This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ouch! I've got virus'

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,,
I've had a specialist look at my laptop and because I've loaded two virus programs (learned my lesson about that) and they canceled each other, I've been infected. The bad ones are identified as such: 99601cv.zip and similar. Could sure use some help cleaning my system. Here's my hijackthis file:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:27:40 PM, on 10/3/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe
C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Xobni\XobniService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\CA\CA Internet Security Suite\casc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Siber Systems\GoodSync\GoodSync.exe
C:\WINDOWS\explorer.exe
C:\Program Files\CA\CA Internet Security Suite\ccEvtMgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: (no name) - {7418E5F5-0E48-4144-8F92-5CA791C82396} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {DE713078-8012-4B75-92BA-398D4642A64B} - (no file)
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HttpWatch Basic - {F1F69322-008F-4895-B2BF-AD194219825A} - C:\Program Files\HttpWatch\httpwatchsc.dll
O3 - Toolbar: MP3Bar - {F6BD6330-76F8-44d9-B775-87614E2D8374} - C:\Program Files\Fiesta Download Manager\mp3bar.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\casc.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O8 - Extra context menu item: &MP3Bar - res://C:\Program Files\Fiesta Download Manager\mp3bar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {A573D71B-951B-4BAD-B8CC-708AE84769C9} - (no file)
O9 - Extra button: HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatch.dll
O9 - Extra 'Tools' menuitem: HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatch.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162929174093
O16 - DPF: {7D30109B-DD2B-4339-BE80-1CD48723C2BC} (LiveX(v6.0.1.0)) - http://bowwow2.serveftp.com/cab/Live.cab
O16 - DPF: {BC18E6DF-BE57-4580-93E8-F228F9A133AA} (MaxisSimCity4LotTeleX Control) - http://simcity.ea.com/exchange/lots/telepo…ty4LotTeleX.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe
O23 - Service: CA Common Scheduler Service (ccSchedulerSVC) - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Google Update Service (gupdate1c99eaad752f79c) (gupdate1c99eaad752f79c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe

–
End of file - 13586 bytes




Would sure appreciate any help.
Regards


Blind Lemon
Hello there, Blind Lemon

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in FIVE(5) days. :)
Hello there,

Please re-open HijackThis and click on Do a system scan only. Check the boxes next to all the entries listed below.(If exist)
O2 - BHO: (no name) - {7418E5F5-0E48-4144-8F92-5CA791C82396} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {DE713078-8012-4B75-92BA-398D4642A64B} - (no file)



Note : Do not worry if you are unable to find any of these entries, continue with the ones that you discovered. Now close all windows other than HijackThis, then click Fix checked. Close HijackThis then reboot.

===================================================
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
OTL log
GMER log

Good Day!
Here's the OTL text:

OTL logfile created on: 10/4/2010 9:11:30 AM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Doug Davis\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

766.00 Mb Total Physical Memory | 225.00 Mb Available Physical Memory | 29.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 65.94 Gb Total Space | 14.46 Gb Free Space | 21.92% Space Free | Partition Type: NTFS
Drive D: | 7.56 Gb Total Space | 0.43 Gb Free Space | 5.70% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 111.81 Gb Total Space | 34.21 Gb Free Space | 30.60% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Drive M: | 107.34 Gb Total Space | 11.82 Gb Free Space | 11.01% Space Free | Partition Type: NTFS
Drive N: | 149.05 Gb Total Space | 35.23 Gb Free Space | 23.64% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: DOUGDAVIS
Current User Name: Doug Davis
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Doug Davis\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccevtmgr.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
PRC - C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\HPQ\shared\HpqToaster.exe ()
PRC - C:\WINDOWS\system32\oodag.exe (O&O; Software GmbH)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Logitech\SetPoint\KEM.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\SetPoint\KHALMNPR.exe (Logitech Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Doug Davis\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcInj.dll (Logitech Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (ccSchedulerSVC) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
SRV - (XobniService) – C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
SRV - (UmxAgent) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
SRV - (UmxPol) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
SRV - (UmxCfg) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (EpsonBidirectionalService) – C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH)
SRV - (mi-raysat_3dsmax9_32) mental ray 3.5 Satellite (32-bit) – C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe ()
SRV - (O&O; Defrag) – C:\WINDOWS\system32\oodag.exe (O&O; Software GmbH)


========== Driver Services (SafeList) ==========

DRV - (C-Dilla) – C:\WINDOWS\System32\drivers\CDANT.SYS File not found
DRV - (KmxAMRT) – C:\WINDOWS\system32\DRIVERS\KmxAMRT.sys (CA)
DRV - (KmxAgent) – C:\WINDOWS\system32\drivers\KmxAgent.sys (CA)
DRV - (KmxCfg) – C:\WINDOWS\system32\drivers\KmxCfg.sys (CA)
DRV - (KmxStart) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys (CA)
DRV - (KmxAMVet) – C:\WINDOWS\system32\drivers\KmxAMVet.sys (Computer Associates International, Inc.)
DRV - (LVcKap) – C:\WINDOWS\system32\drivers\Lvckap.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (LVMVDrv) – C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWATI) – C:\WINDOWS\system32\drivers\HSFHWATI.sys (Conexant Systems, Inc.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (CAMCHALA) – C:\WINDOWS\system32\drivers\camc6hal.sys (Conexant Systems Inc.)
DRV - (CAMCAUD) – C:\WINDOWS\system32\drivers\camc6aud.sys (Conexant Systems Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (LHidUsbK) – C:\WINDOWS\system32\drivers\LHidUsbK.sys (Logitech, Inc.)
DRV - (LMouKE) – C:\WINDOWS\system32\drivers\LMouKE.Sys (Logitech, Inc.)
DRV - (LHidKe) – C:\WINDOWS\system32\drivers\LHidKE.Sys (Logitech, Inc.)
DRV - (cdrbsdrv) – C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?hl=en&source;=iglk"
FF - prefs.js..extensions.enabledItems: [removed]:3.4.4.118
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.6
FF - prefs.js..extensions.enabledItems: {317B5128-0B0B-49b2-B2DB-1E7560E16C74}:2.5.9
FF - prefs.js..extensions.enabledItems: {1E2593B2-E106-4697-BCE7-A9D30DE05D73}:6.2.40
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}:3.0.5
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.1
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: {a45e6b3a-725d-4b20-afde-e7486bfe317c}:3.5.4
FF - prefs.js..extensions.enabledItems: [removed]:0.6.20100805
FF - prefs.js..extensions.enabledItems: {69D30031-F4A8-452a-A5B3-5D6787C3C5CF}:3.6
FF - prefs.js..keyword.URL: "http://www.ask.com/web?&o;=13048&l;=dis&q;="


FF - HKLM\software\mozilla\Firefox\extensions\\{1E2593B2-E106-4697-BCE7-A9D30DE05D73}: C:\Program Files\HttpWatch\Firefox\ [2010/03/20 15:59:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/07/27 10:02:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 18:13:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/16 16:46:42 | 000,000,000 | —D | M]

[2008/09/08 09:45:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Extensions
[2010/10/03 14:28:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions
[2010/04/29 14:15:13 | 000,000,000 | —D | M] (Screengrab) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2006/09/08 08:35:20 | 000,000,000 | —D | M] (ColorGnome) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{1DEAE5AA-E19E-458b-9C8C-73CB651B9A58}(2)
[2010/05/03 09:23:42 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2006/04/26 21:13:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{2A10B180-05EF-11D9-8C50-444553540001}
[2010/07/06 17:50:52 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/11/24 10:36:22 | 000,000,000 | —D | M] (SeoQuake) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2010/05/12 11:02:50 | 000,000,000 | —D | M] (PDF Download) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2006/09/08 08:35:20 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{5c434b90-6318-11da-8cd6-0800200c9a69}(2)
[2009/03/24 11:50:10 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}(2)
[2010/03/09 08:53:35 | 000,000,000 | —D | M] (OldFactory Black) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{69D30031-F4A8-452a-A5B3-5D6787C3C5CF}
[2009/03/25 08:50:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{6C4BAFB6-2AC2-4405-A98D-546B55B3AE92}
[2009/03/24 11:50:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{6C4BAFB6-2AC2-4405-A98D-546B55B3AE92}(2)
[2010/05/06 17:46:40 | 000,000,000 | —D | M] (CookieSafe) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}
[2010/03/25 08:19:23 | 000,000,000 | —D | M] (Aluminium Kai 2) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{a45e6b3a-725d-4b20-afde-e7486bfe317c}
[2007/10/19 15:46:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{b1f0be5b-b66c-41c9-bfcc-f4ec657cd17b}
[2007/10/19 15:46:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{d9647170-b1d4-44fb-8e67-c498a2d9ef16}
[2009/11/03 13:16:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\[removed]
[2006/09/08 08:35:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\blueshift@shift(2).themes
[2006/04/26 21:18:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\[removed]
[2010/08/26 15:43:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\[removed]
[2010/08/26 15:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\[removed]
[2010/08/26 15:43:58 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2008/02/12 15:38:58 | 000,000,728 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (HttpWatch Basic) - {F1F69322-008F-4895-B2BF-AD194219825A} - C:\Program Files\HttpWatch\httpwatchsc.dll (Simtec Limited)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (MP3Bar) - {F6BD6330-76F8-44d9-B775-87614E2D8374} - C:\Program Files\Fiesta Download Manager\mp3bar.dll ()
O3 - HKLM\..\Toolbar: (no name) - SITEguard - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (MP3Bar) - {F6BD6330-76F8-44D9-B775-87614E2D8374} - C:\Program Files\Fiesta Download Manager\mp3bar.dll ()
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [RecGuard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe (Logitech Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &MP3Bar; - C:\Program Files\Fiesta Download Manager\mp3bar.dll ()
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll (Microsoft Corporation)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatch.dll (Simtec Limited)
O9 - Extra 'Tools' menuitem : HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1162929174093 (MUWebControl Class)
O16 - DPF: {7D30109B-DD2B-4339-BE80-1CD48723C2BC} http://bowwow2.serveftp.com/cab/Live.cab (LiveX(v6.0.1.0))
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {BC18E6DF-BE57-4580-93E8-F228F9A133AA} http://simcity.ea.com/exchange/lots/telepo…ty4LotTeleX.cab (MaxisSimCity4LotTeleX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
O18 - Protocol\Handler\mctp {d7b95390-b1c5-11d0-b111-0080c712fe82} - C:\Program Files\Microsoft ActiveSync\aatp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (C:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe) - C:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\System32\UmxWNP.dll (CA)
O24 - Desktop WallPaper: C:\Documents and Settings\Doug Davis\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Doug Davis\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 23:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 15:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2003/04/09 23:19:17 | 000,000,000 | -HS- | M] () - M:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{5b9ab4c4-efef-11de-bb08-000fb0f5b43b}\Shell\AutoRun\command - "" = G:\MI.exe – File not found
O33 - MountPoints2\{8991519a-3e61-11df-bb44-000fb0f5b43b}\Shell - "" = AutoRun
O33 - MountPoints2\{8991519a-3e61-11df-bb44-000fb0f5b43b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8991519a-3e61-11df-bb44-000fb0f5b43b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O; Software GmbH)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH)
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: MSACM.CEGSM - C:\WINDOWS\System32\mobileV.acm ()
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.GEOX - C:\WINDOWS\GeoCodec.dll (Geovision)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.MJPG - C:\WINDOWS\System32\Pvmjpg21.dll (Pegasus Imaging Corporation)
Drivers32: vidc.mpg2 - C:\WINDOWS\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mpg3 - C:\WINDOWS\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.mpg4 - C:\WINDOWS\mpg4c32.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027075282206720)

========== Files/Folders - Created Within 30 Days ==========

[2010/10/04 08:58:46 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Doug Davis\Desktop\OTL.exe
[2010/10/02 10:25:14 | 000,000,000 | RH-D | C] – C:\VProRecovery
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/04 08:58:46 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Doug Davis\Desktop\OTL.exe
[2010/10/04 08:54:02 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/04 08:50:32 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/04 08:50:26 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/04 08:49:51 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/10/04 08:49:39 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/04 08:49:32 | 803,459,072 | -HS- | M] () – C:\hiberfil.sys
[2010/10/04 08:49:27 | 000,492,663 | —- | M] () – C:\WINDOWS\System32\OODBS.lor
[2010/10/04 08:48:37 | 000,009,213 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2010/10/04 08:48:37 | 000,000,209 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2010/10/04 08:48:37 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2010/10/04 08:48:37 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2010/10/04 08:48:37 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2010/10/04 08:48:37 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2010/10/04 08:48:37 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2010/10/04 08:48:37 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2010/10/04 08:48:37 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2010/10/04 08:48:37 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2010/10/04 08:48:37 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2010/10/04 08:48:37 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2010/10/04 08:48:37 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2010/10/04 08:48:37 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2010/10/04 08:48:37 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2010/10/04 08:48:37 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2010/10/04 08:48:12 | 008,912,896 | —- | M] () – C:\Documents and Settings\Doug Davis\ntuser.dat
[2010/10/04 08:48:12 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Doug Davis\ntuser.ini
[2010/10/02 13:17:26 | 2204,320,768 | —- | M] () – C:\Outlook backup.pst
[2010/10/01 17:15:00 | 000,000,404 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/09/28 07:55:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/22 04:03:37 | 000,001,960 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/09/15 17:39:04 | 000,000,837 | —- | M] () – C:\Documents and Settings\Doug Davis\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2010/09/15 17:35:22 | 000,444,596 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/15 17:35:22 | 000,072,306 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/09/15 17:35:21 | 000,523,394 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/15 17:15:54 | 000,000,941 | —- | M] () – C:\WINDOWS\win.ini
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/03 14:56:14 | 803,459,072 | -HS- | C] () – C:\hiberfil.sys
[2010/09/22 04:03:37 | 000,001,960 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/09/15 16:24:16 | 2204,320,768 | —- | C] () – C:\Outlook backup.pst
[2010/04/27 13:35:22 | 000,000,106 | —- | C] () – C:\Documents and Settings\Doug Davis\Local Settings\Application Data\xobni_installer_updater.log
[2010/04/08 20:20:53 | 000,000,000 | —- | C] () – C:\WINDOWS\EEventManager.INI
[2010/04/07 08:59:55 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010/04/07 08:57:45 | 000,000,089 | —- | C] () – C:\WINDOWS\EPWF610.ini
[2009/10/12 09:32:16 | 000,038,476 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\Comma Separated Values (DOS).ADR
[2009/07/08 12:12:06 | 000,000,066 | —- | C] () – C:\WINDOWS\OWPATH.INI
[2009/02/03 18:00:57 | 000,022,100 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\Comma Separated Values (Windows).ADR
[2008/11/18 09:48:48 | 000,059,500 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/07/21 11:37:50 | 000,038,430 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\Tab Separated Values (Windows).ADR
[2007/10/11 19:59:24 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/07/26 17:06:22 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/07/26 17:03:02 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/07/16 09:00:33 | 000,000,649 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/04/02 16:44:11 | 000,000,049 | —- | C] () – C:\WINDOWS\Topo.INI
[2007/01/19 08:32:12 | 000,000,547 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\AutoGK.ini
[2006/12/08 06:50:14 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/12/08 06:47:54 | 001,159,168 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/10/10 17:40:18 | 000,335,872 | —- | C] () – C:\WINDOWS\System32\ldf252.dll
[2006/10/02 10:10:53 | 000,022,082 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\Microsoft Excel.ADR
[2006/06/28 13:21:47 | 000,000,199 | —- | C] () – C:\WINDOWS\swacnfg.ini
[2006/06/06 09:44:10 | 000,176,128 | —- | C] () – C:\WINDOWS\GeoCodecLib.dll
[2006/06/04 21:15:43 | 000,000,231 | —- | C] () – C:\WINDOWS\FORGXP32.INI
[2006/06/04 19:59:00 | 000,000,369 | —- | C] () – C:\WINDOWS\ULead32.ini
[2006/05/01 10:42:46 | 000,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2006/04/17 12:04:26 | 000,003,120 | —- | C] () – C:\WINDOWS\System32\fd20925b-ce57-42b1-bf58-6eb6683232a2.dll
[2006/04/13 10:49:26 | 000,001,397 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/11 20:30:36 | 000,000,488 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/04/09 16:44:01 | 000,094,720 | —- | C] () – C:\WINDOWS\System32\SH30W32.DLL
[2006/04/09 16:43:54 | 000,000,443 | —- | C] () – C:\WINDOWS\8272A4GS.INI
[2006/04/09 16:43:54 | 000,000,412 | —- | C] () – C:\WINDOWS\VIAPLAY.INI
[2006/04/09 16:43:54 | 000,000,000 | R— | C] () – C:\WINDOWS\VMARK.INI
[2006/04/09 16:39:30 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2006/04/09 16:39:27 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\adistres.dll
[2006/04/08 12:19:20 | 000,000,076 | —- | C] () – C:\WINDOWS\System32\PhotoRg2.ini
[2006/04/08 12:18:16 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\ereglb32.dll
[2006/04/08 12:18:16 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\ergint32.dll
[2006/04/08 11:21:45 | 000,373,248 | —- | C] () – C:\WINDOWS\EyeCand3.INI
[2006/04/07 15:05:26 | 000,000,074 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\wklnhst.dat
[2006/04/07 14:39:48 | 000,086,528 | —- | C] () – C:\Documents and Settings\Doug Davis\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/07 03:19:34 | 000,000,133 | —- | C] () – C:\Documents and Settings\Doug Davis\Local Settings\Application Data\fusioncache.dat
[2006/02/17 21:15:35 | 000,000,031 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/02/17 21:12:08 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/02/17 20:56:56 | 000,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/02/17 20:42:56 | 000,028,836 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/02/17 20:36:31 | 000,000,373 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/01/26 06:51:56 | 000,110,080 | —- | C] () – C:\WINDOWS\System32\nlame.dll
[2005/12/02 04:09:10 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/09 16:13:31 | 000,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/09 16:13:31 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2004/08/07 07:16:44 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/08/07 07:10:08 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/15 16:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[1997/06/13 19:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll

========== LOP Check ==========

[2010/08/05 10:43:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Applications
[2007/09/13 09:30:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/01/18 10:10:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2009/10/15 21:13:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2010/04/07 09:15:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2009/11/26 20:11:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fiesta Download Manager
[2010/07/27 10:07:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoodSync
[2006/04/09 20:35:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Links 2003
[2006/02/17 21:14:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2010/07/27 10:02:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2010/03/09 12:57:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\salesforce.com
[2009/05/18 14:02:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2010/10/03 14:37:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2006/05/08 17:16:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2007/03/21 10:34:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo
[2007/08/07 10:39:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ZILLAbar
[2010/06/08 08:31:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/27 18:06:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/03/09 12:57:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\.salesforce.com
[2006/10/10 17:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\ACD Systems
[2009/01/18 19:23:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Amazon
[2006/06/26 09:14:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Autodesk
[2006/10/23 09:41:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Axaware
[2009/04/10 15:52:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Bump Technologies, Inc
[2010/07/04 11:33:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\CoreFTP
[2010/04/08 08:15:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Epson
[2010/10/03 15:08:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\GoodSync
[2009/09/25 11:56:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\gtk-2.0
[2006/04/09 16:38:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\InterTrust
[2006/04/13 09:46:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Leadertech
[2007/08/12 15:46:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\LegalSounds
[2006/04/13 09:57:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\muvee Technologies
[2008/10/15 11:02:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\ntr
[2006/04/11 11:17:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\OLYMPUS
[2007/11/26 18:44:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\RipIt4Me
[2010/03/09 12:57:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\salesforce.com
[2006/04/08 17:08:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\STOPzilla!
[2006/04/07 15:05:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Template
[2010/02/12 16:49:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Trillian
[2006/04/08 10:45:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\TuneUp Software
[2010/02/03 16:35:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2010/10/01 17:15:00 | 000,000,404 | —- | M] () – C:\WINDOWS\Tasks\1-Click Maintenance.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/08/15 13:55:52 | 000,001,872 | —- | M] () – C:\3ds objects.3ds
[2007/08/15 13:53:44 | 000,029,684 | —- | M] () – C:\3ds objects.dwg
[2003/10/29 16:50:44 | 000,232,702 | R— | M] () – C:\3x5master.psd
[2010/06/07 09:54:50 | 000,000,087 | —- | M] () – C:\affid21.txt
[2007/06/05 08:16:21 | 000,125,529 | —- | M] () – C:\andireport.jpg
[2010/08/30 11:25:00 | 000,087,552 | —- | M] () – C:\Background Interview Questions.doc
[2006/10/21 11:59:45 | 073,728,476 | —- | M] () – C:\Bear1videofinal.mpg
[2006/11/07 16:46:27 | 000,000,389 | RHS- | M] () – C:\boot.ini
[2006/04/06 21:20:05 | 000,008,092 | —- | M] () – C:\caavsetup.log
[2009/09/13 10:28:55 | 000,056,250 | —- | M] () – C:\caavsetupLog.txt
[2010/02/01 08:46:16 | 000,836,147 | —- | M] () – C:\caisslog.txt
[2009/09/16 14:07:26 | 000,031,948 | —- | M] () – C:\castle4x3.jpg
[2009/09/16 14:08:11 | 000,003,998 | —- | M] () – C:\castlesmall.jpg
[2007/03/23 14:09:06 | 000,019,769 | —- | M] () – C:\ComboScan.txt
[2007/04/18 15:58:26 | 002,780,587 | —- | M] () – C:\coreftplite.exe
[2004/10/20 11:42:02 | 000,328,488 | —- | M] (InterMute Inc.) – C:\CWSInstall.exe
[2007/09/01 21:52:38 | 000,014,336 | —- | M] () – C:\Day 3.doc
[2007/05/10 16:28:00 | 000,000,000 | —- | M] () – C:\DFM_flyer.pdf
[2007/05/10 16:30:00 | 003,866,073 | —- | M] () – C:\DFM_flyer.pdf.sitx
[2008/10/08 14:53:41 | 000,100,864 | —- | M] () – C:\dougsdatabase.xls
[2010/06/03 13:50:54 | 000,001,098 | —- | M] () – C:\emagazines_IR_trackingpixel.txt
[2010/03/26 08:09:50 | 000,000,045 | —- | M] () – C:\error.log
[2008/11/22 12:40:41 | 000,179,940 | RHS- | M] () – C:\ExecSignature.txt
[2008/03/26 11:01:54 | 028,868,320 | —- | M] (Microsoft Corporation) – C:\FileFormatConverters.exe
[2010/06/17 10:59:16 | 000,000,174 | —- | M] () – C:\goodhk.txt
[2007/11/21 21:24:20 | 013,411,824 | —- | M] () – C:\Google_Earth_BZXV.exe
[2010/10/04 08:49:32 | 803,459,072 | -HS- | M] () – C:\hiberfil.sys
[2006/10/19 08:19:38 | 000,002,303 | -HS- | M] () – C:\hpqp.ini
[2007/06/01 09:37:55 | 000,674,470 | —- | M] () – C:\Image_1.jpg
[2009/05/03 13:45:19 | 000,014,219 | —- | M] () – C:\index.htm
[2006/04/08 11:20:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/01/03 14:12:14 | 000,000,812 | —- | M] () – C:\lmnwhys.txt
[2008/03/11 18:25:59 | 000,013,979 | —- | M] () – C:\Logfile.txt
[2009/06/22 14:27:54 | 003,561,744 | —- | M] (Malwarebytes Corporation ) – C:\mbam-setup.exe
[2006/04/08 11:20:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/07/21 09:46:41 | 000,192,225 | —- | M] () – C:\Newsletter Flyer.pdf
[2006/05/22 20:40:47 | 000,350,720 | —- | M] () – C:\notesforscience.doc
[2004/08/04 02:00:00 | 000,047,564 | RHS- | M] () – C:\ntdetect.com
[2004/08/04 02:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/10/02 13:17:26 | 2204,320,768 | —- | M] () – C:\Outlook backup.pst
[2010/10/04 08:49:27 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2008/09/08 09:54:24 | 000,024,576 | —- | M] () – C:\Real Estate Ad - 2.doc
[2006/05/12 15:49:06 | 000,003,300 | —- | M] () – C:\Rescued document.txt
[2007/06/18 11:35:41 | 000,177,306 | —- | M] () – C:\rick_doug.jpg
[2008/10/01 08:59:30 | 000,038,050 | RHS- | M] () – C:\SdHeuristic.txt
[2008/11/22 12:40:42 | 000,224,398 | RHS- | M] () – C:\SDSignature.txt
[2006/08/08 14:14:36 | 000,020,992 | —- | M] () – C:\seeking.doc
[2006/09/12 08:19:50 | 000,237,100 | —- | M] () – C:\seeking_example.jpg
[2006/04/12 17:41:34 | 000,001,260 | —- | M] () – C:\signaturefile.html
[2003/01/14 11:40:10 | 000,000,968 | —- | M] () – C:\signaturefile2.html
[2008/08/18 06:02:04 | 004,891,216 | —- | M] (Microsoft Corporation) – C:\Silverlight.2.0.exe
[2010/02/15 21:22:23 | 000,023,876 | —- | M] () – C:\SmartDog_logo1.cdr
[2010/03/08 20:56:46 | 000,004,741 | —- | M] () – C:\smarterchaos.htm
[1997/11/26 01:00:00 | 000,000,185 | —- | M] () – C:\spacer.gif
[2007/03/23 10:39:03 | 001,796,308 | —- | M] () – C:\spydetectorlaptopimage.tif
[2007/03/23 10:41:10 | 002,421,880 | —- | M] () – C:\spydetectorlaptopimage2.tif
[2007/02/03 13:54:00 | 000,582,870 | —- | M] () – C:\SuperBowl 41.bmp
[2010/03/23 11:53:13 | 000,208,896 | -H– | M] () – C:\SZKGFS.dat
[2009/04/06 16:21:08 | 023,878,327 | —- | M] () – C:\ToriPhysics720.wmv
[2009/04/06 13:44:34 | 097,661,850 | —- | M] () – C:\ToriPhysicsUT.mpg
[2010/06/10 15:56:57 | 000,579,597 | —- | M] () – C:\unlocker1.8.9.exe
[2007/12/27 17:07:33 | 005,103,912 | —- | M] () – C:\video.pass
[2007/11/08 14:45:33 | 000,539,580 | —- | M] () – C:\wccpatch.tif
[2009/05/10 17:32:00 | 000,725,422 | —- | M] () – C:\Wine Fest logo.eps
[2010/10/03 15:25:37 | 000,002,740 | —- | M] () – C:\winzip.log
[2007/06/11 15:22:00 | 000,024,064 | —- | M] () – C:\WOM Park Facility Reservation Form.doc
[2006/10/19 08:19:30 | 000,000,039 | —- | M] () – C:\XP_TV.ini

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >
[2005/09/24 02:49:16 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2004/08/07 06:57:38 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2010/07/09 08:31:14 | 000,082,184 | —- | M] (Microsoft Corporation.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\lmdippr8.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >
[2001/10/05 10:48:42 | 000,356,883 | —- | M] () – C:\WINDOWS\andreasautumnleaves.jpg
[2002/04/23 09:19:46 | 000,054,567 | —- | M] () – C:\WINDOWS\archifects.jpg
[2004/02/11 19:01:54 | 000,200,804 | —- | M] () – C:\WINDOWS\stevieloslonely.jpg
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/06 23:45:26 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/06 23:45:26 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2004/08/07 06:58:34 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/04/07 03:24:04 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Doug Davis\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/07 07:04:04 | 000,000,079 | —- | M] () – C:\Documents and Settings\Doug Davis\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/07/20 16:44:20 | 002,955,416 | —- | M] (Siber Systems) – C:\Documents and Settings\Doug Davis\Desktop\AiRoboForm.exe
[2009/11/08 12:37:33 | 008,084,968 | —- | M] (Mozilla) – C:\Documents and Settings\Doug Davis\Desktop\Firefox Setup 3.5.5.exe
[2010/02/19 09:15:00 | 008,327,264 | —- | M] (Mozilla) – C:\Documents and Settings\Doug Davis\Desktop\Firefox Setup 3.6.exe
[2010/03/24 11:34:17 | 000,121,864 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Documents and Settings\Doug Davis\Desktop\g2m_download.exe
[2010/03/20 15:58:12 | 009,789,720 | —- | M] (Simtec Limited) – C:\Documents and Settings\Doug Davis\Desktop\httpwatch.exe
[2010/08/05 10:43:04 | 017,005,320 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Doug Davis\Desktop\LMSetup.exe
[2010/04/03 14:49:04 | 007,803,872 | —- | M] (Ventis Media Inc. ) – C:\Documents and Settings\Doug Davis\Desktop\MediaMonkey_3.2.0.1294.exe
[2010/07/09 13:41:12 | 007,822,392 | —- | M] (Ventis Media Inc. ) – C:\Documents and Settings\Doug Davis\Desktop\MediaMonkey_3.2.1.1297.exe
[2010/10/04 08:58:46 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Doug Davis\Desktop\OTL.exe
[2010/03/09 12:50:53 | 011,532,520 | —- | M] (salesforce.com ) – C:\Documents and Settings\Doug Davis\Desktop\setup.exe
[2009/07/23 15:19:13 | 040,407,208 | —- | M] ( ) – C:\Documents and Settings\Doug Davis\Desktop\setup_7.0.0.290_23.07.2009_23-14.exe
[2009/05/30 17:20:51 | 042,529,012 | —- | M] (Logitech ) – C:\Documents and Settings\Doug Davis\Desktop\SqueezeCenter-7.3.2.exe
[2009/09/27 10:47:14 | 046,409,742 | —- | M] (Logitech ) – C:\Documents and Settings\Doug Davis\Desktop\SqueezeCenter-7.3.3.exe
[2010/08/30 14:03:28 | 001,052,224 | —- | M] (BillP Studios) – C:\Documents and Settings\Doug Davis\Desktop\wpsetup.exe
[2010/04/27 13:24:22 | 006,279,816 | —- | M] (Xobni) – C:\Documents and Settings\Doug Davis\Desktop\XobniSetup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >
[2010/03/24 11:32:13 | 000,072,080 | —- | M] () – C:\Documents and Settings\Doug Davis\g2mdlhlpx.exe

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2009/12/09 11:34:32 | 000,000,067 | -HS- | M] () – C:\Documents and Settings\Doug Davis\Cookies\desktop.ini
[2010/10/04 08:51:37 | 000,049,152 | -HS- | M] () – C:\Documents and Settings\Doug Davis\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >
[2007/06/26 23:10:26 | 000,317,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\inf\unregmp2.exe

< %SYSTEMROOT%\Installer\*.exe >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-15 23:15:59

========== Alternate Data Streams ==========

@Alternate Data Stream - 9978 bytes -> C:\rick_doug.jpg:AFP_Resource
@Alternate Data Stream - 8966 bytes -> C:\Image_1.jpg:AFP_Resource
@Alternate Data Stream - 60 bytes -> C:\XP_TV.ini:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\WOM Park Facility Reservation Form.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\wccpatch.tif:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\video.pass:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\TOPO!:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Temporary Items:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\temp:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\SuperBowl 41.bmp:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\spydetectorlaptopimage2.tif:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\spydetectorlaptopimage.tif:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\spacer.gif:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\signaturefile2.html:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\signaturefile.html:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\seeking_example.jpg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\seeking.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\rick_doug.jpg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Rescued document.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Reel Recovery Denver Post:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Program Files\WinZip:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\PhotoOptics:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\notesforscience.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Microsoft Shared:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Logfile.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Image_1.jpg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\I386:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\hp:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Google_Earth_BZXV.exe:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Downloads:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Doug's Personal:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\WINDOWS:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\ntuser.dat_BAK_39550:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\ntuser.dat_BAK_15779:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\LuResult.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\DesktopFolderDB:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\Desktop:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\divx:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\DFT:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\DFM_flyer.pdf:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\DFM_flyer.pdf.sitx:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\DesktopFolderDB:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\ddrd:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Day 3.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\CWSInstall.exe:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\coreftplite.exe:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\ComboScan.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\caavsetup.log:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Binaries:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Bentley_tkp:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Bentley:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Bear1videofinal.mpg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Archifects:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\andireport.jpg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\3DSMAX2.5:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\3ds objects.dwg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\3ds objects.3ds:AFP_AfpInfo
@Alternate Data Stream - 512 bytes -> C:\spacer.gif:CA_INOCULATEIT
@Alternate Data Stream - 14774 bytes -> C:\wccpatch.tif:AFP_Resource
< End of report >

Heres the Extra's text:

OTL Extras logfile created on: 10/4/2010 9:11:30 AM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Doug Davis\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

766.00 Mb Total Physical Memory | 225.00 Mb Available Physical Memory | 29.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 65.94 Gb Total Space | 14.46 Gb Free Space | 21.92% Space Free | Partition Type: NTFS
Drive D: | 7.56 Gb Total Space | 0.43 Gb Free Space | 5.70% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 111.81 Gb Total Space | 34.21 Gb Free Space | 30.60% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded
Drive M: | 107.34 Gb Total Space | 11.82 Gb Free Space | 11.01% Space Free | Partition Type: NTFS
Drive N: | 149.05 Gb Total Space | 35.23 Gb Free Space | 23.64% Space Free | Partition Type: NTFS
Unable to calculate disk information.

Computer Name: DOUGDAVIS
Current User Name: Doug Davis
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
.js [@ = JSFile] – C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe (Macromedia, Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
jsfile [open] – "C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\PROGRA~1\ACDSYS~1\ACDSee\ACDSee.exe" "%1" (ACD Systems, Ltd.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] – "C:\PROGRA~1\MEDIAM~1\MEDIAM~2.EXE" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] – "C:\PROGRA~1\MEDIAM~1\MEDIAM~2.EXE" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] – "C:\PROGRA~1\MEDIAM~1\MEDIAM~2.EXE" /ADD "%1" (Ventis Media Inc.)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"9000:TCP" = 9000:TCP:*:Enabled:SlimServer Web
"3483:UDP" = 3483:UDP:*:Enabled:SlimDiscovery
"3483:TCP" = 3483:TCP:*:Enabled:SlimServer Control
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe" = C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found
"C:\Program Files\Microsoft Games\Links 2003\LinksMMIII.exe" = C:\Program Files\Microsoft Games\Links 2003\LinksMMIII.exe:*:Enabled:Links 2003 – (Microsoft Corporation)
"C:\Program Files\WS_FTP Pro\FTP95PRO.EXE" = C:\Program Files\WS_FTP Pro\FTP95PRO.EXE:*:Enabled:WS_FTP 95 – (Ipswitch, Inc. 81 Hartwell Ave. Lexington, MA)
"C:\Program Files\STOPzilla!\STOPzilla.exe" = C:\Program Files\STOPzilla!\STOPzilla.exe:*:Enabled:Launch STOPzilla! – (iS3, Inc.)
"C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD" = C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD:*:Enabled:Age of Empires II – (Microsoft Corporation)
"C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe" = C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe:*:Enabled:Autodesk 3ds Max 9 32-bit – (Autodesk, Inc.)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:*:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:*:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\CA\CA Internet Security Suite\casecuritycenter.exe" = C:\Program Files\CA\CA Internet Security Suite\casecuritycenter.exe:*:Enabled:CA Security Center – File not found
"C:\Program Files\mSeven Software\mBackup\mBackup.exe" = C:\Program Files\mSeven Software\mBackup\mBackup.exe:*:Enabled:mBackup – (mSeven Software LLC)
"C:\Program Files\Epson Software\Event Manager\EEventManager.exe" = C:\Program Files\Epson Software\Event Manager\EEventManager.exe:*:Enabled:EEventManager.exe – (SEIKO EPSON CORPORATION)
"C:\Program Files\EpsonNet\EpsonNet Setup\tool09\ENEasyApp.exe" = C:\Program Files\EpsonNet\EpsonNet Setup\tool09\ENEasyApp.exe:*:Enabled:EpsonNet Setup – (SEIKO EPSON CORPORATION)
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe" = C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007 – (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01A3E75B-54C0-407F-8B95-B77705C7DCC4}" = AMRT
"{01B845D4-B73E-4CF7-A377-94BC7BB4F77B}" = HttpWatch Basic 6.2.40
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{09D8492A-C8E2-421E-927D-46800FB327A3}" = Wireless Home Network Setup
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}" = Epson FAX Utility
"{0F177611-70E6-4194-B2DD-CAA1B5EBC0F9}" = Bookmark Converter 3.2 (beta 2)
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{1CB34CE9-0E6B-493F-BB66-3425E5DF76E5}" = CP_CalendarTemplates1
"{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS
"{208071CD-45E0-49F7-A2BF-D7470F17EB73}" = mBackup
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{24BEBF2E-73F3-4599-840B-EDC612CCDD0D}" = Destinations
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 19
"{286F29AF-0BE2-4D5F-AB17-B7631A810553}" = muvee autoProducer 4.5
"{2A548002-9042-4083-A270-B67473DE1073}" = SkinsHP1
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{34F3FCF1-817B-4D61-B6AF-19D9486AFEA0}" = Unload
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{38151262-FAF8-4778-9AAB-33E90B60D8E9}" = CA Anti-Virus Plus
"{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}" = Macromedia Flash MX
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{3FE0CFAB-584A-4AA5-B8CD-C32284CFA308}" = RandMap
"{4041C245-7099-4C96-9738-5EBC23827B3C}" = BufferChm
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 2.00 C1
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 2.0
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
"{494D17B5-3369-4905-8C4B-80C972C5E0FF}" = CP_Panorama1Config
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4DA4012B-39AF-48c2-B23B-A4D570D233A6}" = cp_LightScribeConfig
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{53480370-6CA2-47EC-BC05-02B4B9271C31}" = O&O; Defrag Professional Edition
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{54F0998F-73C8-4b51-8286-FE903C231BED}" = cp_PosterPrintConfig
"{5783F2D7-0201-0409-0000-0060B0CE6BBA}" = AutoCAD 2004
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{611BD998-34B9-4DDA-00AE-0CB4632E86FA}" = SimCity 4 Rush Hour
"{661F85B9-FB7F-4884-BFCB-09C71930BA8F}" = ArcSoft MediaImpression for Kodak
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A3755E7-4FC6-4C2F-0D7D-6EDFFB5A7AA7}" = TweetDeck
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{766633B3-1AFA-44B6-A3FC-1DE991CD9C52}" = CP_Package_Basic1
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{79F8E1D4-36C1-439C-95FA-F695050B5B07}" = Sonic_PrimoSDK
"{7ABBE005-0263-4342-9C12-50E34383A49E}" = Circuit City Advantage Protection Plan
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = TIPCI
"{7F2F3F8B-2D57-48A3-99D0-1AC23D594C89}" = LightScribe 1.4.56.1
"{80AE27BA-B0ED-4288-A8B9-D8194BCF4115}" = cp_UpdateProjectsConfig
"{819EC1E4-7F1E-41E9-AE74-A11A5BAEAA7F}" = AttachmentOptions
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{868D7896-99D4-4513-BC62-2B3AD3E24926}" = TuneUp Utilities 2006
"{869C3062-4745-4949-B6C9-98AF24D89030}" = PhotoGallery
"{884705D8-575F-4F12-9FA6-E4558866A127}" = Spam Bully 2 for Outlook Express
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B4AB829-DFD3-436D-B808-D9733D76C590}" = Macromedia Dreamweaver MX
"{8DC069E7-893C-41E1-9442-DE89FEC33371}" = Xobni Core
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}" = Logitech QuickCam
"{9D4ABB0C-F60B-44A6-956C-A4A63D5495C9}" = CueTour
"{9FABFD28-000C-48AB-A0C7-82286B33EFA0}" = BumpTop
"{A01FC76F-CC09-4658-9E37-5C2F635EE708}" = TourSetup
"{A1C93B0F-A53C-406A-A681-EB3ED2EAB964}" = RedShift 5
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A7BF5269-3E74-11D5-B00F-00104B398D77}" = QuarkXPress 5.0
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B11E71BA-498C-42D4-9F1A-9D7A89D9DA61}" = CP_AtenaShokunin1Config
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B26B00DA-2E5D-4CF2-83C5-911198C0F009}" = GoodSync
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7F98125-4955-41E3-8A71-4CE11CE9C198}" = KODAK Gallery Upload Software
"{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"{BBD3BF67-5B89-4CBB-BA58-5818ED5F3290}" = cp_OnlineProjectsConfig
"{BC96BBA7-C634-460E-AD18-A0A994213F80}" = HP User Guides–System Recovery
"{BCC7E198-1D10-4B55-956E-550A196F8056}" = Microsoft Office Live Meeting 2007
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5}" = Microsoft Outlook Personal Folders Backup
"{CA72A82C-7DBC-4814-8CCB-E5BFAC59FAEF}" = ArcSoft MediaImpression for Kodak
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB326EC-8F40-47B2-BA22-BB092565D66F}" = Quick Launch Buttons 5.20 F2
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D17A2FDC-5C16-439C-A0E1-FF350079447E}" = HP User Guides 0026
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DF2035BE-5820-4965-BD97-7FAF8D4A7879}" = Microsoft_VC90_CRT_x86
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E96D4088-AAC5-437F-9E39-EC0E387897B4}" = Autodesk 3ds Max 9 32-bit
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{F165A635-9DFF-4F34-A669-49493E0A5B38}" = M2PMCEncoderZX
"{F82DF41F-4A57-4679-9907-D6430C6310B0}" = Salesforce Outlook Edition 3
"{FC8D25A7-FF1B-41BB-BB3B-9A06C0A60AE0}" = InstantShareDevices
"{FFFAE01B-466F-4C07-9821-A94FD753BDDA}" = EpsonNet Setup
"074EEF5F-3BE8-4112-B253-C5D6CDE2924C" = Zuma Deluxe from Hewlett-Packard Laptops (remove only)
"0E5266B4-9069-401A-93AE-5FF9F1712016" = Insaniquarium Deluxe from Hewlett-Packard Laptops (remove only)
"103EFD47-9F2C-4490-95DD-AE6C442AFB92" = SCRABBLE from Hewlett-Packard Laptops (remove only)
"320F055A-570F-4335-B026-16A836DB9549" = Final Drive Nitro from Hewlett-Packard Laptops (remove only)
"382C11F0-1A18-4F76-B8E0-15CA7F209C22" = Chuzzle Deluxe from Hewlett-Packard Laptops (remove only)
"384E0BF4-1E1F-45A6-B60E-42144A3F15CD" = Blackhawk Striker 2 from Hewlett-Packard Laptops (remove only)
"4C061F83-EE92-445A-A03F-184B0BD59242" = Jewel Quest from Hewlett-Packard Laptops (remove only)
"5658FB14-16A4-4DAE-946B-1457BE31572E" = Boggle Supreme from Hewlett-Packard Laptops (remove only)
"5758A0E8-A112-4A1D-82EC-EC72F7F16B88" = Lexibox Deluxe from Hewlett-Packard Laptops (remove only)
"5DE4D54F-AA79-43A4-9C8A-C173E7E2B025" = 5 Card Slingo from Hewlett-Packard Laptops (remove only)
"6E377D95-DF37-4E67-B64B-68C314600BCB" = Bejeweled 2 Deluxe from Hewlett-Packard Laptops (remove only)
"6ECB6EE6-92E1-4525-AF3B-3CE51A7C5F89" = FATE from Hewlett-Packard Laptops (remove only)
"7948472C-423F-4134-B68F-48D660A05D71" = Big Kahuna Reef from Hewlett-Packard Laptops (remove only)
"7A940E33-6993-404B-ABA6-ED62E8FBE615" = Bounce Symphony from Hewlett-Packard Laptops (remove only)
"7ED8A70C-9597-40BE-AEA0-0573182F1F51" = Super Granny from Hewlett-Packard Laptops (remove only)
"7F8C5718-1BA9-4AAE-96D2-2B04D05F2D54" = Polar Bowler from Hewlett-Packard Laptops (remove only)
"9F3399B2-9ED6-4339-84A2-686432638B86" = Blasterball 2 from Hewlett-Packard Laptops (remove only)
"ACDSee" = ACDSee
"ACT! 4.0 for Windows" = ACT! 4.0 for Windows
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"AI RoboForm" = AI RoboForm (All Users)
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"ATI Display Driver" = ATI Display Driver
"Autodesk Express Viewer" = Autodesk Express Viewer
"AutoGK" = Auto Gordian Knot 2.40
"AviSynth" = AviSynth 2.5
"B0202B33-E73D-4FCD-AC88-0B2971AFC116" = Slyder from Hewlett-Packard Laptops (remove only)
"B0769D17-E72A-4E87-A83F-1F7A3F080008" = Bookworm Deluxe from Hewlett-Packard Laptops (remove only)
"C264D692-8E15-4141-96A2-5621332E5DD0" = Slingo Deluxe from Hewlett-Packard Laptops (remove only)
"cciss_am" = CA Anti-Virus Plus
"CNXT_AUDIO" = Conexant AC-Link Audio
"CNXT_MODEM_PCI_VEN_1002&DEV;_4378" = Soft Data Fax Modem with SmartCP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Core FTP LE 1.3c" = Core FTP LE 1.3c
"D2E44AA4-8665-4490-A6C9-2D0744B47B27" = Polar Golfer from Hewlett-Packard Laptops (remove only)
"DED8E2B5-BA9F-448F-84E8-0AEF79876F95" = Snowboard SuperJam
"Director 8.5 Shockwave Studio" = Director 8.5 Shockwave Studio
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDx_is1" = DVDx
"E332F38A-75F6-4EF2-88CC-246E8A1CB5D7" = Oasis from Hewlett-Packard Laptops (remove only)
"E76A7EFF-7758-49EE-B3FA-9699830A2D6B" = Mah Jong Quest from Hewlett-Packard Laptops (remove only)
"E90E3AE9-73E4-4E5C-BB0F-673989A808D0" = Lemonade Tycoon 2 from Hewlett-Packard Laptops (remove only)
"E94C7046-2F7D-4D4D-B76F-C412DCCEAAC2" = Crystal Maze from Hewlett-Packard Laptops (remove only)
"EB88B6218325D2AB47CFFBF7170236B60A6198FF" = Windows Driver Package - Microsoft Corporation (usbvideo) Image (05/25/2007 1.0.3656.0)
"EF860173-4FB7-4DE1-8BE8-5400F05A0DC5" = Puzzle Express from Hewlett-Packard Laptops (remove only)
"EPSON PC-FAX Driver 2" = Epson PC-FAX Driver
"EPSON Scanner" = EPSON Scan
"EPSON WorkForce 610 Series" = EPSON WorkForce 610 Series Printer Uninstall
"Eye Candy 3" = Eye Candy 3
"F2566CC2-D4C4-44ED-A838-3F8288D8D3FE" = Flip Words from Hewlett-Packard Laptops (remove only)
"F-Manager" = Fiesta Download Manager
"HijackThis" = HijackThis 2.0.2
"HP Game Console" = HP Game Console and games
"HP Imaging Device Functions" = HP Imaging Device Functions 6.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.0
"HP Rhapsody" = HP Rhapsody
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"Kai's Power Tools 5" = Kai's Power Tools 5
"LegalSounds Music Downloader_is1" = LegalSounds Music Downloader 1.4
"LifeGlobe Sharks, Terrors of the Deep 2_is1" = LifeGlobe Sharks, Terrors of the Deep 2
"Links 2003 1.0" = Microsoft Links 2003
"LiveUpdate" = LiveUpdate
"lvdrivers_11.50" = Logitech QuickCam Driver Package
"MediaMonkey_is1" = MediaMonkey 3.2
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2006b" = Microsoft Money 2006
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NetworkAddonMod" = NetworkAddonMod Beta Version 2006.12.24
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"oggcodecs" = oggcodecs 0.71.0946
"PADI Open Water Diver Course" = PADI Open Water Diver Course
"PhotoTools 2.0" = Extensis PhotoTools 2.0
"PocketDVDStudio" = Pocket-DVD Studio(remove only)
"RealPlayer 6.0" = RealPlayer
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SkyPaint" = SkyPaint
"Songsheet Generator_is1" = Songsheet Generator 2.8
"Spam Bully 3 for Outlook" = Spam Bully 3 for Outlook [removed]
"Spam Bully for OE" = Spam Bully for OE [removed]
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemBooster V2.0" = SystemBooster V2.0
"Trillian" = Trillian
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"Unlocker" = Unlocker 1.8.9
"Uru - Ages Beyond Myst" = Uru - Ages Beyond Myst
"ViewBuild Professional" = ViewBuild Professional
"VobSub" = VobSub v2.23 (Remove Only)
"WIC" = Windows Imaging Component
"WildTangent CDA" = WildTangent Web Driver
"Winamp" = Winamp (remove only)
"Windows CE Services" = Microsoft ActiveSync 3.8
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XobniMain" = Xobni
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.5.0.452

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/3/2010 4:31:45 PM | Computer Name = DOUGDAVIS | Source = RaySat_3dsmax9_32 Server | ID = 131074
Description =

Error - 10/3/2010 4:33:53 PM | Computer Name = DOUGDAVIS | Source = UmxAgent | ID = 99
Description = Sync event client C:\Program Files\CA\CA Internet Security Suite\ccEvtMgr.exe
registration timeout

Error - 10/3/2010 4:34:49 PM | Computer Name = DOUGDAVIS | Source = UmxAgent | ID = 67
Description = Cannot send event. Process C:\Program Files\CA\CA Internet Security
Suite\ccEvtMgr.exe ended.

Error - 10/3/2010 4:35:49 PM | Computer Name = DOUGDAVIS | Source = UmxAgent | ID = 99
Description = Sync event client C:\Program Files\CA\CA Internet Security Suite\ccEvtMgr.exe
registration timeout

Error - 10/3/2010 4:56:24 PM | Computer Name = DOUGDAVIS | Source = RaySat_3dsmax9_32 Server | ID = 131074
Description =

Error - 10/3/2010 4:58:31 PM | Computer Name = DOUGDAVIS | Source = UmxAgent | ID = 99
Description = Sync event client C:\Program Files\CA\CA Internet Security Suite\ccEvtMgr.exe
registration timeout

Error - 10/3/2010 5:11:15 PM | Computer Name = DOUGDAVIS | Source = UmxAgent | ID = 67
Description = Cannot send event. Process C:\Program Files\CA\CA Internet Security
Suite\ccEvtMgr.exe ended.

Error - 10/3/2010 5:12:16 PM | Computer Name = DOUGDAVIS | Source = UmxAgent | ID = 99
Description = Sync event client C:\Program Files\CA\CA Internet Security Suite\ccEvtMgr.exe
registration timeout

Error - 10/4/2010 10:50:04 AM | Computer Name = DOUGDAVIS | Source = RaySat_3dsmax9_32 Server | ID = 131074
Description =

Error - 10/4/2010 10:52:28 AM | Computer Name = DOUGDAVIS | Source = UmxAgent | ID = 99
Description = Sync event client C:\Program Files\CA\CA Internet Security Suite\ccEvtMgr.exe
registration timeout

[ System Events ]
Error - 10/3/2010 4:54:36 PM | Computer Name = DOUGDAVIS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service CaCCProvSP
with arguments "" in order to run the server: {AACF4A1C-BC69-4359-9518-DF3F77E462BF}

Error - 10/3/2010 4:54:36 PM | Computer Name = DOUGDAVIS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service UmxCfg with
arguments "" in order to run the server: {8449273F-059F-4B7C-BF37-2E3C028E93D2}

Error - 10/3/2010 4:54:36 PM | Computer Name = DOUGDAVIS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service CaCCProvSP
with arguments "" in order to run the server: {AACF4A1C-BC69-4359-9518-DF3F77E462BF}

Error - 10/3/2010 4:54:36 PM | Computer Name = DOUGDAVIS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service UmxCfg with
arguments "" in order to run the server: {8449273F-059F-4B7C-BF37-2E3C028E93D2}

Error - 10/3/2010 4:54:42 PM | Computer Name = DOUGDAVIS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service CaCCProvSP
with arguments "" in order to run the server: {AACF4A1C-BC69-4359-9518-DF3F77E462BF}

Error - 10/3/2010 4:54:42 PM | Computer Name = DOUGDAVIS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service CaCCProvSP
with arguments "" in order to run the server: {AACF4A1C-BC69-4359-9518-DF3F77E462BF}

Error - 10/3/2010 4:55:00 PM | Computer Name = DOUGDAVIS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service UmxCfg with
arguments "" in order to run the server: {B8417502-7095-4D02-AF41-92134CEA5ED0}

Error - 10/3/2010 4:55:01 PM | Computer Name = DOUGDAVIS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service UmxPol with
arguments "-Service" in order to run the server: {4C89C3FD-5F94-4678-BBB5-F64759C3C54A}

Error - 10/3/2010 4:55:01 PM | Computer Name = DOUGDAVIS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/4/2010 6:09:26 AM | Computer Name = DOUGDAVIS | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.103 for the Network Card with network
address 0014A5719FAC has been denied by the DHCP server 192.168.0.254 (The DHCP
Server sent a DHCPNACK message).


< End of report >

Attachments:

Hi,

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *99601cv*
    *.zip
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

===================================================

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O33 - MountPoints2\{5b9ab4c4-efef-11de-bb08-000fb0f5b43b}\Shell\AutoRun\command - "" = G:\MI.exe – File not found
    O33 - MountPoints2\{8991519a-3e61-11df-bb44-000fb0f5b43b}\Shell - "" = AutoRun
    O33 - MountPoints2\{8991519a-3e61-11df-bb44-000fb0f5b43b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{8991519a-3e61-11df-bb44-000fb0f5b43b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    O33 - MountPoints2\D\Shell - "" = AutoRun
    O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\F\Shell - "" = AutoRun
    O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    
    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
SystemLook log
Fresh OTL log
OTL fix log
MBAM log

Good Day!
Hi Conspire, Thanks so much for helping me. I've attached System Look as it's too big to post and actually had to break it up in two files. I may have to send it in another response. OTL: All processes killed ========== OTL ========== Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b9ab4c4-efef-11de-bb08-000fb0f5b43b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5b9ab4c4-efef-11de-bb08-000fb0f5b43b}\ not found. File G:\MI.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8991519a-3e61-11df-bb44-000fb0f5b43b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8991519a-3e61-11df-bb44-000fb0f5b43b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8991519a-3e61-11df-bb44-000fb0f5b43b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8991519a-3e61-11df-bb44-000fb0f5b43b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8991519a-3e61-11df-bb44-000fb0f5b43b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8991519a-3e61-11df-bb44-000fb0f5b43b}\ not found. File F:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found. File F:\LaunchU3.exe not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Flash cache emptied: 41661 bytes User: Doug Davis ->Java cache emptied: 62778399 bytes ->Flash cache emptied: 293330 bytes User: LocalService User: NetworkService %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 1162769 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 165778577 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 11105994 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 1162277464 bytes Total Files Cleaned = 1,338.00 mb OTL by OldTimer - Version 3.2.14.1 log created on 10052010_081116 Files\Folders moved on Reboot… Registry entries deleted on Reboot… Maleware Bytes: Although I don't believe it. The specialist who look at my system saw some pretty nasty virus' down deep. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4747 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.11 10/5/2010 8:35:55 AM mbam-log-2010-10-05 (08-35-55).txt Scan type: Quick scan Objects scanned: 148946 Time elapsed: 12 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Attachments:

I assume you mean by just running a scan? Not a fix correct?

Here's the log file from a scan:

OTL logfile created on: 10/5/2010 9:43:00 AM - Run 2
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Doug Davis\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

766.00 Mb Total Physical Memory | 142.00 Mb Available Physical Memory | 19.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 47.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 65.94 Gb Total Space | 17.08 Gb Free Space | 25.90% Space Free | Partition Type: NTFS
Drive D: | 7.56 Gb Total Space | 0.43 Gb Free Space | 5.70% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DOUGDAVIS
Current User Name: Doug Davis
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Doug Davis\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE (Microsoft Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccevtmgr.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
PRC - C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\HPQ\shared\HpqToaster.exe ()
PRC - C:\WINDOWS\system32\oodag.exe (O&O; Software GmbH)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Logitech\SetPoint\KEM.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\SetPoint\KHALMNPR.exe (Logitech Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Doug Davis\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcInj.dll (Logitech Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (ccSchedulerSVC) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
SRV - (XobniService) – C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
SRV - (UmxAgent) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
SRV - (UmxPol) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
SRV - (UmxCfg) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (EpsonBidirectionalService) – C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH)
SRV - (mi-raysat_3dsmax9_32) mental ray 3.5 Satellite (32-bit) – C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe ()
SRV - (O&O; Defrag) – C:\WINDOWS\system32\oodag.exe (O&O; Software GmbH)


========== Driver Services (SafeList) ==========

DRV - (C-Dilla) – C:\WINDOWS\System32\drivers\CDANT.SYS File not found
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (KmxAMRT) – C:\WINDOWS\system32\DRIVERS\KmxAMRT.sys (CA)
DRV - (KmxAgent) – C:\WINDOWS\system32\drivers\KmxAgent.sys (CA)
DRV - (KmxCfg) – C:\WINDOWS\system32\drivers\KmxCfg.sys (CA)
DRV - (KmxStart) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys (CA)
DRV - (KmxAMVet) – C:\WINDOWS\system32\drivers\KmxAMVet.sys (Computer Associates International, Inc.)
DRV - (LVcKap) – C:\WINDOWS\system32\drivers\Lvckap.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (LVMVDrv) – C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWATI) – C:\WINDOWS\system32\drivers\HSFHWATI.sys (Conexant Systems, Inc.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (CAMCHALA) – C:\WINDOWS\system32\drivers\camc6hal.sys (Conexant Systems Inc.)
DRV - (CAMCAUD) – C:\WINDOWS\system32\drivers\camc6aud.sys (Conexant Systems Inc.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (LHidUsbK) – C:\WINDOWS\system32\drivers\LHidUsbK.sys (Logitech, Inc.)
DRV - (LMouKE) – C:\WINDOWS\system32\drivers\LMouKE.Sys (Logitech, Inc.)
DRV - (LHidKe) – C:\WINDOWS\system32\drivers\LHidKE.Sys (Logitech, Inc.)
DRV - (cdrbsdrv) – C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?hl=en&source;=iglk"
FF - prefs.js..extensions.enabledItems: [removed]:3.4.4.118
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.6
FF - prefs.js..extensions.enabledItems: {317B5128-0B0B-49b2-B2DB-1E7560E16C74}:2.5.9
FF - prefs.js..extensions.enabledItems: {1E2593B2-E106-4697-BCE7-A9D30DE05D73}:6.2.40
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}:3.0.5
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.1
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: {a45e6b3a-725d-4b20-afde-e7486bfe317c}:3.5.4
FF - prefs.js..extensions.enabledItems: [removed]:0.6.20100805
FF - prefs.js..extensions.enabledItems: {69D30031-F4A8-452a-A5B3-5D6787C3C5CF}:3.6
FF - prefs.js..keyword.URL: "http://www.ask.com/web?&o;=13048&l;=dis&q;="


FF - HKLM\software\mozilla\Firefox\extensions\\{1E2593B2-E106-4697-BCE7-A9D30DE05D73}: C:\Program Files\HttpWatch\Firefox\ [2010/03/20 15:59:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/07/27 10:02:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 18:13:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/16 16:46:42 | 000,000,000 | —D | M]

[2008/09/08 09:45:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Extensions
[2010/10/03 14:28:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions
[2010/04/29 14:15:13 | 000,000,000 | —D | M] (Screengrab) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2006/09/08 08:35:20 | 000,000,000 | —D | M] (ColorGnome) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{1DEAE5AA-E19E-458b-9C8C-73CB651B9A58}(2)
[2010/05/03 09:23:42 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2006/04/26 21:13:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{2A10B180-05EF-11D9-8C50-444553540001}
[2010/07/06 17:50:52 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/11/24 10:36:22 | 000,000,000 | —D | M] (SeoQuake) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2010/05/12 11:02:50 | 000,000,000 | —D | M] (PDF Download) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2006/09/08 08:35:20 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{5c434b90-6318-11da-8cd6-0800200c9a69}(2)
[2009/03/24 11:50:10 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}(2)
[2010/03/09 08:53:35 | 000,000,000 | —D | M] (OldFactory Black) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{69D30031-F4A8-452a-A5B3-5D6787C3C5CF}
[2009/03/25 08:50:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{6C4BAFB6-2AC2-4405-A98D-546B55B3AE92}
[2009/03/24 11:50:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{6C4BAFB6-2AC2-4405-A98D-546B55B3AE92}(2)
[2010/05/06 17:46:40 | 000,000,000 | —D | M] (CookieSafe) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}
[2010/03/25 08:19:23 | 000,000,000 | —D | M] (Aluminium Kai 2) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{a45e6b3a-725d-4b20-afde-e7486bfe317c}
[2007/10/19 15:46:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{b1f0be5b-b66c-41c9-bfcc-f4ec657cd17b}
[2007/10/19 15:46:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\{d9647170-b1d4-44fb-8e67-c498a2d9ef16}
[2009/11/03 13:16:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\[removed]
[2006/09/08 08:35:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\blueshift@shift(2).themes
[2006/04/26 21:18:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\[removed]
[2010/08/26 15:43:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\[removed]
[2010/08/26 15:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Doug Davis\Application Data\Mozilla\Firefox\Profiles\ttg83vup.default\extensions\[removed]
[2010/08/26 15:43:58 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2008/02/12 15:38:58 | 000,000,728 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (HttpWatch Basic) - {F1F69322-008F-4895-B2BF-AD194219825A} - C:\Program Files\HttpWatch\httpwatchsc.dll (Simtec Limited)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (MP3Bar) - {F6BD6330-76F8-44d9-B775-87614E2D8374} - C:\Program Files\Fiesta Download Manager\mp3bar.dll ()
O3 - HKLM\..\Toolbar: (no name) - SITEguard - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (MP3Bar) - {F6BD6330-76F8-44D9-B775-87614E2D8374} - C:\Program Files\Fiesta Download Manager\mp3bar.dll ()
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RecGuard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe (Logitech Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &MP3Bar; - C:\Program Files\Fiesta Download Manager\mp3bar.dll ()
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll (Microsoft Corporation)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatch.dll (Simtec Limited)
O9 - Extra 'Tools' menuitem : HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1162929174093 (MUWebControl Class)
O16 - DPF: {7D30109B-DD2B-4339-BE80-1CD48723C2BC} http://bowwow2.serveftp.com/cab/Live.cab (LiveX(v6.0.1.0))
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {BC18E6DF-BE57-4580-93E8-F228F9A133AA} http://simcity.ea.com/exchange/lots/telepo…ty4LotTeleX.cab (MaxisSimCity4LotTeleX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
O18 - Protocol\Handler\mctp {d7b95390-b1c5-11d0-b111-0080c712fe82} - C:\Program Files\Microsoft ActiveSync\aatp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (C:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe) - C:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\System32\UmxWNP.dll (CA)
O24 - Desktop WallPaper: C:\Documents and Settings\Doug Davis\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Doug Davis\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 23:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 15:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O; Software GmbH)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/10/05 08:22:15 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/10/05 08:22:12 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/10/05 08:22:12 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/10/05 08:20:41 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Doug Davis\Desktop\mbam-setup-1.46.exe
[2010/10/05 08:11:16 | 000,000,000 | —D | C] – C:\_OTL
[2010/10/04 08:58:46 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Doug Davis\Desktop\OTL.exe
[2010/10/02 10:25:14 | 000,000,000 | RH-D | C] – C:\VProRecovery

========== Files - Modified Within 30 Days ==========

[2010/10/05 09:54:17 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/05 08:52:11 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/05 08:52:07 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/05 08:51:53 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/10/05 08:51:51 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/05 08:51:48 | 803,459,072 | -HS- | M] () – C:\hiberfil.sys
[2010/10/05 08:51:43 | 000,493,536 | —- | M] () – C:\WINDOWS\System32\OODBS.lor
[2010/10/05 08:50:54 | 000,009,293 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2010/10/05 08:50:54 | 000,000,289 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2010/10/05 08:50:54 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2010/10/05 08:50:54 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2010/10/05 08:50:54 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2010/10/05 08:50:54 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2010/10/05 08:50:54 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2010/10/05 08:50:54 | 000,000,081 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2010/10/05 08:50:54 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2010/10/05 08:50:54 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2010/10/05 08:50:54 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2010/10/05 08:50:54 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2010/10/05 08:50:54 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2010/10/05 08:50:54 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2010/10/05 08:50:54 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2010/10/05 08:50:54 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2010/10/05 08:50:30 | 008,912,896 | —- | M] () – C:\Documents and Settings\Doug Davis\ntuser.dat
[2010/10/05 08:50:30 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Doug Davis\ntuser.ini
[2010/10/05 08:22:17 | 000,000,741 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/05 08:21:13 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Doug Davis\Desktop\mbam-setup-1.46.exe
[2010/10/05 07:57:11 | 000,075,264 | —- | M] () – C:\Documents and Settings\Doug Davis\Desktop\SystemLook.exe
[2010/10/05 07:55:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/10/04 09:19:13 | 000,293,376 | —- | M] () – C:\Documents and Settings\Doug Davis\Desktop\hxlty0k8.exe
[2010/10/04 08:58:46 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Doug Davis\Desktop\OTL.exe
[2010/10/02 13:17:26 | 2204,320,768 | —- | M] () – C:\Outlook backup.pst
[2010/10/01 17:15:00 | 000,000,404 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/09/22 04:03:37 | 000,001,960 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/09/15 17:39:04 | 000,000,837 | —- | M] () – C:\Documents and Settings\Doug Davis\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2010/09/15 17:35:22 | 000,444,596 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/15 17:35:22 | 000,072,306 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/09/15 17:35:21 | 000,523,394 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/15 17:15:54 | 000,000,941 | —- | M] () – C:\WINDOWS\win.ini

========== Files Created - No Company Name ==========

[2010/10/05 08:22:17 | 000,000,741 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/05 07:57:11 | 000,075,264 | —- | C] () – C:\Documents and Settings\Doug Davis\Desktop\SystemLook.exe
[2010/10/04 09:19:12 | 000,293,376 | —- | C] () – C:\Documents and Settings\Doug Davis\Desktop\hxlty0k8.exe
[2010/10/03 14:56:14 | 803,459,072 | -HS- | C] () – C:\hiberfil.sys
[2010/09/22 04:03:37 | 000,001,960 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/09/15 16:24:16 | 2204,320,768 | —- | C] () – C:\Outlook backup.pst
[2010/04/27 13:35:22 | 000,000,106 | —- | C] () – C:\Documents and Settings\Doug Davis\Local Settings\Application Data\xobni_installer_updater.log
[2010/04/08 20:20:53 | 000,000,000 | —- | C] () – C:\WINDOWS\EEventManager.INI
[2010/04/07 08:59:55 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010/04/07 08:57:45 | 000,000,089 | —- | C] () – C:\WINDOWS\EPWF610.ini
[2009/10/12 09:32:16 | 000,038,476 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\Comma Separated Values (DOS).ADR
[2009/07/08 12:12:06 | 000,000,066 | —- | C] () – C:\WINDOWS\OWPATH.INI
[2009/02/03 18:00:57 | 000,022,100 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\Comma Separated Values (Windows).ADR
[2008/11/18 09:48:48 | 000,059,500 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/07/21 11:37:50 | 000,038,430 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\Tab Separated Values (Windows).ADR
[2007/10/11 19:59:24 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/07/26 17:06:22 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/07/26 17:03:02 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/07/16 09:00:33 | 000,000,649 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/04/02 16:44:11 | 000,000,049 | —- | C] () – C:\WINDOWS\Topo.INI
[2007/01/19 08:32:12 | 000,000,547 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\AutoGK.ini
[2006/12/08 06:50:14 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/12/08 06:47:54 | 001,159,168 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/10/10 17:40:18 | 000,335,872 | —- | C] () – C:\WINDOWS\System32\ldf252.dll
[2006/10/02 10:10:53 | 000,022,082 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\Microsoft Excel.ADR
[2006/06/28 13:21:47 | 000,000,199 | —- | C] () – C:\WINDOWS\swacnfg.ini
[2006/06/06 09:44:10 | 000,176,128 | —- | C] () – C:\WINDOWS\GeoCodecLib.dll
[2006/06/04 21:15:43 | 000,000,231 | —- | C] () – C:\WINDOWS\FORGXP32.INI
[2006/06/04 19:59:00 | 000,000,369 | —- | C] () – C:\WINDOWS\ULead32.ini
[2006/05/01 10:42:46 | 000,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2006/04/17 12:04:26 | 000,003,120 | —- | C] () – C:\WINDOWS\System32\fd20925b-ce57-42b1-bf58-6eb6683232a2.dll
[2006/04/13 10:49:26 | 000,001,397 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/11 20:30:36 | 000,000,488 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/04/09 16:44:01 | 000,094,720 | —- | C] () – C:\WINDOWS\System32\SH30W32.DLL
[2006/04/09 16:43:54 | 000,000,443 | —- | C] () – C:\WINDOWS\8272A4GS.INI
[2006/04/09 16:43:54 | 000,000,412 | —- | C] () – C:\WINDOWS\VIAPLAY.INI
[2006/04/09 16:43:54 | 000,000,000 | R— | C] () – C:\WINDOWS\VMARK.INI
[2006/04/09 16:39:30 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2006/04/09 16:39:27 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\adistres.dll
[2006/04/08 12:19:20 | 000,000,076 | —- | C] () – C:\WINDOWS\System32\PhotoRg2.ini
[2006/04/08 12:18:16 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\ereglb32.dll
[2006/04/08 12:18:16 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\ergint32.dll
[2006/04/08 11:21:45 | 000,373,248 | —- | C] () – C:\WINDOWS\EyeCand3.INI
[2006/04/07 15:05:26 | 000,000,074 | —- | C] () – C:\Documents and Settings\Doug Davis\Application Data\wklnhst.dat
[2006/04/07 14:39:48 | 000,086,528 | —- | C] () – C:\Documents and Settings\Doug Davis\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/07 03:19:34 | 000,000,133 | —- | C] () – C:\Documents and Settings\Doug Davis\Local Settings\Application Data\fusioncache.dat
[2006/02/17 21:15:35 | 000,000,031 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/02/17 21:12:08 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/02/17 20:56:56 | 000,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/02/17 20:42:56 | 000,028,836 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/02/17 20:36:31 | 000,000,373 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/01/26 06:51:56 | 000,110,080 | —- | C] () – C:\WINDOWS\System32\nlame.dll
[2005/12/02 04:09:10 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/09 16:13:31 | 000,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/09 16:13:31 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2004/08/07 07:16:44 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/08/07 07:10:08 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/15 16:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[1997/06/13 19:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 9978 bytes -> C:\rick_doug.jpg:AFP_Resource
@Alternate Data Stream - 8966 bytes -> C:\Image_1.jpg:AFP_Resource
@Alternate Data Stream - 60 bytes -> C:\XP_TV.ini:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\WOM Park Facility Reservation Form.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\wccpatch.tif:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\video.pass:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\TOPO!:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Temporary Items:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\temp:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\SuperBowl 41.bmp:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\spydetectorlaptopimage2.tif:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\spydetectorlaptopimage.tif:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\spacer.gif:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\signaturefile2.html:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\signaturefile.html:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\seeking_example.jpg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\seeking.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\rick_doug.jpg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Rescued document.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Reel Recovery Denver Post:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Program Files\WinZip:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\PhotoOptics:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\notesforscience.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Microsoft Shared:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Logfile.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Image_1.jpg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\I386:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\hp:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Google_Earth_BZXV.exe:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Downloads:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Doug's Personal:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\WINDOWS:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\ntuser.dat_BAK_39550:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\ntuser.dat_BAK_15779:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\LuResult.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\DesktopFolderDB:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Doug Davis\Desktop:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\divx:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\DFT:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\DFM_flyer.pdf:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\DFM_flyer.pdf.sitx:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\DesktopFolderDB:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\ddrd:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Day 3.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\CWSInstall.exe:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\coreftplite.exe:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\ComboScan.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\caavsetup.log:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Binaries:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Bentley_tkp:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Bentley:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Bear1videofinal.mpg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Archifects:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\andireport.jpg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\3DSMAX2.5:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\3ds objects.dwg:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\3ds objects.3ds:AFP_AfpInfo
@Alternate Data Stream - 512 bytes -> C:\spacer.gif:CA_INOCULATEIT
@Alternate Data Stream - 14774 bytes -> C:\wccpatch.tif:AFP_Resource
< End of report >

Thanks much!
Hi,

I don't really see anything out of ordinary from the logs provided, please advice the symptoms or any abnormal behaviour that your computer has?

Please run this also

Kaspersky Online Scanner in IE

I recommend you to leave your computer on for the whole night as the scanning will take longer than you expected.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Please go to Kaspersky website and click on Kaspersky Online Scanner to perform an online scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

    [external image: Posted Image]
  • Please post this log in your next reply.

**Note

For clearer guidance, here's the animated tutorial :-

Click here

To optimize scanning time and produce a more sensible report for review:
  • Close any open programs.
  • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan. Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.
Hi Conspire, My system is running painfully slow, almost as if processes are running in the background. I took it in to specialists, they ran tests and found some bad virus' down deep in the registry, outlook, etc. Maybe we got them with what we did earlier? Also I just purchased new antivirus software called Vipre. I was using CA but wasn't happy with it. Could I go ahead, and uninstall the old and install the new at this point? Or should I run the Kapersky test first and get you that log? Thanks for all your advice.
Hi, Hold up on the uninstallation for CA and I need you to remove Ask Toolbar. I need you to navigate yourself to this directory and find the uninstallation file. If you couldn't find it, let me know. C:\Program Files\AskBarDis\unis000.exe And yes, please post the Kaspersky test for report. Thanks.
Okay, I'll hold off. I could not find this directory/file, it doesn't exist that I see: C:\Program Files\AskBarDis\unis000.exe Working on the Kapersky scan and will get you that when it's done. Thanks Blind Lemon

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI