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0xF6596000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF6AA8000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF6592000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xF658E000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xA9F72000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xA9F5A000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7B00000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF6365000 \SystemRoot\System32\drivers\Dxapi.sys 0xF78C6000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7B8C000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF020000 \SystemRoot\System32\ialmdnt5.dll 0xBF012000 \SystemRoot\System32\ialmrnt5.dll 0xBF042000 \SystemRoot\System32\ialmdev5.DLL 0xBF077000 \SystemRoot\System32\ialmdd5.DLL 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xAA1A3000 \SystemRoot\system32\DRIVERS\tmpreflt.sys 0xA9CD6000 \SystemRoot\system32\DRIVERS\vsapint.sys 0xA9C62000 \SystemRoot\system32\DRIVERS\tmxpflt.sys 0xF78EE000 \SystemRoot\system32\DRIVERS\AegisP.sys 0xA9BFC000 \SystemRoot\system32\DRIVERS\nwlnkipx.sys 0xF6A98000 \SystemRoot\system32\DRIVERS\nwlnknb.sys 0xA9F2E000 \SystemRoot\system32\DRIVERS\s24trans.sys 0xA9CBE000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA99F4000 \SystemRoot\system32\DRIVERS\nwrdr.sys 0xA99A0000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xA994B000 \??\C:\WINDOWS\system32\drivers\tmcomm.sys 0xF7AC4000 \SystemRoot\System32\Drivers\ASCTRM.SYS 0xA9752000 \SystemRoot\System32\Drivers\HTTP.sys 0xF7AC6000 \SystemRoot\System32\Drivers\MASPINT.SYS 0xA96AB000 \SystemRoot\system32\DRIVERS\srv.sys 0xA972E000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys 0xA95BB000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xA9543000 \SystemRoot\system32\DRIVERS\nwlnkspx.sys 0xA9196000 \SystemRoot\system32\drivers\wdmaud.sys 0xA9413000 \SystemRoot\system32\drivers\sysaudio.sys 0xA9423000 \??\C:\WINDOWS\system32\drivers\tmevtmgr.sys 0xA8568000 \??\C:\WINDOWS\system32\drivers\tmactmon.sys 0xA7C8F000 \SystemRoot\system32\DRIVERS\nwusbmdm.sys 0xA7C64000 \SystemRoot\system32\DRIVERS\nwusbser.sys 0xA7C39000 \SystemRoot\system32\DRIVERS\nwusbser2.sys 0xA9FCD000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0xF7876000 \??\C:\PROGRA~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS 0xA9722000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0xA7C0E000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 61): 0 System Idle Process 4 System 1488 C:\WINDOWS\system32\smss.exe 1540 csrss.exe 1564 C:\WINDOWS\system32\winlogon.exe 1608 C:\WINDOWS\system32\services.exe 1620 C:\WINDOWS\system32\lsass.exe 1828 C:\WINDOWS\system32\svchost.exe 1896 svchost.exe 1936 C:\WINDOWS\system32\svchost.exe 212 C:\Program Files\Intel\Wireless\Bin\EvtEng.exe 352 C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe 380 svchost.exe 596 svchost.exe 940 C:\WINDOWS\system32\spoolsv.exe 1012 svchost.exe 264 C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe 284 C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe 304 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 316 C:\Program Files\Bonjour\mDNSResponder.exe 408 aoltpspd.exe 440 C:\WINDOWS\ehome\ehrecvr.exe 460 C:\WINDOWS\ehome\ehSched.exe 680 C:\PROGRA~1\Iomega\AutoDisk\ActivityDisk.exe 700 C:\Program Files\Java\jre6\bin\jqs.exe 740 C:\Program Files\Google\Update\GoogleUpdate.exe 1048 C:\Program Files\MozyHome\mozybackup.exe 1104 C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe 2132 C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe 2184 C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe 2216 C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe 2240 svchost.exe 2316 C:\WINDOWS\system32\svchost.exe 2360 C:\Program Files\Sony\VAIO Event Service\VESMgr.exe 2444 C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe 2712 C:\WINDOWS\explorer.exe 2772 mcrdsvc.exe 2840 C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe 3064 C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe 3100 igfxext.exe 3236 igfxsrvc.exe 3460 C:\WINDOWS\system32\rundll32.exe 3476 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe 3484 C:\Program Files\Java\jre6\bin\jusched.exe 3508 C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe 3552 C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe 3560 C:\WINDOWS\system32\ctfmon.exe 3672 C:\Program Files\Common Files\AOL\1220374803\EE\AOLHostManager.exe 3676 C:\Program Files\MozyHome\mozystat.exe 3760 C:\PROGRA~1\COMMON~1\AOL\122037~1\EE\AOLServiceHost.exe 3996 wmiprvse.exe 2580 C:\WINDOWS\system32\wuauclt.exe 2608 alg.exe 1672 C:\Program Files\Trend Micro\Internet Security\TmProxy.exe 2292 C:\Program Files\Trend Micro\Internet Security\TmPfw.exe 2824 C:\WINDOWS\system32\svchost.exe 2572 C:\Program Files\Trend Micro\BM\TMBMSRV.exe 4356 C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe 2368 C:\Program Files\Internet Explorer\iexplore.exe 4460 C:\Program Files\AOL Toolbar\aoltbServer.exe 5532 C:\Documents and Settings\Thomas\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000001`c01a2400 (NTFS) PhysicalDrive0 Model Number: HTS541010G9SA00, Rev: MBZOC65D Size Device Name MBR Status ——————————————– 93 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done!
Followed instructions; downloaded without problems; began scan as directed; received message window WINDOWS - NO DISK Exception Processing Message c0000013 Parameters 75b6bf9c 75b6bf9c 75b6bf9c This occurred when scan was in SCANNING HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\MOUNTPOINTS2\{166da074-73e5-11df-9
Delete the current copy of OTL from your desktop, and download a fresh copy from the links previously provided. If it still gives you problems with running, then try running it in Safe Mode, and see if you have better luck there.

Entering Safe Mode

  • Restart your computer.
  • As the computer starts to boot-up, Tap the F8 KEY repeatedly,
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll to Safe Mode
  • Then press the Enter Key on your Keyboard
  • Go into your usual account
Afternoon Sweet Tech…I did not need safe mode. Turned off internet and ran OTL. Here are the two logs.
OTL logfile created on: 10/1/2010 3:24:18 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Thomas\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 427.00 Mb Available Physical Memory | 42.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1521 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.16 Gb Total Space | 26.69 Gb Free Space | 30.98% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOMSLAPTOP
Current User Name: Thomas
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Thomas\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
PRC - C:\Program Files\MozyHome\mozystat.exe (Mozy, Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\AOL\1220374803\EE\AOLHostManager.exe (America Online, Inc.)
PRC - C:\Program Files\Common Files\AOL\1220374803\EE\AOLServiceHost.exe (America Online, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLDial.exe (America Online)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe (America Online Inc)
PRC - C:\Program Files\Iomega\AutoDisk\ActivityDisk.exe (Iomega Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Thomas\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEHook.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\AOL\ACS\WLHook.dll (America Online)
MOD - C:\WINDOWS\system32\credui.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\rtutils.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (ZipToA) – C:\WINDOWS\System32\ZipToA.exe File not found
SRV - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (TmProxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (VzCdbSvc) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (VzFw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (Vcsw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (VAIO Event Service) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (SonicStageMonitoring) – C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (America Online)
SRV - (AOL TopSpeedMonitor) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (Iomega Activity Disk) – C:\Program Files\Iomega\AutoDisk\ActivityDisk.exe (Iomega Corporation)


========== Driver Services (SafeList) ==========

DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (tmactmon) – C:\WINDOWS\system32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmevtmgr) – C:\WINDOWS\system32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (Tcpip6) – C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (NWUSBCDFIL) – C:\WINDOWS\system32\drivers\NwUsbCdFil.sys (Novatel Wireless Inc.)
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\WINDOWS\system32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\WINDOWS\system32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\WINDOWS\system32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (SMSIVZAM5) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMSIVZAM5.sys (Smith Micro Inc.)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (SonyImgF) – C:\WINDOWS\system32\drivers\SonyImgF.sys (Sony Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (usbvm321) – C:\WINDOWS\system32\drivers\usbvm321.sys (Vimicro Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (Tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (ti21sony) – C:\WINDOWS\system32\drivers\ti21sony.sys (Texas Instruments)
DRV - (SI3132) – C:\WINDOWS\system32\DRIVERS\SI3132.sys (Silicon Image, Inc.)
DRV - (SiRemFil) – C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (cmudau) – C:\WINDOWS\system32\drivers\cmudaxu.sys (C-Media Inc)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (TdxVGAMINI) – C:\WINDOWS\system32\drivers\TdxVgaMini.sys (Generic Provider.)
DRV - (TdxMrMINI) – C:\WINDOWS\system32\drivers\TdxMrMini.sys (Generic Provider.)
DRV - (TdxVGAUSB) TARGUS USB2.0 VGA DOCK DEVICE(USB) – C:\WINDOWS\system32\drivers\TdxVGAUSB.sys (Generic Provider.)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (SiFilter) – C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (U2SP) OEM USB to Serial Converter Driver(Philips) – C:\WINDOWS\system32\drivers\U2S2KXP.sys (Magic Control Technology Corp.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (ADM851X) – C:\WINDOWS\system32\drivers\ADM851X.sys (ADMtek Incorporated)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (iomdisk) – C:\WINDOWS\System32\DRIVERS\iomdisk.sys (Iomega Corporation)
DRV - (DMICall) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (SNC) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)
DRV - (MASPINT) – C:\WINDOWS\System32\drivers\MASPINT.SYS (MicroStaff Co.,Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"


[2007/01/30 23:58:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\Mozilla\Firefox\Profiles\y02zykve.default\extensions
[2007/12/06 02:07:22 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2007/12/06 02:07:22 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2007/02/25 11:13:12 | 000,066,672 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jar50.dll
[2007/02/25 11:13:12 | 000,054,376 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jsd3250.dll
[2007/02/25 11:13:13 | 000,034,952 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\myspell.dll
[2007/02/25 11:13:14 | 000,046,720 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\spellchk.dll
[2007/02/25 11:13:14 | 000,172,144 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\xpinstal.dll

O1 HOSTS File: ([2008/03/31 09:39:17 | 000,000,741 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 192.168.2.2 HP0017A429A737
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AOL Toolbar Loader) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (IE Toolbar)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (IE Toolbar)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe (America Online)
O4 - HKLM..\Run: [CmUsbSound] File not found
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1220374803\EE\AOLHostManager.exe (America Online, Inc.)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe (Mozy, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &AOL; Toolbar search - C:\Program Files\AOL Toolbar\toolbar.dll (IE Toolbar)
O9 - Extra Button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (IE Toolbar)
O9 - Extra 'Tools' menuitem : AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (IE Toolbar)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: //@install.mar@ ([]msni in My Computer)
O15 - HKCU\..Trusted Domains: //@mail.mar@ ([]msni in Local intranet)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1196962825921 (WUWebControl Class)
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab (HpProductDetection Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1196962813609 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop Components:0 () - http://healthnews.uc.edu/images/global/external.gif
O24 - Desktop Components:1 () - http://kidney.niddk.nih.gov/images/skip.gif
O24 - Desktop Components:2 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Thomas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Thomas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/16 00:14:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{166da074-73e5-11df-993a-0013020cc322}\Shell - "" = AutoRun
O33 - MountPoints2\{166da074-73e5-11df-993a-0013020cc322}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{166da074-73e5-11df-993a-0013020cc322}\Shell\AutoRun\command - "" = F:\PhotoViewer.exe – File not found
O33 - MountPoints2\{7d82ba30-c25a-11df-9967-0013020cc322}\Shell - "" = AutoRun
O33 - MountPoints2\{7d82ba30-c25a-11df-9967-0013020cc322}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{7d82ba30-c25a-11df-9967-0013020cc322}\Shell\AutoRun\command - "" = F:\VZAccess_Manager.exe – File not found
O33 - MountPoints2\{7d82ba35-c25a-11df-9967-0013020cc322}\Shell - "" = AutoRun
O33 - MountPoints2\{7d82ba35-c25a-11df-9967-0013020cc322}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{7d82ba35-c25a-11df-9967-0013020cc322}\Shell\AutoRun\command - "" = G:\VZAccess_Manager.exe – File not found
O33 - MountPoints2\{b2b253c3-b155-11da-828e-0013020cc322}\Shell - "" = AutoRun
O33 - MountPoints2\{b2b253c3-b155-11da-828e-0013020cc322}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{b2b253c3-b155-11da-828e-0013020cc322}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (SsiEfr.e) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\System32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.dvsd - C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll (Sony Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183528496136192)

========== Files/Folders - Created Within 90 Days ==========

[2010/10/01 14:00:02 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Thomas\Desktop\OTL.exe
[2010/09/19 13:30:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Thomas\Application Data\Verizon Wireless
[2010/09/19 13:28:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WEngineLite
[2010/09/19 13:28:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Verizon Wireless
[2010/09/19 13:25:46 | 000,000,000 | —D | C] – C:\Program Files\Verizon Wireless
[2010/09/19 13:24:03 | 000,000,000 | —D | C] – C:\Program Files\Novatel Wireless
[2010/09/19 13:23:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Thomas\Local Settings\Application Data\Downloaded Installations
[2010/09/19 13:23:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Thomas\Application Data\InstallShield
[2010/09/07 09:04:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Temp
[2010/09/02 08:23:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Thomas\Application Data\Webroot
[2010/09/01 21:18:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Thomas\My Documents\CGMP INFO
[2010/07/28 11:28:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Thomas\My Documents\GENZYME Project
[2010/07/23 10:36:53 | 000,000,000 | —D | C] – C:\Program Files\MozyHome
[2010/07/21 12:17:20 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2010/07/21 10:51:20 | 000,736,768 | —- | C] (Корпорация Майкрософт) – C:\WINDOWS\System32\dllcache\sprb0419.dll
[2010/07/21 10:51:20 | 000,427,008 | —- | C] (Корпорация Майкрософт) – C:\WINDOWS\System32\dllcache\obrb0419.dll
[2010/07/21 10:51:20 | 000,192,512 | —- | C] (Корпорация Майкрософт) – C:\WINDOWS\System32\dllcache\spra0419.dll
[2010/07/21 10:50:40 | 000,281,088 | —- | C] (Cinematronics) – C:\WINDOWS\System32\dllcache\pinball.exe
[2010/07/10 09:37:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Thomas\My Documents\My Stuff - Terry
[2008/02/02 17:59:14 | 000,437,392 | —- | C] (Yahoo! Inc.) – C:\Program Files\msgr8us.exe
[56 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
[2123 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[17 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Thomas\My Documents\*.tmp files -> C:\Documents and Settings\Thomas\My Documents\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/10/01 15:22:16 | 000,000,437 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010/10/01 15:21:24 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/01 15:19:48 | 015,466,496 | —- | M] () – C:\Documents and Settings\Thomas\ntuser.dat
[2010/10/01 15:19:41 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/01 15:19:41 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\PCConfidential.job
[2010/10/01 15:19:35 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/10/01 15:19:30 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/01 15:19:25 | 000,278,152 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/01 15:18:23 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Thomas\ntuser.ini
[2010/10/01 14:44:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/01 14:00:02 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Thomas\Desktop\OTL.exe
[2010/10/01 09:22:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/30 16:52:28 | 000,139,264 | —- | M] () – C:\Documents and Settings\Thomas\My Documents\sterile drug substance.doc
[2010/09/30 16:51:28 | 000,002,483 | —- | M] () – C:\Documents and Settings\Thomas\Desktop\Microsoft Word.lnk
[2010/09/30 14:21:22 | 000,080,384 | —- | M] () – C:\Documents and Settings\Thomas\Desktop\MBRCheck.exe
[2010/09/30 11:05:02 | 000,002,809 | —- | M] () – C:\Documents and Settings\Thomas\Desktop\HiJackThis.lnk
[2010/09/30 10:10:30 | 001,402,880 | —- | M] () – C:\Documents and Settings\Thomas\Desktop\HiJackThis.msi
[2010/09/29 10:52:14 | 000,012,340 | —- | M] () – C:\WINDOWS\mozy.flt
[2010/09/29 10:52:14 | 000,004,528 | —- | M] () – C:\WINDOWS\mozy.blk
[2010/09/27 22:06:58 | 000,000,181 | —- | M] () – C:\WINDOWS\hpbafd.ini
[2010/09/26 15:18:02 | 000,106,941 | —- | M] () – C:\Documents and Settings\Thomas\My Documents\Seatingchart_Orch.gif
[2010/09/26 11:03:13 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/09/23 17:05:27 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/09/21 11:43:28 | 002,110,554 | -H– | M] () – C:\Documents and Settings\Thomas\Local Settings\Application Data\IconCache.db
[2010/09/19 13:31:45 | 000,579,838 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/19 13:31:45 | 000,479,496 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/19 13:31:45 | 000,089,890 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/09/19 13:28:38 | 000,001,013 | —- | M] () – C:\Documents and Settings\All Users\Desktop\VZAccess Manager.lnk
[2010/09/17 22:04:28 | 000,002,085 | —- | M] () – C:\WINDOWS\win.ini
[2010/09/08 14:45:21 | 000,076,840 | —- | M] () – C:\Documents and Settings\Thomas\Application Data\GDIPFONTCACHEV1.DAT
[2010/09/08 13:12:09 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MozyHome Status.lnk
[2010/08/31 09:56:34 | 000,039,936 | —- | M] () – C:\Documents and Settings\Thomas\Desktop\Olympus IPSEN Document Tracking Sheet.xls
[2010/08/28 17:30:51 | 000,023,040 | —- | M] () – C:\Documents and Settings\Thomas\My Documents\Letter to Pete Maravelias.doc
[2010/08/23 22:09:44 | 000,000,452 | —- | M] () – C:\WINDOWS\System\CMCNFGU.INI
[2010/08/23 12:50:18 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/13 15:26:51 | 000,000,792 | —- | M] () – C:\Documents and Settings\Thomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk
[2010/08/12 09:43:01 | 000,078,578 | —- | M] () – C:\VETlog.dmp
[2010/08/09 16:17:28 | 000,093,184 | —- | M] () – C:\Documents and Settings\Thomas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/07 15:37:44 | 000,020,480 | —- | M] () – C:\Documents and Settings\Thomas\My Documents\Protocol Execution Addendum VP.doc
[2010/08/01 09:34:04 | 000,029,696 | —- | M] () – C:\Documents and Settings\Thomas\My Documents\CHECKLIST FOR REPORTS.doc
[2010/07/31 08:57:33 | 000,149,504 | —- | M] () – C:\Documents and Settings\Thomas\My Documents\Copy of Calendar Wizard - 4-2011.doc
[2010/07/30 13:29:10 | 000,249,424 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmxpflt.sys
[2010/07/30 13:29:00 | 000,036,432 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmpreflt.sys
[2010/07/30 13:06:08 | 001,331,512 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\vsapint.sys
[2010/07/29 11:32:32 | 000,022,016 | —- | M] () – C:\Documents and Settings\Thomas\My Documents\Kimi.doc
[2010/07/23 10:08:56 | 000,023,552 | —- | M] () – C:\Documents and Settings\Thomas\My Documents\1930 Carmel Ridge Road Charlotte.doc
[2010/07/21 12:51:14 | 000,000,031 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2010/07/21 12:19:19 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2010/07/21 12:18:30 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2010/07/21 12:18:30 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2010/07/21 11:21:35 | 000,250,032 | —- | M] () – C:\ntldr
[2010/07/19 14:03:10 | 000,059,472 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmactmon.sys
[2010/07/19 14:03:00 | 000,051,792 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2010/07/19 14:02:54 | 000,163,408 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2010/07/15 10:17:21 | 000,027,136 | —- | M] () – C:\Documents and Settings\Thomas\My Documents\July 15.doc
[2010/07/14 22:06:20 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/07/10 09:45:39 | 000,001,791 | —- | M] () – C:\Documents and Settings\Thomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2123 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[17 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Thomas\My Documents\*.tmp files -> C:\Documents and Settings\Thomas\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/30 16:52:28 | 000,139,264 | —- | C] () – C:\Documents and Settings\Thomas\My Documents\sterile drug substance.doc
[2010/09/30 14:21:21 | 000,080,384 | —- | C] () – C:\Documents and Settings\Thomas\Desktop\MBRCheck.exe
[2010/09/30 11:05:02 | 000,002,809 | —- | C] () – C:\Documents and Settings\Thomas\Desktop\HiJackThis.lnk
[2010/09/30 10:10:29 | 001,402,880 | —- | C] () – C:\Documents and Settings\Thomas\Desktop\HiJackThis.msi
[2010/09/26 15:20:59 | 000,106,941 | —- | C] () – C:\Documents and Settings\Thomas\My Documents\Seatingchart_Orch.gif
[2010/09/19 13:28:38 | 000,001,013 | —- | C] () – C:\Documents and Settings\All Users\Desktop\VZAccess Manager.lnk
[2010/09/08 15:20:55 | 000,003,150 | —- | C] () – C:\Documents and Settings\All Users\Application Data\OutlookFail.20100908.log
[2010/08/28 17:19:43 | 000,023,040 | —- | C] () – C:\Documents and Settings\Thomas\My Documents\Letter to Pete Maravelias.doc
[2010/08/13 15:26:56 | 000,000,175 | —- | C] () – C:\Documents and Settings\All Users\Application Data\OutlookFail.20100813.log
[2010/08/07 15:37:43 | 000,020,480 | —- | C] () – C:\Documents and Settings\Thomas\My Documents\Protocol Execution Addendum VP.doc
[2010/08/01 09:18:39 | 000,029,696 | —- | C] () – C:\Documents and Settings\Thomas\My Documents\CHECKLIST FOR REPORTS.doc
[2010/07/31 08:47:55 | 000,149,504 | —- | C] () – C:\Documents and Settings\Thomas\My Documents\Copy of Calendar Wizard - 4-2011.doc
[2010/07/29 11:32:32 | 000,022,016 | —- | C] () – C:\Documents and Settings\Thomas\My Documents\Kimi.doc
[2010/07/23 10:37:11 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MozyHome Status.lnk
[2010/07/23 10:01:55 | 000,023,552 | —- | C] () – C:\Documents and Settings\Thomas\My Documents\1930 Carmel Ridge Road Charlotte.doc
[2010/07/22 09:48:26 | 000,012,340 | —- | C] () – C:\WINDOWS\mozy.flt
[2010/07/22 09:48:26 | 000,004,528 | —- | C] () – C:\WINDOWS\mozy.blk
[2010/07/21 10:51:10 | 000,759,966 | —- | C] () – C:\WINDOWS\System32\dllcache\apph_sp.sdb
[2010/07/21 10:50:54 | 000,079,996 | —- | C] () – C:\WINDOWS\System32\dllcache\apps.chm
[2010/07/21 10:50:52 | 000,216,862 | —- | C] () – C:\WINDOWS\System32\dllcache\apphelp.sdb
[2010/07/21 10:50:49 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\dllcache\fpencode.dll
[2010/07/21 10:50:44 | 000,198,736 | —- | C] () – C:\WINDOWS\System32\dllcache\msimain.sdb
[2010/07/21 10:50:39 | 000,279,040 | —- | C] () – C:\WINDOWS\System32\dllcache\tshoot.dll
[2010/07/21 10:50:39 | 000,034,816 | —- | C] () – C:\WINDOWS\System32\dllcache\sniffpol.dll
[2010/07/21 10:50:39 | 000,033,280 | —- | C] () – C:\WINDOWS\System32\dllcache\sstub.dll
[2010/07/21 10:50:24 | 000,070,656 | —- | C] () – C:\WINDOWS\System32\dllcache\amstream.dll
[2010/07/21 10:50:02 | 000,035,328 | —- | C] () – C:\WINDOWS\System32\dllcache\mciqtz32.dll
[2010/07/21 10:49:46 | 000,004,310 | —- | C] () – C:\WINDOWS\System32\dllcache\odbcconf.rsp
[2010/07/21 10:49:43 | 000,733,696 | —- | C] () – C:\WINDOWS\System32\dllcache\qedwipes.dll
[2010/07/21 10:49:43 | 000,279,040 | —- | C] () – C:\WINDOWS\System32\dllcache\qdv.dll
[2010/07/21 10:49:43 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\dllcache\qcap.dll
[2010/07/21 10:49:42 | 001,291,776 | —- | C] () – C:\WINDOWS\System32\dllcache\quartz.dll
[2010/07/21 10:49:19 | 000,009,424 | —- | C] () – C:\WINDOWS\System32\dllcache\drvmain.sdb
[2010/07/15 10:12:12 | 000,027,136 | —- | C] () – C:\Documents and Settings\Thomas\My Documents\July 15.doc
[2009/12/20 10:41:55 | 000,000,036 | —- | C] () – C:\Documents and Settings\Thomas\Local Settings\Application Data\housecall.guid.cache
[2009/09/05 19:12:55 | 000,000,088 | —- | C] () – C:\WINDOWS\System32\pdfwritr.ini
[2009/09/05 17:17:39 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\custmon2k.dll
[2009/09/05 17:16:29 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\wh2robo.dll
[2009/09/05 17:16:29 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\KVSHash.dll
[2009/05/19 17:25:00 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2008/08/09 10:59:40 | 000,000,350 | —- | C] () – C:\Documents and Settings\All Users\Application Data\OutlookFail.20080809.log
[2008/07/21 21:21:10 | 000,000,058 | —- | C] () – C:\WINDOWS\ScrAntic.ini
[2008/05/31 13:57:55 | 005,154,304 | —- | C] () – C:\Program Files\WindowsDefender.msi
[2008/02/25 23:07:12 | 000,018,725 | —- | C] () – C:\Program Files\Readme.txt
[2008/01/26 20:41:46 | 001,597,936 | —- | C] () – C:\Program Files\lj1100pcl5ewin2kxp2003-en.exe
[2008/01/25 14:09:38 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2008/01/21 11:01:06 | 000,000,156 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2008/01/21 10:56:39 | 000,000,804 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2008/01/07 01:19:57 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2008/01/06 21:18:30 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/11/18 20:26:27 | 000,003,826 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/07/28 15:25:10 | 000,000,163 | —- | C] () – C:\WINDOWS\Viewer.ini
[2007/07/28 15:23:10 | 000,000,104 | —- | C] () – C:\WINDOWS\VDECK.INI
[2007/06/09 14:27:10 | 000,028,672 | —- | C] () – C:\WINDOWS\KVSHash.dll
[2007/04/06 23:18:20 | 000,021,791 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2007/04/06 23:18:20 | 000,001,037 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2007/04/06 23:17:28 | 000,038,576 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2007/04/06 23:17:28 | 000,010,225 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2007/04/06 23:17:27 | 000,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2007/03/24 11:49:29 | 000,299,454 | —- | C] () – C:\WINDOWS\ALLSIM.INI
[2007/03/24 11:49:29 | 000,061,268 | —- | C] () – C:\WINDOWS\BIUTILSM.INI
[2007/03/24 11:49:29 | 000,057,969 | —- | C] () – C:\WINDOWS\SIMSIM.INI
[2007/03/24 11:49:29 | 000,051,712 | —- | C] () – C:\WINDOWS\System32\ngprtserv.dll
[2007/03/24 11:49:29 | 000,000,580 | —- | C] () – C:\WINDOWS\Common.ini
[2007/03/24 11:49:28 | 000,000,645 | —- | C] () – C:\WINDOWS\Setupwizard.ini
[2007/03/05 14:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/01/16 14:29:19 | 000,001,024 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sowdp88.dat
[2007/01/16 14:29:05 | 000,000,048 | —- | C] () – C:\WINDOWS\System32\pdfutil.ini
[2007/01/16 14:29:02 | 002,169,344 | —- | C] () – C:\WINDOWS\System32\pdfutil.dll
[2007/01/11 12:56:53 | 000,000,000 | —- | C] () – C:\WINDOWS\pcfriend.INI
[2006/11/20 12:21:05 | 000,684,032 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2006/11/20 12:21:05 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2006/08/30 11:52:07 | 000,000,181 | —- | C] () – C:\WINDOWS\hpbafd.ini
[2006/08/21 09:23:37 | 000,000,000 | —- | C] () – C:\WINDOWS\EAREMOVE.INI
[2006/07/26 14:53:00 | 000,044,544 | —- | C] () – C:\WINDOWS\System32\gif89.dll
[2006/07/26 14:52:35 | 000,000,586 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2006/07/26 13:29:31 | 000,000,132 | —- | C] () – C:\WINDOWS\winamp.ini
[2006/07/25 13:01:01 | 000,000,137 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\fusioncache.dat
[2006/07/24 12:01:47 | 000,030,208 | —- | C] () – C:\WINDOWS\System32\WNASPI32.DLL
[2006/07/24 12:01:47 | 000,000,291 | —- | C] () – C:\WINDOWS\msfsetup.ini
[2006/07/24 09:56:18 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\CmDrvRmU.DLL
[2006/06/14 23:36:39 | 000,000,047 | —- | C] () – C:\WINDOWS\winhlp32.ini
[2006/06/14 23:36:39 | 000,000,047 | —- | C] () – C:\WINDOWS\winhelp.ini
[2006/06/14 23:35:10 | 000,017,552 | —- | C] () – C:\WINDOWS\System32\TTYTWIN.DRV
[2006/06/14 23:34:40 | 000,110,080 | —- | C] () – C:\WINDOWS\System32\NCSPI8EN.DLL
[2006/06/14 23:34:26 | 000,022,480 | —- | C] () – C:\WINDOWS\System32\PFMAPI16.DLL
[2006/06/14 23:34:26 | 000,020,992 | —- | C] () – C:\WINDOWS\System32\PFMAPI32.DLL
[2006/05/29 09:09:06 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\SfwIFmt.dll
[2006/05/29 09:09:06 | 000,000,719 | —- | C] () – C:\WINDOWS\PODW.INI
[2006/05/07 04:34:22 | 000,000,948 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/10 19:40:47 | 000,000,020 | —- | C] () – C:\WINDOWS\Hposcv07.INI
[2006/04/10 19:21:12 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2006/04/10 17:51:43 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS5y.DLL
[2006/04/10 13:50:08 | 000,002,156 | —- | C] () – C:\WINDOWS\FONTSMRT.INI
[2006/04/10 13:49:47 | 000,000,415 | —- | C] () – C:\WINDOWS\prntname.ini
[2006/04/10 11:32:12 | 000,000,076 | —- | C] () – C:\WINDOWS\tmprn.ini
[2006/04/01 11:25:08 | 000,093,184 | —- | C] () – C:\Documents and Settings\Thomas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/20 08:15:27 | 000,000,059 | —- | C] () – C:\WINDOWS\WinInit.ini.backup
[2006/03/17 12:34:21 | 000,000,794 | —- | C] () – C:\WINDOWS\lrun32.ini
[2006/03/17 12:32:11 | 000,000,000 | —- | C] () – C:\WINDOWS\AutoRun.INI
[2006/03/14 11:49:17 | 000,000,286 | —- | C] () – C:\Documents and Settings\Thomas\Application Data\wklnhst.dat
[2006/03/11 19:20:56 | 000,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2006/03/11 19:20:56 | 000,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2006/03/11 18:58:43 | 000,000,129 | —- | C] () – C:\Documents and Settings\Thomas\Local Settings\Application Data\fusioncache.dat
[2005/12/16 04:37:50 | 000,002,154 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2005/12/16 04:30:37 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2005/12/16 04:28:39 | 000,000,031 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2005/12/16 04:28:04 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/12/16 04:28:04 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/12/16 04:28:04 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/12/16 04:28:04 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/12/16 04:28:04 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/12/16 04:28:04 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/12/16 04:25:17 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/12/16 03:19:55 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/12/16 02:04:14 | 000,000,120 | —- | C] () – C:\WINDOWS\WinInit.ini
[2005/12/16 02:00:03 | 000,000,000 | —- | C] () – C:\WINDOWS\VAIOUpdt.INI
[2005/12/16 00:33:45 | 000,000,811 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/12/15 22:52:37 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2005/12/15 22:52:31 | 000,000,758 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/12/15 22:52:01 | 000,022,040 | —- | C] () – C:\WINDOWS\System32\_004246_.tmp.dll
[2005/12/15 22:51:53 | 000,249,270 | —- | C] () – C:\WINDOWS\System32\_004279_.tmp.dll
[2005/11/01 21:53:38 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/05 18:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/03/27 17:28:44 | 000,004,955 | —- | C] () – C:\WINDOWS\System32\DProg.ini
[2002/06/12 16:21:12 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\winchip.dll
[2001/07/07 04:00:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[2001/03/02 22:26:29 | 000,088,064 | —- | C] () – C:\WINDOWS\System32\AudioExCtl.dll

========== LOP Check ==========

[2010/01/17 14:32:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bondi
[2005/12/16 04:37:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2009/10/16 13:50:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2007/12/06 02:07:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Metacafe
[2009/09/05 19:32:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2006/07/26 18:32:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Retrospect
[2007/02/08 10:06:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/09/19 13:28:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEngineLite
[2009/06/06 14:04:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Winferno
[2007/11/27 12:22:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YourPrivacyGuard
[2010/01/17 14:20:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\Downloaded Installations
[2009/09/05 19:33:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\DriverCure
[2006/12/04 18:32:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\FUJIFILM
[2010/07/06 09:58:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\Image Zone Express
[2006/05/20 15:37:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\InterVideo
[2006/04/24 16:16:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\Leadertech
[2007/12/06 02:07:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\Metacafe
[2007/07/25 22:19:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\MSNInstaller
[2008/02/10 11:55:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\OfficeUpdate12
[2007/11/20 11:09:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\Printer Info Cache
[2008/02/05 17:12:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\Template
[2009/06/06 14:01:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\Titanium Gears
[2007/02/08 10:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\Viewpoint
[2007/11/27 12:27:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Thomas\Application Data\YourPrivacyGuard
[2010/10/01 15:19:41 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\PCConfidential.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/06/01 16:20:39 | 000,000,011 | —- | M] () – C:\AuResult.ini
[2005/12/16 00:14:29 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/04/12 12:53:18 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2005/12/16 00:14:29 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/03/11 14:57:11 | 000,000,164 | —- | M] () – C:\install.dat
[2005/12/16 00:14:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/03/31 09:39:10 | 000,013,425 | —- | M] () – C:\mombi.log
[2005/12/16 00:14:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/07/21 11:21:35 | 000,250,032 | —- | M] () – C:\ntldr
[2010/10/01 15:19:20 | 1594,884,096 | -HS- | M] () – C:\pagefile.sys
[2007/03/24 12:53:40 | 000,000,004 | —- | M] () – C:\ss_nb.dat
[2007/03/24 12:53:39 | 000,000,004 | —- | M] () – C:\ss_udp.dat
[2007/03/24 12:53:39 | 000,000,004 | —- | M] () – C:\ss_udp2.dat
[2010/08/12 09:43:01 | 000,078,578 | —- | M] () – C:\VETlog.dmp
[2010/08/12 09:43:01 | 001,909,197 | —- | M] () – C:\VETlog.txt
[2008/02/03 11:17:34 | 000,000,146 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[56 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/12/16 00:13:51 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
[56 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/04/23 01:00:00 | 000,017,920 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD5y.DLL
[2004/04/23 01:00:00 | 000,054,272 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP5y.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/07/03 12:54:12 | 000,091,648 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp4sa.dll
[2004/03/22 19:17:08 | 000,025,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/02/08 16:29:26 | 000,257,776 | —- | M] (MacSourcery) – C:\WINDOWS\Crizal Screensoother.scr
[1992/12/09 17:08:52 | 000,295,952 | —- | M] () – C:\WINDOWS\SCRANTIC.SCR
[17 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/07/19 09:51:32 | 000,001,746 | -H– | M] () – C:\Documents and Settings\Thomas\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2008/01/26 20:42:30 | 001,597,936 | —- | M] () – C:\Program Files\lj1100pcl5ewin2kxp2003-en.exe
[2008/02/02 17:59:15 | 000,437,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\msgr8us.exe
[2008/02/25 23:07:12 | 000,018,725 | —- | M] () – C:\Program Files\Readme.txt
[2008/05/31 13:58:08 | 005,154,304 | —- | M] () – C:\Program Files\WindowsDefender.msi

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/12/15 16:00:36 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/12/15 16:00:36 | 000,663,552 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/12/15 16:00:36 | 000,913,408 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/12/16 00:14:36 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2004/05/05 21:59:01 | 000,004,096 | —- | M] () – C:\WINDOWS\system32\Thumbs.db
[2123 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/08/06 21:41:09 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Thomas\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/07/21 20:20:53 | 000,000,079 | —- | M] () – C:\Documents and Settings\Thomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2003/05/04 11:54:54 | 000,561,152 | —- | M] (Joshua F. Madison) – C:\Documents and Settings\Thomas\Desktop\Convert.exe
[2008/07/15 15:00:57 | 000,401,720 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Thomas\Desktop\HiJackThis.exe
[2008/10/20 00:15:44 | 067,167,528 | —- | M] (Apple Inc.) – C:\Documents and Settings\Thomas\Desktop\iTunes801Setup.exe
[2010/09/30 14:21:22 | 000,080,384 | —- | M] () – C:\Documents and Settings\Thomas\Desktop\MBRCheck.exe
[2010/10/01 14:00:02 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Thomas\Desktop\OTL.exe
[2008/07/15 12:40:07 | 081,779,752 | —- | M] (Trend Micro Inc. ) – C:\Documents and Settings\Thomas\Desktop\TrendMicro_TIS_16.1_1063_x32.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >
[2009/04/12 10:17:43 | 074,622,480 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Thomas\My Documents\00606_Digital_River_TrendMicro_TIS_17_10.exe
[2003/05/04 10:54:54 | 000,561,152 | —- | M] (Joshua F. Madison) – C:\Documents and Settings\Thomas\My Documents\Convert.exe
[2007/01/11 13:30:08 | 002,955,412 | —- | M] (AAAPDF, Inc. ) – C:\Documents and Settings\Thomas\My Documents\pdfdecrypt_setup.exe
[1 C:\Documents and Settings\Thomas\My Documents\*.tmp files -> C:\Documents and Settings\Thomas\My Documents\*.tmp -> ]

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2006/06/14 23:36:07 | 000,000,568 | —- | M] () – C:\Documents and Settings\Thomas\Favorites\Corel Macros.LNK
[2008/08/06 21:41:09 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Thomas\Favorites\Desktop.ini
[2006/06/14 23:36:07 | 000,000,572 | —- | M] () – C:\Documents and Settings\Thomas\Favorites\Graphics.LNK
[2006/06/14 23:36:07 | 000,000,426 | —- | M] () – C:\Documents and Settings\Thomas\Favorites\Personal Files.LNK

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >
Crizal Screensoother.exe

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010/04/18 14:09:58 | 000,000,067 | -HS- | M] () – C:\Documents and Settings\Thomas\Cookies\desktop.ini
[2010/10/01 15:19:54 | 000,393,216 | —- | M] () – C:\Documents and Settings\Thomas\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >
[2004/08/10 08:00:00 | 000,192,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\inf\unregmp2.exe

< %SYSTEMROOT%\Installer\*.exe >
[2005/11/30 20:12:22 | 000,552,960 | —- | M] (Intel Corporation) – C:\WINDOWS\Installer\iProInst.exe
[2005/08/01 17:24:00 | 001,003,215 | —- | M] () – C:\WINDOWS\Installer\ms_office_trial.exe
[7 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]

< %systemroot%\system32\config\*.bak2 >

< %systemroot%\system32\Computers\*.* >

< %SystemRoot%\system32\Sound\*.* >

< %SystemRoot%\system32\SpecialImg\*.* >

< %SystemRoot%\system32\code\*.* >

< %SystemRoot%\system32\draft\*.* >

< %SystemRoot%\system32\MSSSys\*.* >

< %ProgramFiles%\Javascript\*.* >

< %systemroot%\pchealth\helpctr\System\*.exe /s >

< %systemroot%\Web\*.exe >

< %systemroot%\system32\msn\*.* >

< %systemroot%\system32\*.tro >

< %AppData%\Microsoft\Installer\msupdates\*.* >

< %ProgramFiles%\Messenger\*.exe >
[2004/10/13 12:24:37 | 001,694,208 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe

< %systemroot%\system32\systhem32\*.* >

< %systemroot%\system\*.exe >
[2005/01/19 09:52:18 | 000,061,440 | —- | M] () – C:\WINDOWS\system\CmSNXeye.exe

< %USERPROFILE%\Templates\*.tmp >

< %SYSTEMDRIVE%\explorexxx.exe\*.* >

< %Windir%\Installer\*.tmp >
[7 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]

< %systemroot%\System32\*.xco >

< %ProgramFiles%\system32\*.* >

< %systemroot%\System32\windos\*.* >

< %SystemRoot%\system32\sandbox\*.* >

< %SystemRoot%\system32\*.amo >

< %SystemRoot%\system32\Windows Live\*.* >

< %ProgramFiles%\logs\*.* >

< %ProgramFiles%\Bifrost\*.* >

< %SystemRoot%\system32\*.goo >

< %systemroot%\system32\IME\*.* >

< %systemroot%\BackUp\*.* >

< %systemroot%\system32\*.ico >

< %systemroot%\system\*.dat >

< %systemroot%\system\*.exe >
[2005/01/19 09:52:18 | 000,061,440 | —- | M] () – C:\WINDOWS\system\CmSNXeye.exe

< %AppData%\Macromedia\Common\*.* >

< %SYSTEMDRIVE%\dir\*.* /s >

< %systemroot%\system32\ras\*.exe >

< %SYSTEMDRIVE%\MFILES\*.* >

< %SYSTEMDRIVE%\mDNSRespon.exe\*.* >

< %systemroot%\system32\services\*.* >

< %systemroot%\Spooler\*.* >

< %ProgramFiles%\system32\*.* >

< %systemroot%\system32\Setup\*.dll /x >
[112 C:\WINDOWS\system32\Setup\*.tmp files -> C:\WINDOWS\system32\Setup\*.tmp -> ]

< %systemroot%\system32\*.mine >

< %SYSTEMDRIVE%\cleansweep.exe\*.* >

< %systemroot%\system32\ras\*.dll >

< %systemroot%\system32\ras\*.drv >

< %systemroot%\*.iq >

< %systemroot%\system32\XP\*.* >

< %SYSTEMDRIVE%\Extracted\*.* >

< %systemroot%\system32\windows\*.* >

< %systemroot%\logs\*.* >

< %SYSTEMDRIVE%\Win.Msi\*.* >

< %systemroot%\regedit\*.* >

< %systemroot%\system32\skype\*.* >

< %AppData%\Adobe\dlluplwin25\*.* >

< %UserProfile%\*.dat >
[2010/10/01 15:19:48 | 015,466,496 | —- | M] () – C:\Documents and Settings\Thomas\ntuser.dat

< %UserProfile%\*.dll >

< %systemroot%\system32\*.sxo >

< %SYSTEMDRIVE%\Gazma\*.* /s >

< %systemroot%\system32\spynet\*.* >

< %systemroot%\system32\System\*.* >

< %appdata%\Microsoft\Windows\*.* >

< %systemroot%\system32\WinDir\*.* >

< %systemroot%\_\*.* >

< %systemroot%\system32\windows32\*.* >

< %ProgramFiles%\win\*.* >

< %AppData%\Microsoft\CD Burning\*.* >

< %systemroot%\*.cab >

< %systemroot%\K.Backup\*.* >

< %ProgramFiles%\Massenger\*.* >

< %systemroot%\System32\*.doc >

< %systemroot%\Office12\*.* >

< %systemroot%\System32\Rundl32.exe\*.* >

< %ProgramFiles%\yahoo.net\*.* >

< %systemroot%\system32\*.igo >

< %systemroot%\*.rew >

< %systemroot%\System32\spool\DRIVERS\W32X86\3\*.exe >
[2004/04/23 01:00:00 | 000,080,896 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMPV5y.EXE
[2004/04/23 01:00:00 | 000,008,704 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMSD5y.EXE
[2004/04/23 01:00:00 | 000,130,048 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMSM5y.EXE
[2004/04/23 01:00:00 | 000,006,656 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\drivers\w32x86\3\CNMSQ5y.EXE
[2001/10/30 19:59:02 | 000,368,640 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzeng04.exe
[2001/10/30 19:59:21 | 000,405,504 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbx04.exe
[3 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\*.tmp files -> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\*.tmp -> ]

< %USERPROFILE%\.COMMgr\*.* >

< %USERPROFILE%\Desktop\*.bat >

< %PROGRAMFILES%\Common Files\Real\visualizations\*.* >
[2006/12/05 11:22:44 | 000,043,008 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Visualizations\Annabelle.rpv
[2006/12/05 11:22:44 | 000,080,384 | —- | M] () – C:\Program Files\Common Files\Real\Visualizations\CosmicBelt.rpv
[2006/12/05 11:22:44 | 000,007,168 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Visualizations\Fire.rpv
[2006/12/05 11:22:44 | 000,007,680 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Visualizations\FreqBands.rpv
[2006/12/05 11:22:44 | 000,069,632 | —- | M] () – C:\Program Files\Common Files\Real\Visualizations\Nebula.rpv

< %PROGRAMFILES%\Internet Explorer\*.Jmp >

< %PROGRAMFILES%\Windows NT\system\*.dll >

< %systemroot%\system32\*.ext >

< %systemroot%\system32\Com\*.cfg >

< %systemroot%\system32\btz\*.* >

< %systemroot%\system32\EMP\*.* >

< %systemroot%\system32\expo\*.* >

< %systemroot%\system32\inet2\*.* >

< %systemroot%\system32\xrem\*.* >

< %ProgramFiles%\Microsoft\*.* >

< %systemroot%\usgwmt\*.* >

< %ProgramFiles%\B\*.* >

< %SYSTEMDRIVE%\lspp\*.* >

< %systemroot%\Kral\*.* >

< %SYSTEMDRIVE%\windowsdvd.exe\*.* >

< %systemroot%\system32\*.ipo >

< %SYSTEMDRIVE%\usxxxxxxxx.exe\*.* >

< %systemroot%\system32\*.mof >

< %systemroot%\*.atm >

< %systemroot%\system32\svhost\*.* >

< %ProgramFiles%\system32\*.* >

< %ProgramFiles%\Docmentt\*.* >

< %systemroot%\Help\*.vbs >

< %ProgramFiles%\Windows WinSxs\*.* /s >

< %ProgramFiles%\Outlook Express\IDT\*.* /s >

< %ProgramFiles%\Microsoft Office\365\*.* /s >

< %ProgramFiles%\Windows Live\*.* >

< %systemroot%\system32\win32\*.* >

< %SYSTEMDRIVE%\RECYCLER\*.* >

< %systemroot%\Fresh1\*.* >

< %ProgramFiles%\Kekj\*.* /s >

< %systemroot%\GDU\*.* >

< %systemroot%\KA\*.* >

< %systemroot%\R\*.* >

< %systemroot%\system32\*.fyo >

< %USERPROFILE%\System\*.* >

< %systemroot%\Source\*.* >

< %systemroot%\system32\ac\*.* >

< %ProgramFiles%\MSDN\*.* >

< %AppData%\AdobeUM\winvcldll54\*.* /s >

< %ProgramFiles%\Internet Explorer\*.ico >

< %systemroot%\system32\*.ojo >

< %systemroot%\system32\d323s\*.* >

< %systemroot%\system32\re\*.* >

< %UserProfile%\Microsoft\*.dll >

< %UserProfile%\Microsoft\*.log >

< %systemroot%\Bios\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-30 02:01:42
< End of report >
OTL Extras logfile created on: 10/1/2010 3:24:18 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Thomas\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 427.00 Mb Available Physical Memory | 42.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1521 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.16 Gb Total Space | 26.69 Gb Free Space | 30.98% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOMSLAPTOP
Current User Name: Thomas
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] – "C:\Program Files\FinePixViewer\FinePixViewer.exe" "%1" (FUJI PHOTO FILM CO.,LTD.)
Directory [FinePixPrint] – "C:\Program Files\FinePixViewer\FinePixViewer.exe" /p "%1" (FUJI PHOTO FILM CO.,LTD.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\aol.exe" = C:\Program Files\America Online 9.0\aol.exe:*:Disabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Disabled:AOL – File not found
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Disabled:AOL – File not found
"C:\Program Files\Common Files\AOL\1134721647\ee\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1134721647\ee\AOLServiceHost.exe:*:Disabled:AOL – File not found
"C:\Program Files\Soulseek\slsk.exe" = C:\Program Files\Soulseek\slsk.exe:*:Disabled:Soulseek – ()
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"E:\setup\HPZNET01.EXE" = E:\setup\HPZNET01.EXE:*:Enabled:hpznet01.exe – File not found
"E:\setup\HPONICIFS01.EXE" = E:\setup\HPONICIFS01.EXE:*:Enabled:hponicifs01.exe – File not found
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online)
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (America Online)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon – (America Online, Inc)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed – (America Online Inc)
"C:\Program Files\Common Files\AOL\1220374803\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1220374803\EE\AOLServiceHost.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL – (America Online Inc.)
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL – (Gteko Ltd.)
"C:\Program Files\America Online 9.0a\waol.exe" = C:\Program Files\America Online 9.0a\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\America Online 9.0b\waol.exe" = C:\Program Files\America Online 9.0b\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\America Online 9.0c\waol.exe" = C:\Program Files\America Online 9.0c\waol.exe:*:Enabled:AOL – (America Online, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library
"{04F13802-1C88-44F5-92E3-CC14B1123B7F}" = Targus USB Port Replicator with Video(ACP50) V5.1.3A
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio DigitalMedia Data
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{0DF00135-D5A7-476A-BFB3-EDFF2840076A}" = VAIO Wireless LAN Setup Utility
"{10C69612-017B-45F5-B986-7D113D5A2EA3}" = MSN Toolbar
"{138BD312-3557-40F8-BC5E-6DFF00A6880D}" = BPDSoftware_Ini
"{1417F599-1DBD-4499-9375-B2813E9F890C}" = VAIO Camera Utility
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{17E81C48-407E-499f-A105-1B49ACDB9BA4}" = ProductContext
"{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver
"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.4.2
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{26BB11D7-36D1-49ee-986F-8F8AD4D051C8}" = L7600
"{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}" = Wireless Switch Setting Utility
"{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FF660F4-147B-48CB-B824-2B595759D9EF}" = VZAccess Manager
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 2
"{4AE80E7B-6633-4046-9C15-D3B281C4F73D}" = BPDSoftware
"{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0
"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{5958CAC6-373E-402F-84FE-0A699AA920B9}" = LAN Setting Utility
"{629CCE02-041D-4577-892C-577861181771}" = Verizon Wireless USB760 Firmware Updates
"{639BB4D3-AA30-4A7B-8CB5-6DE681AD6659}" = VAIO Light Flo Wallpaper
"{63B8FB69-A1B6-425D-B67D-5257B7A1F663}" = Image Converter 2 Plus
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6DE9751D-3FFE-400E-8761-26A92DB734DE}" = BPD_HPSU
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security
"{7729A02E-D1AD-4830-8FC5-11853500D90D}" = HP Officejet Pro All-In-One Series
"{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 5.0
"{80EE18E6-F16C-11D4-8BE8-006097C9A3ED}" = ISScript
"{82081533-F045-469E-BD53-F16839E445C3}" = VAIO Support Central
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C045626-4496-4238-B3B8-394CC6D46427}" = 7500_7600_7700_Help
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for VAIO
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9B77AF57-F7B2-488F-8B75-1DDDCC447545}_is1" = Hitman Pro
"{9B953606-000E-491C-B74D-78ECFDD520A0}" = OpenMG Metadata Extractor for Windows Media Player
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9D2B0322-44AE-460E-9283-4D2D7A9205AE}" = Trend Micro Internet Security
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{9E407618-D9CD-4F39-9490-9ED45294073D}" = Click to DVD 2.0.03 Menu Data
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A87EBA79-93DB-4A87-B9BA-62F8FB12D993}" = ImageStation
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio DigitalMedia Audio
"{AC2BA148-EE9C-4F1A-AFCE-F38C2C71D29B}" = Mobile Broadband Generic Drivers
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0.5
"{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 5.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio DigitalMedia Copy
"{B5B606B5-7FF0-4946-80E3-35185EEF84AD}" = Rolling Stone - Cover to Cover
"{B85C4D19-6CEB-48CF-BD98-C887AC8C6F94}" = iTunes
"{B9987754-9A14-4B61-ABB3-73A79503238D}" = iPod for Windows User Guide
"{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}" = Sony Video Shared Library
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}" = Safari
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = BPDfax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0448678-1203-4158-A58F-B3D0B616BF9E}" = Sony Certificate PCH
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D48AD533-BAD5-469B-A9AA-272C6D80E70B}" = MPM
"{D89EF3B3-6F17-4665-B7A9-A4235A6DC787}" = Ghost Recon
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (VAIO_VEDB)
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E6B84761-D63F-2A56-4948-E53F1B6D6EF1}" = MozyHome
"{E809063C-51A3-4269-8984-D1EB742F2151}" = Click to DVD 2.5.00
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"{F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}" = Windows Media Connect
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FB714F13-10C9-48DB-91C9-DDBCCCBF9370}" = VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FE3BF611-9B8B-44DC-A424-F8C4BA122A1D}" = VAIO Security Center
"3D Deck" = Sierra 3D Deck
"AAA PDF Password Remover_is1" = AAA PDF Password Remover V2.0
"Active Disk" = Active Disk
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"AG_Gone_Fishing" = AG_Gone_Fishing Screen Saver
"AG_Natural_High" = AG_Natural_High Screen Saver
"AG_Volcano" = AG_Volcano Screen Saver
"America Online us" = America Online (Choose which version to remove)
"AOL Connectivity Services" = AOL Connectivity Services
"AOL Deskbar" = AOL Deskbar
"AOL Search Enhancement" = Search Enhancement by AOL Search
"AOL Toolbar" = AOL Toolbar
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"CANONBJ_Deinstall_CNMCP5y.DLL" = Canon PIXMA iP1500
"C-Media USB Sound Driver" = C-Media USB Sound Driver
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFA&SUBSYS;_20030003" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"Corel Remove Program" = Corel Business Applications
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Electrical Wiring" = Sierra Electrical Wiring
"F/A-18 Precision Strike Fighter" = F/A-18 Precision Strike Fighter
"GCH Guitar academy" = GCH Guitar academy
"GEPDFWriter" = GEPDFWriter
"Google Chrome" = Google Chrome
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP LaserJet 1100" = HP LaserJet 1100
"hp officejet d series 1144712463" = hp officejet d series
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"InstallShield_{B9987754-9A14-4B61-ABB3-73A79503238D}" = iPod for Windows User Guide
"InstallShield_{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"InstallShield_{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"Kaye Validator 3.12" = Kaye Validator 3.12
"Kaye Validator Initialization 3.12" = Kaye Validator Initialization 3.12
"Kwinzy" = Kwinzy 1.0 build 119
"Languages of the World" = Languages of the World
"Metacafe" = Metacafe
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Press Interactive Training" = Microsoft Interactive Training
"Mobile Broadband Generic Drivers" = Mobile Broadband Generic Drivers
"MWASPI" = MicroStaff WINASPI
"NETGEAR Print Server Software" = NETGEAR Print Server Software
"NETGEAR Print Server Utility" = NETGEAR Print Server Utility
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OpenMG HotFix4.3-05-09-14-01" = OpenMG Limited Patch 4.3-05-10-05-01
"PhotoWorks" = PhotoWorks
"Port Magic" = Pure Networks Port Magic
"ProInst" = Intel® PROSet/Wireless Software
"PROSet" = Intel® PRO Network Connections Drivers
"RealPlayer 6.0" = RealPlayer Basic
"Rosetta Stone 2.1.4.1A" = Rosetta Stone 2.1.4.1A
"SI Calendar 2009" = SI Calendar 2009
"Sierra Home Architect" = Sierra Home Architect
"Soulseek" = SoulSeek Client 156c
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.2
"Unitype Applications" = Unitype Applications
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Connect" = Windows Media Connect
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinZip" = WinZip
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Toolbar" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/1/2010 4:20:52 AM | Computer Name = TOMSLAPTOP | Source = Google Update | ID = 20
Description =

Error - 10/1/2010 5:20:52 AM | Computer Name = TOMSLAPTOP | Source = Google Update | ID = 20
Description =

Error - 10/1/2010 6:20:52 AM | Computer Name = TOMSLAPTOP | Source = Google Update | ID = 20
Description =

Error - 10/1/2010 7:20:52 AM | Computer Name = TOMSLAPTOP | Source = Google Update | ID = 20
Description =

Error - 10/1/2010 9:14:12 AM | Computer Name = TOMSLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.14.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/1/2010 9:14:50 AM | Computer Name = TOMSLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.14.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/1/2010 9:15:06 AM | Computer Name = TOMSLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.14.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/1/2010 9:23:13 AM | Computer Name = TOMSLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.14.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/1/2010 9:23:28 AM | Computer Name = TOMSLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.14.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/1/2010 2:02:49 PM | Computer Name = TOMSLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.14.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 10/1/2010 3:03:27 PM | Computer Name = TOMSLAPTOP | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 10/1/2010 3:03:27 PM | Computer Name = TOMSLAPTOP | Source = Service Control Manager | ID = 7003
Description = The Simple Mail Transfer Protocol (SMTP) service depends on the following
nonexistent service: IISADMIN

Error - 10/1/2010 3:03:27 PM | Computer Name = TOMSLAPTOP | Source = Service Control Manager | ID = 7001
Description = The VAIO Entertainment File Import Service service depends on the
VAIO Entertainment Database Service service which failed to start because of the
following error: %%1068

Error - 10/1/2010 3:03:27 PM | Computer Name = TOMSLAPTOP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD DMICall Fips intelppm IPSec mozyFilter MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip Tcpip6 tmtdi
Tosrfcom

Error - 10/1/2010 3:07:22 PM | Computer Name = TOMSLAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/1/2010 3:08:06 PM | Computer Name = TOMSLAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 10/1/2010 3:16:08 PM | Computer Name = TOMSLAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/1/2010 3:18:20 PM | Computer Name = TOMSLAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/1/2010 3:20:15 PM | Computer Name = TOMSLAPTOP | Source = Service Control Manager | ID = 7003
Description = The Simple Mail Transfer Protocol (SMTP) service depends on the following
nonexistent service: IISADMIN

Error - 10/1/2010 3:20:15 PM | Computer Name = TOMSLAPTOP | Source = Service Control Manager | ID = 7000
Description = The Upload Manager service failed to start due to the following error:
%%1079


< End of report >
Hello,

Good Afternoon!

Did you add the following to your trusted domain list in Internet Explorer?

O15 - HKCU\..Trusted Domains: //@install.mar@ ([]msni in My Computer)
O15 - HKCU\..Trusted Domains: //@mail.mar@ ([]msni in Local intranet)


Also, is your Internet Service Provider (ISP) currently AOL?

OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    SRV - (ZipToA) – C:\WINDOWS\System32\ZipToA.exe File not found
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
    O4 - HKLM..\Run: [CmUsbSound] File not found
    O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O24 - Desktop Components:0 () - http://healthnews.uc.edu/images/global/external.gif
    O24 - Desktop Components:1 () - http://kidney.niddk.nih.gov/images/skip.gif
    O33 - MountPoints2\{166da074-73e5-11df-993a-0013020cc322}\Shell - "" = AutoRun
    O33 - MountPoints2\{166da074-73e5-11df-993a-0013020cc322}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{166da074-73e5-11df-993a-0013020cc322}\Shell\AutoRun\command - "" = F:\PhotoViewer.exe – File not found
    O33 - MountPoints2\{7d82ba30-c25a-11df-9967-0013020cc322}\Shell - "" = AutoRun
    O33 - MountPoints2\{7d82ba30-c25a-11df-9967-0013020cc322}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{7d82ba30-c25a-11df-9967-0013020cc322}\Shell\AutoRun\command - "" = F:\VZAccess_Manager.exe – File not found
    O33 - MountPoints2\{7d82ba35-c25a-11df-9967-0013020cc322}\Shell - "" = AutoRun
    O33 - MountPoints2\{7d82ba35-c25a-11df-9967-0013020cc322}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{7d82ba35-c25a-11df-9967-0013020cc322}\Shell\AutoRun\command - "" = G:\VZAccess_Manager.exe – File not found
    O33 - MountPoints2\{b2b253c3-b155-11da-828e-0013020cc322}\Shell - "" = AutoRun
    O33 - MountPoints2\{b2b253c3-b155-11da-828e-0013020cc322}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{b2b253c3-b155-11da-828e-0013020cc322}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    [56 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
    [2123 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [17 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\Documents and Settings\Thomas\My Documents\*.tmp files -> C:\Documents and Settings\Thomas\My Documents\*.tmp -> ]
    [2123 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [17 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\Documents and Settings\Thomas\My Documents\*.tmp files -> C:\Documents and Settings\Thomas\My Documents\*.tmp -> ]
    [56 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
    [56 C:\WINDOWS\Fonts\*.tmp files -> C:\WINDOWS\Fonts\*.tmp -> ]
    [17 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2123 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
    [7 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
    [7 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
    [112 C:\WINDOWS\system32\Setup\*.tmp files -> C:\WINDOWS\system32\Setup\*.tmp -> ]
    [3 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\*.tmp files -> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\*.tmp -> ]
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



If you don't use the following toolbars then I suggest you remove them via Add/Remove Programs which can be located in your Control Panel.

MSN Toolbar
AOL Toolbar
Yahoo! Toolbar



NEXT:



Java Outdated
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "JDK 6 Update 21 (JDK or JRE)".
  • Click the "Download JRE" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586.exe to install the newest version.
  • If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
– Starting with Java 6u10, the uninstaller incorporated in each new release uses Enhanced Auto update to automatically remove the previous version when updating to a later update release. It will not remove older versions, so they will need to be removed manually.
– Java is updated frequently. If you want to be automatically notified of future updates, just turn on the Java Automatic Update feature and you will not have to remember to update when Java releases a new version.


Note:
The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
Click Ok and reboot your computer.


NEXT



Clean Java Cache & Temporary Files
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT:



Please download JavaRa and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location and post it in your next reply.


NEXT:



Please Set Your System to Show Hidden Files
  • Go to Start -> My Computer (Or click the My Computer icon on your desktop)
  • Go to the Tools Menu -> Folder Options.
  • Select the "View" tab.
  • Where you see [external image: Posted Image], click the [external image: Posted Image] radio button.
  • Uncheck "Hide extensions for known file types"
  • Uncheck "Hide protected operating system files"
  • Click Ok.
  • Exit/Close My Computer.


NEXT:



VirusTotal File Scan
Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: C:\WINDOWS\System32\_004246_.tmp.dll
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please repeat the above process for the following files below:

C:\WINDOWS\System32\_004279_.tmp.dll

Please post the results in your next reply
Here is first log as requested after pressing RUN FIX Error: Unable to interpret <%SYSTEMDRIVE%\*.*> in the current context! Error: Unable to interpret <%systemroot%\Fonts\*.com> in the current context! Error: Unable to interpret <%systemroot%\Fonts\*.dll> in the current context! Error: Unable to interpret <%systemroot%\Fonts\*.ini> in the current context! Error: Unable to interpret <%systemroot%\Fonts\*.ini2> in the current context! Error: Unable to interpret <%systemroot%\Fonts\*.exe> in the current context! Error: Unable to interpret <%systemroot%\system32\spool\prtprocs\w32x86\*.*> in the current context! Error: Unable to interpret <%systemroot%\REPAIR\*.bak1> in the current context! Error: Unable to interpret <%systemroot%\REPAIR\*.ini> in the current context! Error: Unable to interpret <%systemroot%\system32\*.jpg > in the current context! Error: Unable to interpret <%systemroot%\*.jpg > in the current context! Error: Unable to interpret <%systemroot%\*.png > in the current context! Error: Unable to interpret <%systemroot%\*.scr> in the current context! Error: Unable to interpret <%systemroot%\*._sy> in the current context! Error: Unable to interpret <%APPDATA%\Adobe\Update\*.*> in the current context! Error: Unable to interpret <%ALLUSERSPROFILE%\Favorites\*.*> in the current context! Error: Unable to interpret <%APPDATA%\Microsoft\*.* > in the current context! Error: Unable to interpret <%PROGRAMFILES%\*.*> in the current context! Error: Unable to interpret <%APPDATA%\Update\*.*> in the current context! Error: Unable to interpret <%systemroot%\*. /mp /s> in the current context! Error: Unable to interpret <%systemroot%\System32\config\*.sav > in the current context! Error: Unable to interpret <%PROGRAMFILES%\bak. /s> in the current context! Error: Unable to interpret <%systemroot%\system32\bak. /s> in the current context! Error: Unable to interpret <%ALLUSERSPROFILE%\Start Menu\*.lnk /x > in the current context! Error: Unable to interpret <%systemroot%\system32\config\systemprofile\*.dat /x> in the current context! Error: Unable to interpret <%systemroot%\*.config> in the current context! Error: Unable to interpret <%systemroot%\system32\*.db> in the current context! Error: Unable to interpret <%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x> in the current context! Error: Unable to interpret <%USERPROFILE%\Desktop\*.exe> in the current context! Error: Unable to interpret <%PROGRAMFILES%\Common Files\*.*> in the current context! Error: Unable to interpret <%systemroot%\*.src> in the current context! Error: Unable to interpret <%systemroot%\install\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\DLL\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\HelpFiles\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\rundll\*.*> in the current context! Error: Unable to interpret <%systemroot%\winn32\*.*> in the current context! Error: Unable to interpret <%systemroot%\Java\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\test\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\Rundll32\*.*> in the current context! Error: Unable to interpret <%systemroot%\AppPatch\Custom\*.*> in the current context! Error: Unable to interpret <%APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x> in the current context! Error: Unable to interpret <%PROGRAMFILES%\PC-Doctor\Downloads\*.*> in the current context! Error: Unable to interpret <%PROGRAMFILES%\Internet Explorer\*.tmp> in the current context! Error: Unable to interpret <%PROGRAMFILES%\Internet Explorer\*.dat> in the current context! Error: Unable to interpret <%USERPROFILE%\My Documents\*.exe> in the current context! Error: Unable to interpret <%USERPROFILE%\*.exe> in the current context! Error: Unable to interpret <%systemroot%\ADDINS\*.*> in the current context! Error: Unable to interpret <%systemroot%\assembly\*.bak2> in the current context! Error: Unable to interpret <%systemroot%\Config\*.*> in the current context! Error: Unable to interpret <%systemroot%\REPAIR\*.bak2> in the current context! Error: Unable to interpret <%systemroot%\SECURITY\Database\*.sdb /x> in the current context! Error: Unable to interpret <%systemroot%\SYSTEM\*.bak2> in the current context! Error: Unable to interpret <%systemroot%\Web\*.bak2> in the current context! Error: Unable to interpret <%systemroot%\Driver Cache\*.*> in the current context! Error: Unable to interpret <%PROGRAMFILES%\Mozilla Firefox\0*.exe> in the current context! Error: Unable to interpret <%ProgramFiles%\Microsoft Common\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\TinyProxy.> in the current context! Error: Unable to interpret <%USERPROFILE%\Favorites\*.url /x> in the current context! Error: Unable to interpret <%systemroot%\system32\*.bk> in the current context! Error: Unable to interpret <%systemroot%\*.te> in the current context! Error: Unable to interpret <%systemroot%\system32\system32\*.*> in the current context! Error: Unable to interpret <%ALLUSERSPROFILE%\*.dat /x> in the current context! Error: Unable to interpret <%systemroot%\system32\drivers\*.rmv> in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret <%PROGRAMFILES%\Microsoft\*.*> in the current context! Error: Unable to interpret <%systemroot%\System32\Wbem\proquota.exe> in the current context! Error: Unable to interpret <%PROGRAMFILES%\Mozilla Firefox\*.dat> in the current context! Error: Unable to interpret <%USERPROFILE%\Cookies\*.txt /x> in the current context! Error: Unable to interpret <%SystemRoot%\system32\fonts\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\winlog\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\Language\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\Settings\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\*.quo> in the current context! Error: Unable to interpret <%SYSTEMROOT%\AppPatch\*.exe> in the current context! Error: Unable to interpret <%SYSTEMROOT%\inf\*.exe> in the current context! Error: Unable to interpret <%SYSTEMROOT%\Installer\*.exe> in the current context! Error: Unable to interpret <%systemroot%\system32\config\*.bak2> in the current context! Error: Unable to interpret <%systemroot%\system32\Computers\*.*> in the current context! Error: Unable to interpret <%SystemRoot%\system32\Sound\*.*> in the current context! Error: Unable to interpret <%SystemRoot%\system32\SpecialImg\*.*> in the current context! Error: Unable to interpret <%SystemRoot%\system32\code\*.*> in the current context! Error: Unable to interpret <%SystemRoot%\system32\draft\*.*> in the current context! Error: Unable to interpret <%SystemRoot%\system32\MSSSys\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\Javascript\*.*> in the current context! Error: Unable to interpret <%systemroot%\pchealth\helpctr\System\*.exe /s> in the current context! Error: Unable to interpret <%systemroot%\Web\*.exe> in the current context! Error: Unable to interpret <%systemroot%\system32\msn\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\*.tro> in the current context! Error: Unable to interpret <%AppData%\Microsoft\Installer\msupdates\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\Messenger\*.exe> in the current context! Error: Unable to interpret <%systemroot%\system32\systhem32\*.*> in the current context! Error: Unable to interpret <%systemroot%\system\*.exe> in the current context! Error: Unable to interpret <%USERPROFILE%\Templates\*.tmp> in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\explorexxx.exe\*.*> in the current context! Error: Unable to interpret <%Windir%\Installer\*.tmp> in the current context! Error: Unable to interpret <%systemroot%\System32\*.xco> in the current context! Error: Unable to interpret <%ProgramFiles%\system32\*.*> in the current context! Error: Unable to interpret <%systemroot%\System32\windos\*.*> in the current context! Error: Unable to interpret <%SystemRoot%\system32\sandbox\*.*> in the current context! Error: Unable to interpret <%SystemRoot%\system32\*.amo> in the current context! Error: Unable to interpret <%SystemRoot%\system32\Windows Live\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\logs\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\Bifrost\*.*> in the current context! Error: Unable to interpret <%SystemRoot%\system32\*.goo> in the current context! Error: Unable to interpret <%systemroot%\system32\IME\*.*> in the current context! Error: Unable to interpret <%systemroot%\BackUp\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\*.ico> in the current context! Error: Unable to interpret <%systemroot%\system\*.dat> in the current context! Error: Unable to interpret <%systemroot%\system\*.exe> in the current context! Error: Unable to interpret <%AppData%\Macromedia\Common\*.*> in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\dir\*.* /s> in the current context! Error: Unable to interpret <%systemroot%\system32\ras\*.exe> in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\MFILES\*.*> in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\mDNSRespon.exe\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\services\*.*> in the current context! Error: Unable to interpret <%systemroot%\Spooler\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\system32\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\Setup\*.dll /x> in the current context! Error: Unable to interpret <%systemroot%\system32\*.mine > in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\cleansweep.exe\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\ras\*.dll > in the current context! Error: Unable to interpret <%systemroot%\system32\ras\*.drv> in the current context! Error: Unable to interpret <%systemroot%\*.iq > in the current context! Error: Unable to interpret <%systemroot%\system32\XP\*.*> in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\Extracted\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\windows\*.*> in the current context! Error: Unable to interpret <%systemroot%\logs\*.*> in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\Win.Msi\*.*> in the current context! Error: Unable to interpret <%systemroot%\regedit\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\skype\*.*> in the current context! Error: Unable to interpret <%AppData%\Adobe\dlluplwin25\*.*> in the current context! Error: Unable to interpret <%UserProfile%\*.dat> in the current context! Error: Unable to interpret <%UserProfile%\*.dll> in the current context! Error: Unable to interpret <%systemroot%\system32\*.sxo> in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\Gazma\*.* /s> in the current context! Error: Unable to interpret <%systemroot%\system32\spynet\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\System\*.*> in the current context! Error: Unable to interpret <%appdata%\Microsoft\Windows\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\WinDir\*.*> in the current context! Error: Unable to interpret <%systemroot%\_\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\windows32\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\win\*.*> in the current context! Error: Unable to interpret <%AppData%\Microsoft\CD Burning\*.*> in the current context! Error: Unable to interpret <%systemroot%\*.cab> in the current context! Error: Unable to interpret <%systemroot%\K.Backup\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\Massenger\*.*> in the current context! Error: Unable to interpret <%systemroot%\System32\*.doc> in the current context! Error: Unable to interpret <%systemroot%\Office12\*.*> in the current context! Error: Unable to interpret <%systemroot%\System32\Rundl32.exe\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\yahoo.net\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\*.igo> in the current context! Error: Unable to interpret <%systemroot%\*.rew> in the current context! Error: Unable to interpret <%systemroot%\System32\spool\DRIVERS\W32X86\3\*.exe> in the current context! Error: Unable to interpret <%USERPROFILE%\.COMMgr\*.*> in the current context! Error: Unable to interpret <%USERPROFILE%\Desktop\*.bat> in the current context! Error: Unable to interpret <%PROGRAMFILES%\Common Files\Real\visualizations\*.*> in the current context! Error: Unable to interpret <%PROGRAMFILES%\Internet Explorer\*.Jmp> in the current context! Error: Unable to interpret <%PROGRAMFILES%\Windows NT\system\*.dll> in the current context! Error: Unable to interpret <%systemroot%\system32\*.ext> in the current context! Error: Unable to interpret <%systemroot%\system32\Com\*.cfg> in the current context! Error: Unable to interpret <%systemroot%\system32\btz\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\EMP\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\expo\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\inet2\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\xrem\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\Microsoft\*.*> in the current context! Error: Unable to interpret <%systemroot%\usgwmt\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\B\*.*> in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\lspp\*.*> in the current context! Error: Unable to interpret <%systemroot%\Kral\*.*> in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\windowsdvd.exe\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\*.ipo> in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\usxxxxxxxx.exe\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\*.mof> in the current context! Error: Unable to interpret <%systemroot%\*.atm> in the current context! Error: Unable to interpret <%systemroot%\system32\svhost\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\system32\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\Docmentt\*.*> in the current context! Error: Unable to interpret <%systemroot%\Help\*.vbs> in the current context! Error: Unable to interpret <%ProgramFiles%\Windows WinSxs\*.* /s> in the current context! Error: Unable to interpret <%ProgramFiles%\Outlook Express\IDT\*.* /s> in the current context! Error: Unable to interpret <%ProgramFiles%\Microsoft Office\365\*.* /s> in the current context! Error: Unable to interpret <%ProgramFiles%\Windows Live\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\win32\*.*> in the current context! Error: Unable to interpret <%SYSTEMDRIVE%\RECYCLER\*.*> in the current context! Error: Unable to interpret <%systemroot%\Fresh1\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\Kekj\*.* /s> in the current context! Error: Unable to interpret <%systemroot%\GDU\*.*> in the current context! Error: Unable to interpret <%systemroot%\KA\*.*> in the current context! Error: Unable to interpret <%systemroot%\R\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\*.fyo> in the current context! Error: Unable to interpret <%USERPROFILE%\System\*.*> in the current context! Error: Unable to interpret <%systemroot%\Source\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\ac\*.*> in the current context! Error: Unable to interpret <%ProgramFiles%\MSDN\*.*> in the current context! Error: Unable to interpret <%AppData%\AdobeUM\winvcldll54\*.* /s> in the current context! Error: Unable to interpret <%ProgramFiles%\Internet Explorer\*.ico> in the current context! Error: Unable to interpret <%systemroot%\system32\*.ojo> in the current context! Error: Unable to interpret <%systemroot%\system32\d323s\*.*> in the current context! Error: Unable to interpret <%systemroot%\system32\re\*.*> in the current context! Error: Unable to interpret <%UserProfile%\Microsoft\*.dll> in the current context! Error: Unable to interpret <%UserProfile%\Microsoft\*.log> in the current context! Error: Unable to interpret <%systemroot%\Bios\*.*> in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! OTL by OldTimer - Version 3.2.14.1 log created on 10012010_162733 Going to go through other processes you advised :thumbup:
Ran OTL Fix…asked for reboot; received notepad report and then ACTIVE DESKTOP RECOVERY came up; restarted my VZ Broadband connection (in a hotel in Boston) and opened Internet Explorer….here are results of OTL Fix

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Error: No service named ZipToA was found to stop!
Service\Driver key ZipToA not found.
File C:\WINDOWS\System32\ZipToA.exe File not found not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CmUsbSound not found.
Starting removal of ActiveX control {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0\ deleted successfully.
File http://healthnews.uc.edu/images/global/external.gif not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1\ not found.
File http://kidney.niddk.nih.gov/images/skip.gif not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{166da074-73e5-11df-993a-0013020cc322}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166da074-73e5-11df-993a-0013020cc322}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{166da074-73e5-11df-993a-0013020cc322}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166da074-73e5-11df-993a-0013020cc322}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{166da074-73e5-11df-993a-0013020cc322}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166da074-73e5-11df-993a-0013020cc322}\ not found.
File F:\PhotoViewer.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7d82ba30-c25a-11df-9967-0013020cc322}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7d82ba30-c25a-11df-9967-0013020cc322}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7d82ba30-c25a-11df-9967-0013020cc322}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7d82ba30-c25a-11df-9967-0013020cc322}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7d82ba30-c25a-11df-9967-0013020cc322}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7d82ba30-c25a-11df-9967-0013020cc322}\ not found.
File F:\VZAccess_Manager.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7d82ba35-c25a-11df-9967-0013020cc322}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7d82ba35-c25a-11df-9967-0013020cc322}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7d82ba35-c25a-11df-9967-0013020cc322}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7d82ba35-c25a-11df-9967-0013020cc322}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7d82ba35-c25a-11df-9967-0013020cc322}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7d82ba35-c25a-11df-9967-0013020cc322}\ not found.
File move failed. G:\VZAccess_Manager.exe scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2b253c3-b155-11da-828e-0013020cc322}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b2b253c3-b155-11da-828e-0013020cc322}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2b253c3-b155-11da-828e-0013020cc322}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b2b253c3-b155-11da-828e-0013020cc322}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2b253c3-b155-11da-828e-0013020cc322}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b2b253c3-b155-11da-828e-0013020cc322}\ not found.
File F:\LaunchU3.exe not found.
File/Folder C:\WINDOWS\Fonts\*.tmp not found.
File/Folder C:\WINDOWS\System32\*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
File/Folder C:\Documents and Settings\Thomas\My Documents\*.tmp not found.
File/Folder C:\WINDOWS\System32\*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
File/Folder C:\Documents and Settings\Thomas\My Documents\*.tmp not found.
File/Folder C:\WINDOWS\Fonts\*.tmp not found.
File/Folder C:\WINDOWS\Fonts\*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
File/Folder C:\WINDOWS\system32\*.tmp not found.
File/Folder C:\WINDOWS\Installer\*.tmp not found.
File/Folder C:\WINDOWS\Installer\*.tmp not found.
File/Folder C:\WINDOWS\system32\Setup\*.tmp not found.
File/Folder C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\*.tmp not found.
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Thomas\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Thomas\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point (0)

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Thomas
->Temp folder emptied: 450893 bytes
->Temporary Internet Files folder emptied: 6550591 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 328733 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 197272 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 64715884 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 1504069 bytes

Total Files Cleaned = 70.00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: Thomas
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.14.1 log created on 10052010_092208

Files\Folders moved on Reboot…
File move failed. G:\VZAccess_Manager.exe scheduled to be moved on reboot.
C:\Documents and Settings\Thomas\Local Settings\Temporary Internet Files\Content.IE5\VARV3DFB\like[1].htm moved successfully.
C:\Documents and Settings\Thomas\Local Settings\Temporary Internet Files\Content.IE5\SN8ZZFNW\index[2].htm moved successfully.
C:\Documents and Settings\Thomas\Local Settings\Temporary Internet Files\Content.IE5\GZT1JXIV\iframe[1].htm moved successfully.
C:\Documents and Settings\Thomas\Local Settings\Temporary Internet Files\Content.IE5\GZT1JXIV\index[1].htm moved successfully.
C:\Documents and Settings\Thomas\Local Settings\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_408.dat not found!

Registry entries deleted on Reboot…
WILL CONTINUE ON WITH REST OF REPLY
Ran all Java instructions to remove and download, etc. The following is the JAVARA log followed by the VIRUS TOTAL logs requested on the Windows System 32 files:

JavaRa 1.16 Removal Log.
Report follows after line.
————————————
The JavaRa removal process was started on Tue Oct 05 10:44:31 2010

Found and removed: C:\Documents and Settings\Thomas\Application Data\Sun\Java\jre1.6.0_13
Found and removed: C:\Documents and Settings\Thomas\Application Data\Sun\Java\jre1.6.0_14
Found and removed: C:\Documents and Settings\Thomas\Application Data\Sun\Java\jre1.6.0_15
Found and removed: C:\Documents and Settings\Thomas\Application Data\Sun\Java\jre1.6.0_16
Found and removed: C:\Documents and Settings\Thomas\Application Data\Sun\Java\jre1.6.0_17
Found and removed: C:\Documents and Settings\Thomas\Application Data\Sun\Java\jre1.6.0_20
JavaRa 1.16 Removal Log.
Report follows after line.
————————————
The JavaRa removal process was started on Tue Oct 05 10:49:11 2010

————————————
Finished reporting.


VIRUS TOTAL

• Table
• Tabulated
• CSV
• HTML
• BBCode
• Show positives only
Antivirus Version Last update Result
AhnLab-V3 2010.10.05.00 2010.10.04 -
AntiVir 7.10.12.135 2010.10.05 -
Antiy-AVL 2.0.3.7 2010.10.05 -
Authentium 5.2.0.5 2010.10.05 -
Avast 4.8.1351.0 2010.10.05 -
Avast5 5.0.594.0 2010.10.05 -
AVG 9.0.0.851 2010.10.05 -
BitDefender 7.2 2010.10.05 -
CAT-QuickHeal 11.00 2010.10.05 -
ClamAV 0.96.2.0-git 2010.10.05 -
Comodo 6289 2010.10.05 -
DrWeb 5.0.2.03300 2010.10.05 -
Emsisoft 5.0.0.50 2010.10.05 -
eSafe 7.0.17.0 2010.10.03 -
eTrust-Vet 36.1.7893 2010.10.05 -
F-Prot 4.6.2.117 2010.10.04 -
F-Secure 9.0.15370.0 2010.10.05 -
Fortinet 4.2.249.0 2010.10.05 -
GData 21 2010.10.05 -
Ikarus T3.1.1.90.0 2010.10.05 -
Jiangmin 13.0.900 2010.10.03 -
K7AntiVirus 9.63.2672 2010.10.04 -
Kaspersky 7.0.0.125 2010.10.05 -
McAfee 5.400.0.1158 2010.10.05 -
McAfee-GW-Edition 2010.1C 2010.10.05 -
Microsoft 1.6201 2010.10.05 -
NOD32 5505 2010.10.05 -
Norman 6.06.07 2010.10.05 -
nProtect 2010-10-05.02 2010.10.05 -
Panda 10.0.2.7 2010.10.05 -
PCTools 7.0.3.5 2010.10.02 -
Prevx 3.0 2010.10.05 -
Rising 22.67.02.07 2010.09.30 -
Sophos 4.58.0 2010.10.05 -
Sunbelt 6987 2010.10.05 -
SUPERAntiSpyware 4.40.0.1006 2010.10.05 -
Symantec 20101.2.0.161 2010.10.05 -
TheHacker 6.7.0.1.048 2010.10.04 -
TrendMicro 9.120.0.1004 2010.10.05 -
TrendMicro-HouseCall 9.120.0.1004 2010.10.05 -
VBA32 3.12.14.1 2010.10.05 -
ViRobot 2010.10.4.4074 2010.10.05 -
VirusBuster 12.67.3.0 2010.10.05 -
MD5: 3967aeee12073446c4fb4af0b681f0fa
SHA1: f17b1f85fa7eafe33b105a02cb593d1f45dbdf30
SHA256: 6d5726709b97ef935e04cfedf1bebb6c308b19217254eb572793f4191636bcb6
File size: 22040 bytes
Scan date: 2010-10-05 15:08:31 (UTC)
Antivirus Version Last update Result
AhnLab-V3 2010.10.05.00 2010.10.04 -
AntiVir 7.10.12.135 2010.10.05 -
Antiy-AVL 2.0.3.7 2010.10.05 -
Authentium 5.2.0.5 2010.10.05 -
Avast 4.8.1351.0 2010.10.05 -
Avast5 5.0.594.0 2010.10.05 -
AVG 9.0.0.851 2010.10.05 -
BitDefender 7.2 2010.10.05 -
CAT-QuickHeal 11.00 2010.10.05 -
ClamAV 0.96.2.0-git 2010.10.05 -
Comodo 6289 2010.10.05 -
DrWeb 5.0.2.03300 2010.10.05 -
Emsisoft 5.0.0.50 2010.10.05 -
eSafe 7.0.17.0 2010.10.03 -
eTrust-Vet 36.1.7893 2010.10.05 -
F-Prot 4.6.2.117 2010.10.04 -
F-Secure 9.0.15370.0 2010.10.05 -
Fortinet 4.2.249.0 2010.10.05 -
GData 21 2010.10.05 -
Ikarus T3.1.1.90.0 2010.10.05 -
Jiangmin 13.0.900 2010.10.03 -
K7AntiVirus 9.63.2672 2010.10.04 -
Kaspersky 7.0.0.125 2010.10.05 -
McAfee 5.400.0.1158 2010.10.05 -
McAfee-GW-Edition 2010.1C 2010.10.05 -
Microsoft 1.6201 2010.10.05 -
NOD32 5505 2010.10.05 -
Norman 6.06.07 2010.10.05 -
nProtect 2010-10-05.02 2010.10.05 -
Panda 10.0.2.7 2010.10.05 -
PCTools 7.0.3.5 2010.10.02 -
Prevx 3.0 2010.10.05 -
Rising 22.67.02.07 2010.09.30 -
Sophos 4.58.0 2010.10.05 -
Sunbelt 6987 2010.10.05 -
SUPERAntiSpyware 4.40.0.1006 2010.10.05 -
Symantec 20101.2.0.161 2010.10.05 -
TheHacker 6.7.0.1.048 2010.10.04 -
TrendMicro 9.120.0.1004 2010.10.05 -
TrendMicro-HouseCall 9.120.0.1004 2010.10.05 -
VBA32 3.12.14.1 2010.10.05 -
ViRobot 2010.10.4.4074 2010.10.05 -
VirusBuster 12.67.3.0 2010.10.05 -
MD5: 3967aeee12073446c4fb4af0b681f0fa
SHA1: f17b1f85fa7eafe33b105a02cb593d1f45dbdf30
SHA256: 6d5726709b97ef935e04cfedf1bebb6c308b19217254eb572793f4191636bcb6
File size: 22040 bytes
Scan date: 2010-10-05 15:08:31 (UTC)
"Antivirus", "Version", "Last update", "Result"
"AhnLab-V3", "2010.10.05.00", "2010.10.04", "-"
"AntiVir", "7.10.12.135", "2010.10.05", "-"
"Antiy-AVL", "2.0.3.7", "2010.10.05", "-"
"Authentium", "5.2.0.5", "2010.10.05", "-"
"Avast", "4.8.1351.0", "2010.10.05", "-"
"Avast5", "5.0.594.0", "2010.10.05", "-"
"AVG", "9.0.0.851", "2010.10.05", "-"
"BitDefender", "7.2", "2010.10.05", "-"
"CAT-QuickHeal", "11.00", "2010.10.05", "-"
"ClamAV", "0.96.2.0-git", "2010.10.05", "-"
"Comodo", "6289", "2010.10.05", "-"
"DrWeb", "5.0.2.03300", "2010.10.05", "-"
"Emsisoft", "[removed]", "2010.10.05", "-"
"eSafe", "7.0.17.0", "2010.10.03", "-"
"eTrust-Vet", "36.1.7893", "2010.10.05", "-"
"F-Prot", "4.6.2.117", "2010.10.04", "-"
"F-Secure", "9.0.15370.0", "2010.10.05", "-"
"Fortinet", "4.2.249.0", "2010.10.05", "-"
"GData", "21", "2010.10.05", "-"
"Ikarus", "T3.[removed]", "2010.10.05", "-"
"Jiangmin", "13.0.900", "2010.10.03", "-"
"K7AntiVirus", "9.63.2672", "2010.10.04", "-"
"Kaspersky", "7.0.0.125", "2010.10.05", "-"
"McAfee", "5.400.0.1158", "2010.10.05", "-"
"McAfee-GW-Edition", "2010.1C", "2010.10.05", "-"
"Microsoft", "1.6201", "2010.10.05", "-"
"NOD32", "5505", "2010.10.05", "-"
"Norman", "6.06.07", "2010.10.05", "-"
"nProtect", "2010-10-05.02", "2010.10.05", "-"
"Panda", "10.0.2.7", "2010.10.05", "-"
"PCTools", "[removed]", "2010.10.02", "-"
"Prevx", "3.0", "2010.10.05", "-"
"Rising", "22.67.02.07", "2010.09.30", "-"
"Sophos", "4.58.0", "2010.10.05", "-"
"Sunbelt", "6987", "2010.10.05", "-"
"SUPERAntiSpyware", "4.40.0.1006", "2010.10.05", "-"
"Symantec", "20101.2.0.161", "2010.10.05", "-"
"TheHacker", "6.7.0.1.048", "2010.10.04", "-"
"TrendMicro", "9.120.0.1004", "2010.10.05", "-"
"TrendMicro-HouseCall", "9.120.0.1004", "2010.10.05", "-"
"VBA32", "[removed]", "2010.10.05", "-"
"ViRobot", "2010.10.4.4074", "2010.10.05", "-"
"VirusBuster", "[removed]", "2010.10.05", "-"
"MD5", "3967aeee12073446c4fb4af0b681f0fa"
"SHA1", "f17b1f85fa7eafe33b105a02cb593d1f45dbdf30"
"SHA256", "6d5726709b97ef935e04cfedf1bebb6c308b19217254eb572793f4191636bcb6"
"File size", "22040 bytes"
"Scan date", "2010-10-05 15:08:31 (UTC)"









































































































































































































































































Antivirus Version Last update Result
AhnLab-V3 2010.10.05.00 2010.10.04 -
AntiVir 7.10.12.135 2010.10.05 -
Antiy-AVL 2.0.3.7 2010.10.05 -
Authentium 5.2.0.5 2010.10.05 -
Avast 4.8.1351.0 2010.10.05 -
Avast5 5.0.594.0 2010.10.05 -
AVG 9.0.0.851 2010.10.05 -
BitDefender 7.2 2010.10.05 -
CAT-QuickHeal 11.00 2010.10.05 -
ClamAV 0.96.2.0-git 2010.10.05 -
Comodo 6289 2010.10.05 -
DrWeb 5.0.2.03300 2010.10.05 -
Emsisoft 5.0.0.50 2010.10.05 -
eSafe 7.0.17.0 2010.10.03 -
eTrust-Vet 36.1.7893 2010.10.05 -
F-Prot 4.6.2.117 2010.10.04 -
F-Secure 9.0.15370.0 2010.10.05 -
Fortinet 4.2.249.0 2010.10.05 -
GData 21 2010.10.05 -
Ikarus T3.1.1.90.0 2010.10.05 -
Jiangmin 13.0.900 2010.10.03 -
K7AntiVirus 9.63.2672 2010.10.04 -
Kaspersky 7.0.0.125 2010.10.05 -
McAfee 5.400.0.1158 2010.10.05 -
McAfee-GW-Edition 2010.1C 2010.10.05 -
Microsoft 1.6201 2010.10.05 -
NOD32 5505 2010.10.05 -
Norman 6.06.07 2010.10.05 -
nProtect 2010-10-05.02 2010.10.05 -
Panda 10.0.2.7 2010.10.05 -
PCTools 7.0.3.5 2010.10.02 -
Prevx 3.0 2010.10.05 -
Rising 22.67.02.07 2010.09.30 -
Sophos 4.58.0 2010.10.05 -
Sunbelt 6987 2010.10.05 -
SUPERAntiSpyware 4.40.0.1006 2010.10.05 -
Symantec 20101.2.0.161 2010.10.05 -
TheHacker 6.7.0.1.048 2010.10.04 -
TrendMicro 9.120.0.1004 2010.10.05 -
TrendMicro-HouseCall 9.120.0.1004 2010.10.05 -
VBA32 3.12.14.1 2010.10.05 -
ViRobot 2010.10.4.4074 2010.10.05 -
VirusBuster 12.67.3.0 2010.10.05 -





















Additional information
MD5: 3967aeee12073446c4fb4af0b681f0fa
SHA1: f17b1f85fa7eafe33b105a02cb593d1f45dbdf30
SHA256: 6d5726709b97ef935e04cfedf1bebb6c308b19217254eb572793f4191636bcb6
File size: 22040 bytes
Scan date: 2010-10-05 15:08:31 (UTC)

Antivirus results
AhnLab-V3 - 2010.10.05.00 - 2010.10.04 - -
AntiVir - 7.10.12.135 - 2010.10.05 - -
Antiy-AVL - 2.0.3.7 - 2010.10.05 - -
Authentium - 5.2.0.5 - 2010.10.05 - -
Avast - 4.8.1351.0 - 2010.10.05 - -
Avast5 - 5.0.594.0 - 2010.10.05 - -
AVG - 9.0.0.851 - 2010.10.05 - -
BitDefender - 7.2 - 2010.10.05 - -
CAT-QuickHeal - 11.00 - 2010.10.05 - -
ClamAV - 0.96.2.0-git - 2010.10.05 - -
Comodo - 6289 - 2010.10.05 - -
DrWeb - 5.0.2.03300 - 2010.10.05 - -
Emsisoft - 5.0.0.50 - 2010.10.05 - -
eSafe - 7.0.17.0 - 2010.10.03 - -
eTrust-Vet - 36.1.7893 - 2010.10.05 - -
F-Prot - 4.6.2.117 - 2010.10.04 - -
F-Secure - 9.0.15370.0 - 2010.10.05 - -
Fortinet - 4.2.249.0 - 2010.10.05 - -
GData - 21 - 2010.10.05 - -
Ikarus - T3.1.1.90.0 - 2010.10.05 - -
Jiangmin - 13.0.900 - 2010.10.03 - -
K7AntiVirus - 9.63.2672 - 2010.10.04 - -
Kaspersky - 7.0.0.125 - 2010.10.05 - -
McAfee - 5.400.0.1158 - 2010.10.05 - -
McAfee-GW-Edition - 2010.1C - 2010.10.05 - -
Microsoft - 1.6201 - 2010.10.05 - -
NOD32 - 5505 - 2010.10.05 - -
Norman - 6.06.07 - 2010.10.05 - -
nProtect - 2010-10-05.02 - 2010.10.05 - -
Panda - 10.0.2.7 - 2010.10.05 - -
PCTools - [removed] - 2010.10.02 - -
Prevx - 3.0 - 2010.10.05 - -
Rising - 22.67.02.07 - 2010.09.30 - -
Sophos - 4.58.0 - 2010.10.05 - -
Sunbelt - 6987 - 2010.10.05 - -
SUPERAntiSpyware - 4.40.0.1006 - 2010.10.05 - -
Symantec - 20101.2.0.161 - 2010.10.05 - -
TheHacker - 6.7.0.1.048 - 2010.10.04 - -
TrendMicro - 9.120.0.1004 - 2010.10.05 - -
TrendMicro-HouseCall - 9.120.0.1004 - 2010.10.05 - -
VBA32 - [removed] - 2010.10.05 - -
ViRobot - 2010.10.4.4074 - 2010.10.05 - -
VirusBuster - 12.67.3.0 - 2010.10.05 - -
File info:
MD5: 3967aeee12073446c4fb4af0b681f0fa
SHA1: f17b1f85fa7eafe33b105a02cb593d1f45dbdf30
SHA256: 6d5726709b97ef935e04cfedf1bebb6c308b19217254eb572793f4191636bcb6
File size: 22040 bytes
Scan date: 2010-10-05 15:08:31 (UTC)

• Table
• Tabulated
• CSV
• HTML
• BBCode
• Show positives only
Antivirus Version Last update Result
AhnLab-V3 2010.10.05.00 2010.10.04 -
AntiVir 7.10.12.135 2010.10.05 -
Antiy-AVL 2.0.3.7 2010.10.05 -
Authentium 5.2.0.5 2010.10.05 -
Avast 4.8.1351.0 2010.10.05 -
Avast5 5.0.594.0 2010.10.05 -
AVG 9.0.0.851 2010.10.05 -
BitDefender 7.2 2010.10.05 -
CAT-QuickHeal 11.00 2010.10.05 -
ClamAV 0.96.2.0-git 2010.10.05 -
Comodo 6290 2010.10.05 -
DrWeb 5.0.2.03300 2010.10.05 -
Emsisoft 5.0.0.50 2010.10.05 -
eSafe 7.0.17.0 2010.10.03 -
eTrust-Vet 36.1.7893 2010.10.05 -
F-Prot 4.6.2.117 2010.10.04 -
F-Secure 9.0.15370.0 2010.10.05 -
Fortinet 4.2.249.0 2010.10.05 -
GData 21 2010.10.05 -
Ikarus T3.1.1.90.0 2010.10.05 -
Jiangmin 13.0.900 2010.10.03 -
K7AntiVirus 9.63.2680 2010.10.05 -
Kaspersky 7.0.0.125 2010.10.05 -
McAfee 5.400.0.1158 2010.10.05 -
McAfee-GW-Edition 2010.1C 2010.10.05 -
Microsoft 1.6201 2010.10.05 -
NOD32 5505 2010.10.05 -
Norman 6.06.07 2010.10.05 -
nProtect 2010-10-05.02 2010.10.05 -
Panda 10.0.2.7 2010.10.05 -
PCTools 7.0.3.5 2010.10.02 -
Prevx 3.0 2010.10.05 -
Rising 22.67.02.07 2010.09.30 -
Sophos 4.58.0 2010.10.05 -
Sunbelt 6987 2010.10.05 -
SUPERAntiSpyware 4.40.0.1006 2010.10.05 -
Symantec 20101.2.0.161 2010.10.05 -
TheHacker 6.7.0.1.048 2010.10.04 -
TrendMicro 9.120.0.1004 2010.10.05 -
TrendMicro-HouseCall 9.120.0.1004 2010.10.05 -
VBA32 3.12.14.1 2010.10.05 -
ViRobot 2010.10.4.4074 2010.10.05 -
VirusBuster 12.67.3.0 2010.10.05 -
MD5: 1f3e83a56b5177a22ba9594a37f986be
SHA1: 2ee66b8e0318a4278fa393a03215322be6391a67
SHA256: b8e00e308e12d6625d90c7d62b3620cea36ae9f5d44de1635136496a6f07690a
File size: 249270 bytes
Scan date: 2010-10-05 15:31:41 (UTC)
Antivirus Version Last update Result
AhnLab-V3 2010.10.05.00 2010.10.04 -
AntiVir 7.10.12.135 2010.10.05 -
Antiy-AVL 2.0.3.7 2010.10.05 -
Authentium 5.2.0.5 2010.10.05 -
Avast 4.8.1351.0 2010.10.05 -
Avast5 5.0.594.0 2010.10.05 -
AVG 9.0.0.851 2010.10.05 -
BitDefender 7.2 2010.10.05 -
CAT-QuickHeal 11.00 2010.10.05 -
ClamAV 0.96.2.0-git 2010.10.05 -
Comodo 6290 2010.10.05 -
DrWeb 5.0.2.03300 2010.10.05 -
Emsisoft 5.0.0.50 2010.10.05 -
eSafe 7.0.17.0 2010.10.03 -
eTrust-Vet 36.1.7893 2010.10.05 -
F-Prot 4.6.2.117 2010.10.04 -
F-Secure 9.0.15370.0 2010.10.05 -
Fortinet 4.2.249.0 2010.10.05 -
GData 21 2010.10.05 -
Ikarus T3.1.1.90.0 2010.10.05 -
Jiangmin 13.0.900 2010.10.03 -
K7AntiVirus 9.63.2680 2010.10.05 -
Kaspersky 7.0.0.125 2010.10.05 -
McAfee 5.400.0.1158 2010.10.05 -
McAfee-GW-Edition 2010.1C 2010.10.05 -
Microsoft 1.6201 2010.10.05 -
NOD32 5505 2010.10.05 -
Norman 6.06.07 2010.10.05 -
nProtect 2010-10-05.02 2010.10.05 -
Panda 10.0.2.7 2010.10.05 -
PCTools 7.0.3.5 2010.10.02 -
Prevx 3.0 2010.10.05 -
Rising 22.67.02.07 2010.09.30 -
Sophos 4.58.0 2010.10.05 -
Sunbelt 6987 2010.10.05 -
SUPERAntiSpyware 4.40.0.1006 2010.10.05 -
Symantec 20101.2.0.161 2010.10.05 -
TheHacker 6.7.0.1.048 2010.10.04 -
TrendMicro 9.120.0.1004 2010.10.05 -
TrendMicro-HouseCall 9.120.0.1004 2010.10.05 -
VBA32 3.12.14.1 2010.10.05 -
ViRobot 2010.10.4.4074 2010.10.05 -
VirusBuster 12.67.3.0 2010.10.05 -
MD5: 1f3e83a56b5177a22ba9594a37f986be
SHA1: 2ee66b8e0318a4278fa393a03215322be6391a67
SHA256: b8e00e308e12d6625d90c7d62b3620cea36ae9f5d44de1635136496a6f07690a
File size: 249270 bytes
Scan date: 2010-10-05 15:31:41 (UTC)
"Antivirus", "Version", "Last update", "Result"
"AhnLab-V3", "2010.10.05.00", "2010.10.04", "-"
"AntiVir", "7.10.12.135", "2010.10.05", "-"
"Antiy-AVL", "2.0.3.7", "2010.10.05", "-"
"Authentium", "5.2.0.5", "2010.10.05", "-"
"Avast", "4.8.1351.0", "2010.10.05", "-"
"Avast5", "5.0.594.0", "2010.10.05", "-"
"AVG", "9.0.0.851", "2010.10.05", "-"
"BitDefender", "7.2", "2010.10.05", "-"
"CAT-QuickHeal", "11.00", "2010.10.05", "-"
"ClamAV", "0.96.2.0-git", "2010.10.05", "-"
"Comodo", "6290", "2010.10.05", "-"
"DrWeb", "5.0.2.03300", "2010.10.05", "-"
"Emsisoft", "[removed]", "2010.10.05", "-"
"eSafe", "7.0.17.0", "2010.10.03", "-"
"eTrust-Vet", "36.1.7893", "2010.10.05", "-"
"F-Prot", "4.6.2.117", "2010.10.04", "-"
"F-Secure", "9.0.15370.0", "2010.10.05", "-"
"Fortinet", "4.2.249.0", "2010.10.05", "-"
"GData", "21", "2010.10.05", "-"
"Ikarus", "T3.[removed]", "2010.10.05", "-"
"Jiangmin", "13.0.900", "2010.10.03", "-"
"K7AntiVirus", "9.63.2680", "2010.10.05", "-"
"Kaspersky", "7.0.0.125", "2010.10.05", "-"
"McAfee", "5.400.0.1158", "2010.10.05", "-"
"McAfee-GW-Edition", "2010.1C", "2010.10.05", "-"
"Microsoft", "1.6201", "2010.10.05", "-"
"NOD32", "5505", "2010.10.05", "-"
"Norman", "6.06.07", "2010.10.05", "-"
"nProtect", "2010-10-05.02", "2010.10.05", "-"
"Panda", "10.0.2.7", "2010.10.05", "-"
"PCTools", "[removed]", "2010.10.02", "-"
"Prevx", "3.0", "2010.10.05", "-"
"Rising", "22.67.02.07", "2010.09.30", "-"
"Sophos", "4.58.0", "2010.10.05", "-"
"Sunbelt", "6987", "2010.10.05", "-"
"SUPERAntiSpyware", "4.40.0.1006", "2010.10.05", "-"
"Symantec", "20101.2.0.161", "2010.10.05", "-"
"TheHacker", "6.7.0.1.048", "2010.10.04", "-"
"TrendMicro", "9.120.0.1004", "2010.10.05", "-"
"TrendMicro-HouseCall", "9.120.0.1004", "2010.10.05", "-"
"VBA32", "[removed]", "2010.10.05", "-"
"ViRobot", "2010.10.4.4074", "2010.10.05", "-"
"VirusBuster", "[removed]", "2010.10.05", "-"
"MD5", "1f3e83a56b5177a22ba9594a37f986be"
"SHA1", "2ee66b8e0318a4278fa393a03215322be6391a67"
"SHA256", "b8e00e308e12d6625d90c7d62b3620cea36ae9f5d44de1635136496a6f07690a"
"File size", "249270 bytes"
"Scan date", "2010-10-05 15:31:41 (UTC)"









































































































































































































































































Antivirus Version Last update Result
AhnLab-V3 2010.10.05.00 2010.10.04 -
AntiVir 7.10.12.135 2010.10.05 -
Antiy-AVL 2.0.3.7 2010.10.05 -
Authentium 5.2.0.5 2010.10.05 -
Avast 4.8.1351.0 2010.10.05 -
Avast5 5.0.594.0 2010.10.05 -
AVG 9.0.0.851 2010.10.05 -
BitDefender 7.2 2010.10.05 -
CAT-QuickHeal 11.00 2010.10.05 -
ClamAV 0.96.2.0-git 2010.10.05 -
Comodo 6290 2010.10.05 -
DrWeb 5.0.2.03300 2010.10.05 -
Emsisoft 5.0.0.50 2010.10.05 -
eSafe 7.0.17.0 2010.10.03 -
eTrust-Vet 36.1.7893 2010.10.05 -
F-Prot 4.6.2.117 2010.10.04 -
F-Secure 9.0.15370.0 2010.10.05 -
Fortinet 4.2.249.0 2010.10.05 -
GData 21 2010.10.05 -
Ikarus T3.1.1.90.0 2010.10.05 -
Jiangmin 13.0.900 2010.10.03 -
K7AntiVirus 9.63.2680 2010.10.05 -
Kaspersky 7.0.0.125 2010.10.05 -
McAfee 5.400.0.1158 2010.10.05 -
McAfee-GW-Edition 2010.1C 2010.10.05 -
Microsoft 1.6201 2010.10.05 -
NOD32 5505 2010.10.05 -
Norman 6.06.07 2010.10.05 -
nProtect 2010-10-05.02 2010.10.05 -
Panda 10.0.2.7 2010.10.05 -
PCTools 7.0.3.5 2010.10.02 -
Prevx 3.0 2010.10.05 -
Rising 22.67.02.07 2010.09.30 -
Sophos 4.58.0 2010.10.05 -
Sunbelt 6987 2010.10.05 -
SUPERAntiSpyware 4.40.0.1006 2010.10.05 -
Symantec 20101.2.0.161 2010.10.05 -
TheHacker 6.7.0.1.048 2010.10.04 -
TrendMicro 9.120.0.1004 2010.10.05 -
TrendMicro-HouseCall 9.120.0.1004 2010.10.05 -
VBA32 3.12.14.1 2010.10.05 -
ViRobot 2010.10.4.4074 2010.10.05 -
VirusBuster 12.67.3.0 2010.10.05 -





















Additional information
MD5: 1f3e83a56b5177a22ba9594a37f986be
SHA1: 2ee66b8e0318a4278fa393a03215322be6391a67
SHA256: b8e00e308e12d6625d90c7d62b3620cea36ae9f5d44de1635136496a6f07690a
File size: 249270 bytes
Scan date: 2010-10-05 15:31:41 (UTC)

Antivirus results
AhnLab-V3 - 2010.10.05.00 - 2010.10.04 - -
AntiVir - 7.10.12.135 - 2010.10.05 - -
Antiy-AVL - 2.0.3.7 - 2010.10.05 - -
Authentium - 5.2.0.5 - 2010.10.05 - -
Avast - 4.8.1351.0 - 2010.10.05 - -
Avast5 - 5.0.594.0 - 2010.10.05 - -
AVG - 9.0.0.851 - 2010.10.05 - -
BitDefender - 7.2 - 2010.10.05 - -
CAT-QuickHeal - 11.00 - 2010.10.05 - -
ClamAV - 0.96.2.0-git - 2010.10.05 - -
Comodo - 6290 - 2010.10.05 - -
DrWeb - 5.0.2.03300 - 2010.10.05 - -
Emsisoft - 5.0.0.50 - 2010.10.05 - -
eSafe - 7.0.17.0 - 2010.10.03 - -
eTrust-Vet - 36.1.7893 - 2010.10.05 - -
F-Prot - 4.6.2.117 - 2010.10.04 - -
F-Secure - 9.0.15370.0 - 2010.10.05 - -
Fortinet - 4.2.249.0 - 2010.10.05 - -
GData - 21 - 2010.10.05 - -
Ikarus - T3.1.1.90.0 - 2010.10.05 - -
Jiangmin - 13.0.900 - 2010.10.03 - -
K7AntiVirus - 9.63.2680 - 2010.10.05 - -
Kaspersky - 7.0.0.125 - 2010.10.05 - -
McAfee - 5.400.0.1158 - 2010.10.05 - -
McAfee-GW-Edition - 2010.1C - 2010.10.05 - -
Microsoft - 1.6201 - 2010.10.05 - -
NOD32 - 5505 - 2010.10.05 - -
Norman - 6.06.07 - 2010.10.05 - -
nProtect - 2010-10-05.02 - 2010.10.05 - -
Panda - 10.0.2.7 - 2010.10.05 - -
PCTools - [removed] - 2010.10.02 - -
Prevx - 3.0 - 2010.10.05 - -
Rising - 22.67.02.07 - 2010.09.30 - -
Sophos - 4.58.0 - 2010.10.05 - -
Sunbelt - 6987 - 2010.10.05 - -
SUPERAntiSpyware - 4.40.0.1006 - 2010.10.05 - -
Symantec - 20101.2.0.161 - 2010.10.05 - -
TheHacker - 6.7.0.1.048 - 2010.10.04 - -
TrendMicro - 9.120.0.1004 - 2010.10.05 - -
TrendMicro-HouseCall - 9.120.0.1004 - 2010.10.05 - -
VBA32 - [removed] - 2010.10.05 - -
ViRobot - 2010.10.4.4074 - 2010.10.05 - -
VirusBuster - 12.67.3.0 - 2010.10.05 - -
File info:
MD5: 1f3e83a56b5177a22ba9594a37f986be
SHA1: 2ee66b8e0318a4278fa393a03215322be6391a67
SHA256: b8e00e308e12d6625d90c7d62b3620cea36ae9f5d44de1635136496a6f07690a
File size: 249270 bytes
Scan date: 2010-10-05 15:31:41 (UTC)
Hello,

How are things running?


Scanning with MalwareBytes' Anti-Malware
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT:



Kaspersky Online Scanner
Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


NEXT:


Security Check
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Hello Sweet Tech…sorry you have not heard back from me. I was called out of town and did not take my laptop with me. I followed the instructions and the reports following are from the Malware scan and Security Scan. The Kaspersky online scanner ran for over an hour updating the database but the report was blank. There was nothing reported. Is that normal? It said at the end it had finished downloading prior to my going into my Computer.

Here are the reports requested:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4810

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11

10/13/2010 8:49:54 AM
mbam-log-2010-10-13 (08-49-54).txt

Scan type: Quick scan
Objects scanned: 164258
Time elapsed: 17 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 4
Files Infected: 9

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf} (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bec0} (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e} (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\kwinzy (Adware.Kwinzy) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\Yourprivacyguard (Rogue.Yourprivacyguard) -> Quarantined and deleted successfully.
C:\Documents and Settings\Thomas\Application Data\Yourprivacyguard (Rogue.Yourprivacyguard) -> Quarantined and deleted successfully.
C:\Documents and Settings\Thomas\Application Data\Yourprivacyguard\Logs (Rogue.Yourprivacyguard) -> Quarantined and deleted successfully.
C:\Documents and Settings\Thomas\Start Menu\Antivirus 2009 (Rogue.AntiVirus2008) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\All Users\Application Data\Yourprivacyguard\Abbr (Rogue.Yourprivacyguard) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Yourprivacyguard\ProdCode (Rogue.Yourprivacyguard) -> Quarantined and deleted successfully.
C:\Documents and Settings\Thomas\Application Data\Yourprivacyguard\Logs\update.log (Rogue.Yourprivacyguard) -> Quarantined and deleted successfully.
C:\Documents and Settings\Thomas\Start Menu\Antivirus 2009\Antivirus 2009.lnk (Rogue.AntiVirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\Thomas\Start Menu\Antivirus 2009\Uninstall Antivirus 2009.lnk (Rogue.AntiVirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\Thomas\Favorites\Error Cleaner.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\Thomas\Favorites\Privacy Protector.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\Thomas\Favorites\Spyware&Malware Protection.url (Rogue.Link) -> Quarantined and deleted successfully.

C:\WIND Results of screen317's Security Check version 0.99.5
Windows XP Service Pack 2
Out of date service pack!!
Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
Trend Micro Internet Security
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:

Ad-Aware
Malwarebytes' Anti-Malware
Java™ 6 Update 21
Adobe Flash Player 9.0.124.0
Adobe Reader 7.0.5
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Ad-Aware AAWService.exe is disabled!
Ad-Aware AAWTray.exe is disabled!
Trend Micro Internet Security UfSeAgnt.exe
Trend Micro Internet Security TMAS_OE TMAS_OEMon.exe
Trend Micro Internet Security SfCtlCom.exe
Trend Micro Internet Security TmPfw.exe
Trend Micro Internet Security TmProxy.exe
Trend Micro BM TMBMSRV.exe
````````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log```````````` OWS\rs.txt (Malware.Trace) -> Quarantined and deleted successfully.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI