This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Redirect/Fake Microsoft Security Alert/Intermittent Internet A

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've never done this before, so hopefully I did it correctly.

Thanks in advance for any help that can be given. I am a complete novice so you'll have to talk slowly and use small words. =)


—-
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:52:20 PM, on 10/12/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Documents and Settings\Dedrie Smith\Application Data\hotfix.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IObit\IObit Security 360\IS360tray.exe
C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
C:\Program Files\PC Tools Security\pctsTray.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\msdtc.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\AOL\1210613219\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Program Files\Common Files\AOL\1210613219\ee\anotify.exe
C:\Program Files\IObit\IObit Security 360\is360.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\spider.exe
c:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Dedrie Smith\Desktop\HiJackThis.exe
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\WINDOWS\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=3080419
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=3080419
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HttpWatch Basic - {F1F69322-008F-4895-B2BF-AD194219825A} - C:\Program Files\HttpWatch\httpwatchsc.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools Security\pctsTray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [NortonUpdateAgent] C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1\AOL.EXE" -b
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatch.dll
O9 - Extra 'Tools' menuitem: HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatch.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6796.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6BAB93B7-1917-4214-A7D2-874FA6DB4740} (AOL Newport Editor Ctrl) - http://o.aolcdn.com/pictures/ap/Resources/…ns.10.6.0.8.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab
O20 - AppInit_DLLs: c:\windows\system32\hisakite.dll c:\windows\system32\zudalure.dll c:\windows\system32\rovozefa.dll c:\windows\system32\bulimane.dll c:\windows\system32\moriyava.dll c:\windows\system32\supilime.dll c:\windows\system32\bevoweja.dll c:\windows\system32\kiyajeru.dll c:\windows\system32\dehaseha.dll c:\windows\system32\natulevo.dll c:\windows\system32\vomuganu.dll c:\windows\system32\mayonibe.dll c:\windows\system32\dogatidi.dll c:\windows\system32\pekuhedo.dll,pemobupo.dll
O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O21 - SSODL: bajiwupuh - {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - c:\windows\system32\teyufeve.dll (file missing)
O21 - SSODL: lolozimav - {289d3c51-2110-4650-8827-bb3d197b98ad} - c:\windows\system32\teyufeve.dll (file missing)
O21 - SSODL: fafejuvek - {c66ae819-8c35-4f9f-a643-63045cbebecf} - c:\windows\system32\moriyava.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: gahurihor - {018b02ca-d120-4bf3-be8d-a5c5d3e0b107} - (no file)
O22 - SharedTaskScheduler: mujuzedij - {002401d3-541f-4a08-a167-988bcde63d5e} - (no file)
O22 - SharedTaskScheduler: gahurihor - {b7be70e5-57a5-4aeb-a646-cd1061addc8c} - (no file)
O22 - SharedTaskScheduler: gahurihor - {0a42816f-86a2-4018-8e75-c7490c653054} - (no file)
O22 - SharedTaskScheduler: gahurihor - {95a847ee-8b44-460f-8d4e-6f242ea7682f} - (no file)
O22 - SharedTaskScheduler: mujuzedij - {b6c16ada-5ae0-431e-8797-578fa2dfd46f} - (no file)
O22 - SharedTaskScheduler: jugezatag - {da73c12d-3a42-4e3d-94f8-418ebe5fd807} - (no file)
O22 - SharedTaskScheduler: tokatiluy - {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - c:\windows\system32\teyufeve.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {289d3c51-2110-4650-8827-bb3d197b98ad} - c:\windows\system32\teyufeve.dll (file missing)
O22 - SharedTaskScheduler: gahurihor - {71a41e06-4419-479b-b44c-12ddf5528c1c} - (no file)
O22 - SharedTaskScheduler: tokatiluy - {1cf542fb-1517-4773-b966-ffd3dbab02dc} - (no file)
O22 - SharedTaskScheduler: mujuzedij - {d09ec36b-34df-4f50-a0ec-868f49b6094b} - (no file)
O22 - SharedTaskScheduler: tokatiluy - {6a1355d4-879e-4d83-b740-d59902b31b6c} - (no file)
O22 - SharedTaskScheduler: tokatiluy - {c66ae819-8c35-4f9f-a643-63045cbebecf} - c:\windows\system32\moriyava.dll (file missing)
O22 - SharedTaskScheduler: tokatiluy - {9675de18-8f52-4612-a8f9-c16451dbbefe} - (no file)
O22 - SharedTaskScheduler: gahurihor - {34c75cca-3d66-42ae-bf3f-f005b7bc0086} - (no file)
O22 - SharedTaskScheduler: tokatiluy - {298bd6e5-7f07-4e5a-b7a0-53082cab9b63} - (no file)
O22 - SharedTaskScheduler: jugezatag - {429a2580-6151-47fb-af1d-cc581c2bd535} - (no file)
O22 - SharedTaskScheduler: gahurihor - {f3e2d788-efd6-491f-a8b2-725b06fc5828} - (no file)
O22 - SharedTaskScheduler: gahurihor - {0b331eaa-ffcb-49bb-aeec-4919f87b373c} - (no file)
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools Security\pctsSvc.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 19348 bytes
Hello and welcome to What The Tech.

I am currently assessing your situation and will be back with a fix for your problem as soon as possible.

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this, click Options, then click Track this topic. Please select Immediate Email Notification for the topic subscription, then click Proceed.

Please be patient with me during this time.

Meanwhile, please make a reply to this topic to acknowledge that you have read this and is still with me to tackle the problem until the end. If I do not get any response within 3 days, this topic will be closed.
Hello nocompguru :),

Welcome to What The Tech. I am Jack&Jill, and I will be helping you out.

Before we go further, there are a few things that I would like to make clear so that we are share the same understanding.
  • Please observe and follow these Terms of Use and the rules in Are you Infected? Getting Started: How To Get Help.
  • Any advice is for your computer only and is taken at your own risk. Fixes sometimes will cause unexpected results, but I will do my best to assist you.
  • Please read the instructions carefully and follow them closely, in the order they are presented to you.
  • If you have any doubts or problems during the fix, please stop and ask.
  • All the tools that I will ask you to download and use are safe. Please allow if prompted by any of your security softwares.
  • Do not use or run any malware cleaning tools without supervision as they may cause more harm if improperly used.
  • Refrain from installing any new programs except those that I request during the fix to prevent interference to my diagnosis of the problem.
  • Lack of malware symptoms does not mean your computer is clean. Stick to this topic until I give the All Clear.
  • If you do not reply within 3 days, this topic will be closed.
If you are agreeable to the above, then everything should go smoothly :) . We may begin.

——————–

Your Windows (Service Pack) is outdated and no longer supported by Microsoft. As such, you will not receive any security updates and thus will become a magnet for malware.

Platform: Windows XP SP2 (WinNT 5.01.2600)

You will need to update to a higher Service Pack version to stay patched against the latest threats. However, it must only be installed after we get your computer malware-free, not before. Please have a read here.

During the course of the fix, please keep to the minimum the usage of Internet until your system is cleared and patched. It is also possible that I may advise a reformat and reinstall depending on the severity of infections present.

——————–

Please download OTL© by OldTimer from one of the links below and save it to your desktop.

Link 1
Link 2

Scan with OTL
  • Double click on OTL.exe to run it.
  • Make sure all the Use SafeList options is checked (ticked). There are six of them.
  • Check Scan All Users.
  • At the lower right corner, check LOP Check and Purity Check.
  • Click on Run Scan at the top left hand corner. This might take a while.
  • When done, two Notepad files will open. Please post the contents of these 2 Notepad files in your next reply. One log per reply please.
    Note: These files are saved as OTL.txt and Extras.txt on the desktop.
——————–

Please post back:
1. the OTL logs (OTL.txt and Extras.txt)
OTL.txt

OTL logfile created on: 10/13/2010 4:12:51 PM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Dedrie Smith\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.44 Gb Total Space | 30.75 Gb Free Space | 41.30% Space Free | Partition Type: NTFS
Drive E: | 952.19 Mb Total Space | 2.22 Mb Free Space | 0.23% Space Free | Partition Type: FAT

Computer Name: DLSCONSULTING | User Name: Dedrie Smith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/10/13 16:11:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
PRC - [2010/10/11 20:50:31 | 000,655,360 | —- | M] (Companu de viru) – C:\Documents and Settings\Dedrie Smith\Application Data\hotfix.exe
PRC - [2010/09/07 15:40:04 | 001,819,504 | —- | M] (Symantec Corporation) – C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
PRC - [2010/07/14 21:51:02 | 000,198,608 | —- | M] (Threat Expert Ltd.) – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
PRC - [2010/06/11 18:14:24 | 001,280,344 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\is360tray.exe
PRC - [2010/06/11 18:14:22 | 000,312,152 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\is360srv.exe
PRC - [2010/05/11 11:51:52 | 001,287,120 | —- | M] (PC Tools) – C:\Program Files\PC Tools Security\pctsTray.exe
PRC - [2010/03/15 11:50:36 | 001,142,224 | —- | M] (PC Tools) – C:\Program Files\PC Tools Security\pctsSvc.exe
PRC - [2010/03/11 11:09:22 | 000,366,840 | —- | M] (PC Tools) – C:\Program Files\PC Tools Security\pctsAuxs.exe
PRC - [2009/09/13 18:52:50 | 001,048,392 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2009/07/02 17:36:52 | 000,017,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2008/11/06 07:42:59 | 000,039,208 | —- | M] (AOL, LLC.) – C:\Program Files\AOL 9.1\waol.exe
PRC - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
PRC - [2008/06/24 14:34:50 | 000,041,824 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\1210613219\ee\aolsoftware.exe
PRC - [2008/05/12 11:44:01 | 001,251,720 | —- | M] () – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2007/11/08 23:50:10 | 001,552,384 | —- | M] () – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
PRC - [2007/09/07 18:29:04 | 000,737,280 | —- | M] (Wave Systems Corp.) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
PRC - [2007/08/31 11:49:50 | 000,243,064 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2007/07/03 14:53:40 | 000,475,136 | —- | M] (Dell Inc.) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/04/02 08:33:32 | 000,063,120 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
PRC - [2006/11/03 19:02:14 | 000,050,688 | —- | M] (Avanquest Software ) – C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2006/10/23 08:50:35 | 000,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\acs\AOLacsd.exe


========== Modules (SafeList) ==========

MOD - [2010/10/13 16:11:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
MOD - [2010/02/26 07:16:18 | 000,154,160 | —- | M] (PC Tools) – C:\Program Files\PC Tools Security\smum32.dll
MOD - [2008/11/06 07:42:57 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcr71.dll
MOD - [2008/11/06 07:42:56 | 000,006,144 | —- | M] (AOL, LLC.) – C:\Program Files\AOL 9.1\idleproc.dll
MOD - [2006/08/25 09:45:56 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/08/04 06:00:00 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – C:\WINDOWS\System32\hidserv.dll – (HidServ)
SRV - File not found [Auto | Stopped] – C:\WINDOWS\System32\6to4v32.dll – (6to4)
SRV - [2010/07/14 21:51:02 | 000,198,608 | —- | M] (Threat Expert Ltd.) [Auto | Running] – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2010/06/11 18:14:22 | 000,312,152 | —- | M] (IObit) [Auto | Running] – C:\Program Files\IObit\IObit Security 360\is360srv.exe – (IS360service)
SRV - [2010/03/15 11:50:36 | 001,142,224 | —- | M] (PC Tools) [Auto | Running] – C:\Program Files\PC Tools Security\pctsSvc.exe – (sdCoreService)
SRV - [2010/03/11 11:09:22 | 000,366,840 | —- | M] (PC Tools) [Auto | Running] – C:\Program Files\PC Tools Security\pctsAuxs.exe – (sdAuxService)
SRV - [2009/07/02 17:36:52 | 000,017,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (LiveUpdate Notice)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (CLTNetCnService)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccSetMgr)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccEvtMgr)
SRV - [2008/05/23 14:51:16 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2008/05/12 11:44:01 | 001,251,720 | —- | M] () [On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe – (Symantec Core LC)
SRV - [2008/04/19 00:50:42 | 000,029,744 | —- | M] (Google) [On_Demand | Stopped] – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe – (GoogleDesktopManager-010708-104812)
SRV - [2008/04/19 00:50:19 | 000,654,848 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe – (BcmSqlStartupSvc)
SRV - [2007/12/27 14:50:12 | 003,192,184 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE – (LiveUpdate)
SRV - [2007/12/27 14:46:30 | 000,055,640 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe – (comHost)
SRV - [2007/12/11 04:39:12 | 000,382,320 | —- | M] (SupportSoft, Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\supportsoft\bin\ssrc.exe – (SupportSoft RemoteAssist)
SRV - [2007/11/08 23:50:10 | 001,552,384 | —- | M] () [Auto | Running] – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe – (tcsd_win32.exe)
SRV - [2007/09/13 15:31:44 | 000,192,512 | —- | M] (Wave Systems Corp.) [On_Demand | Stopped] – C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe – (WaveEnrollmentService)
SRV - [2007/09/07 18:29:04 | 000,737,280 | —- | M] (Wave Systems Corp.) [Auto | Running] – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe – (TdmService)
SRV - [2007/08/31 18:39:18 | 000,486,400 | —- | M] (Wave Systems Corp.) [On_Demand | Stopped] – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe – (SecureStorageService)
SRV - [2007/08/31 11:49:50 | 000,243,064 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2007/07/03 14:53:40 | 000,475,136 | —- | M] (Dell Inc.) [Auto | Running] – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe – (NICCONFIGSVC)
SRV - [2006/10/23 08:50:35 | 000,046,640 | R— | M] (AOL LLC) [Auto | Running] – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\oksobxup.sys – (oksobxup)
DRV - File not found [Kernel | System | Stopped] – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{21C425F4-D933-43C8-9F1D-C785D864EFD2}\MpKslc38d941c.sys – (MpKslc38d941c)
DRV - [2010/06/22 14:52:12 | 000,010,344 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\symlcbrd.sys – (symlcbrd)
DRV - [2010/06/16 12:09:32 | 000,002,304 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\msdemgr.sys – (msdemgr)
DRV - [2010/03/29 10:06:14 | 000,218,592 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\PCTCore.sys – (PCTCore)
DRV - [2009/07/13 04:00:00 | 000,875,728 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090806.023\NAVEX15.SYS – (NAVEX15)
DRV - [2009/07/13 04:00:00 | 000,087,888 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090806.023\NAVENG.SYS – (NAVENG)
DRV - [2009/06/16 04:00:00 | 000,101,936 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2009/02/25 05:00:00 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2009/02/19 12:31:42 | 000,031,280 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SymIM.sys – (SymIMMP)
DRV - [2009/02/19 12:31:42 | 000,031,280 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SymIM.sys – (SymIM)
DRV - [2009/02/19 12:31:16 | 000,184,496 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI)
DRV - [2009/02/19 12:31:16 | 000,096,560 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMFW.SYS – (SYMFW)
DRV - [2009/02/19 12:31:16 | 000,038,576 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMIDS.SYS – (SYMIDS)
DRV - [2009/02/19 12:31:16 | 000,037,424 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS – (SYMNDIS)
DRV - [2009/02/19 12:31:16 | 000,022,320 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV)
DRV - [2009/02/19 12:31:16 | 000,013,616 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMDNS.SYS – (SYMDNS)
DRV - [2009/02/09 18:59:18 | 000,251,768 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20090730.002\SymIDSCo.sys – (SYMIDSCO)
DRV - [2009/01/08 21:53:46 | 000,124,464 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2008/09/05 14:31:42 | 000,447,024 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys – (SPBBCDrv)
DRV - [2008/07/30 17:42:12 | 000,023,888 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\COH_Mon.sys – (COH_Mon)
DRV - [2007/12/27 14:43:48 | 000,036,056 | —- | M] (Symantec Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\CO_Mon.sys – (CO_Mon)
DRV - [2007/12/05 21:07:36 | 001,222,840 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2007/12/02 19:26:22 | 000,989,952 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DPV.sys – (HSF_DPV)
DRV - [2007/12/02 19:26:20 | 000,731,136 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2007/12/02 19:26:20 | 000,211,200 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWAZL.sys – (HSFHWAZL)
DRV - [2007/11/30 23:57:12 | 000,317,616 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\srtspl.sys – (SRTSPL)
DRV - [2007/11/30 23:57:12 | 000,279,088 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\WINDOWS\system32\drivers\srtsp.sys – (SRTSP)
DRV - [2007/11/30 23:57:12 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\srtspx.sys – (SRTSPX)
DRV - [2007/11/28 17:18:24 | 000,062,208 | —- | M] (O2Micro) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\oz776.sys – (guardian2)
DRV - [2007/10/09 05:17:42 | 001,123,328 | —- | M] (Broadcom Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2007/09/10 10:55:00 | 000,161,280 | —- | M] (Wave Systems Corp.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\WavxDMgr.sys – (WavxDMgr)
DRV - [2007/09/07 10:57:14 | 000,026,608 | —- | M] (Dell Inc) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\PBADRV.sys – (PBADRV)
DRV - [2007/09/06 10:18:40 | 000,018,176 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WaveFDE.sys – (WaveFDE)
DRV - [2007/08/06 17:27:28 | 006,835,744 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2007/07/17 20:46:12 | 000,037,376 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2007/07/17 20:46:10 | 000,056,832 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2007/07/17 20:46:08 | 000,039,936 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2007/07/17 15:16:36 | 000,161,792 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\b57xp32.sys – (b57w2k)
DRV - [2007/05/24 14:59:14 | 000,202,912 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2006/08/18 14:18:08 | 000,009,400 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResM.SYS – (DLADResM)
DRV - [2006/08/18 14:17:46 | 000,035,096 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABMFSM.SYS – (DLABMFSM)
DRV - [2006/08/18 14:17:44 | 000,097,848 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/08/18 14:17:44 | 000,094,648 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/08/18 14:17:42 | 000,026,008 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/08/18 14:17:40 | 000,032,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/08/18 14:17:38 | 000,104,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/08/18 14:17:38 | 000,014,520 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/08/11 12:05:58 | 000,051,768 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\DRVNDDM.SYS – (DRVNDDM)
DRV - [2006/08/11 11:35:18 | 000,012,920 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2006/08/11 11:35:16 | 000,028,184 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_M.SYS – (DLARTL_M)
DRV - [2006/07/21 12:21:26 | 000,099,176 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS – (DRVMCDB)
DRV - [2006/01/19 10:17:38 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrUsbSer.sys – (BrUsbSer)
DRV - [2006/01/19 05:44:46 | 000,053,248 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrSerIf.sys – (BrSerIf)
DRV - [2005/08/12 18:50:46 | 000,016,128 | —- | M] (Dell Inc) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS – (APPDRV)
DRV - [2004/10/15 12:50:20 | 000,015,295 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrScnUsb.sys – (BrScnUsb)
DRV - [2004/08/12 18:45:54 | 000,137,728 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Hdaudbus.sys – (HDAudBus)
DRV - [2004/08/04 00:07:44 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2004/08/04 00:07:44 | 000,041,088 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2004/08/03 23:07:56 | 000,059,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2003/01/10 17:13:04 | 000,033,588 | R— | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 15:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 15:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 15:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 15:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 15:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 14:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 14:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 14:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 14:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 14:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 14:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 14:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 14:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 14:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 14:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Search Defender"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {cb84136f-9c44-433a-9048-c5cd9df1dc16}:2.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..keyword.URL: "http://www.search-results.com/web?o=15868&l;=dis&prt;=PRT&chn;=UN&geo;=US&ver;=UN&q;="


FF - HKLM\software\mozilla\Firefox\extensions\\{1E2593B2-E106-4697-BCE7-A9D30DE05D73}: C:\Program Files\HttpWatch\Firefox\ [2010/02/13 11:35:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\FireFox\ [2010/06/24 16:57:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/21 18:09:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/21 18:09:38 | 000,000,000 | —D | M]

[2009/11/29 17:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Extensions
[2009/11/29 17:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Extensions\[removed]
[2010/10/11 12:46:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\extensions
[2009/10/30 00:12:16 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/15 19:49:53 | 000,004,555 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\aol-search.xml
[2010/06/24 11:10:08 | 000,002,425 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\askcom.xml
[2010/10/11 12:36:23 | 000,002,698 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\search-defender.xml
[2010/10/11 12:46:00 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/13 09:00:04 | 000,028,488 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll
[2010/04/13 09:00:04 | 000,185,240 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll
[2010/04/13 09:00:23 | 000,046,408 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\atmccli.dll
[2009/08/25 09:05:45 | 000,098,712 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2010/04/13 09:00:02 | 000,061,848 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2008/06/30 23:02:00 | 000,663,072 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
[2009/09/29 19:35:55 | 000,221,184 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll

Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
Sorry – I left part of the OTL.txt file out of my last post – here is the complete file.

OTL logfile created on: 10/13/2010 4:12:51 PM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Dedrie Smith\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.44 Gb Total Space | 30.75 Gb Free Space | 41.30% Space Free | Partition Type: NTFS
Drive E: | 952.19 Mb Total Space | 2.22 Mb Free Space | 0.23% Space Free | Partition Type: FAT

Computer Name: DLSCONSULTING | User Name: Dedrie Smith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/10/13 16:11:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
PRC - [2010/10/11 20:50:31 | 000,655,360 | —- | M] (Companu de viru) – C:\Documents and Settings\Dedrie Smith\Application Data\hotfix.exe
PRC - [2010/09/07 15:40:04 | 001,819,504 | —- | M] (Symantec Corporation) – C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
PRC - [2010/07/14 21:51:02 | 000,198,608 | —- | M] (Threat Expert Ltd.) – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
PRC - [2010/06/11 18:14:24 | 001,280,344 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\is360tray.exe
PRC - [2010/06/11 18:14:22 | 000,312,152 | —- | M] (IObit) – C:\Program Files\IObit\IObit Security 360\is360srv.exe
PRC - [2010/05/11 11:51:52 | 001,287,120 | —- | M] (PC Tools) – C:\Program Files\PC Tools Security\pctsTray.exe
PRC - [2010/03/15 11:50:36 | 001,142,224 | —- | M] (PC Tools) – C:\Program Files\PC Tools Security\pctsSvc.exe
PRC - [2010/03/11 11:09:22 | 000,366,840 | —- | M] (PC Tools) – C:\Program Files\PC Tools Security\pctsAuxs.exe
PRC - [2009/09/13 18:52:50 | 001,048,392 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2009/07/02 17:36:52 | 000,017,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2008/11/06 07:42:59 | 000,039,208 | —- | M] (AOL, LLC.) – C:\Program Files\AOL 9.1\waol.exe
PRC - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
PRC - [2008/06/24 14:34:50 | 000,041,824 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\1210613219\ee\aolsoftware.exe
PRC - [2008/05/12 11:44:01 | 001,251,720 | —- | M] () – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2007/11/08 23:50:10 | 001,552,384 | —- | M] () – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
PRC - [2007/09/07 18:29:04 | 000,737,280 | —- | M] (Wave Systems Corp.) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
PRC - [2007/08/31 11:49:50 | 000,243,064 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2007/07/03 14:53:40 | 000,475,136 | —- | M] (Dell Inc.) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/04/02 08:33:32 | 000,063,120 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
PRC - [2006/11/03 19:02:14 | 000,050,688 | —- | M] (Avanquest Software ) – C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2006/10/23 08:50:35 | 000,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\acs\AOLacsd.exe


========== Modules (SafeList) ==========

MOD - [2010/10/13 16:11:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
MOD - [2010/02/26 07:16:18 | 000,154,160 | —- | M] (PC Tools) – C:\Program Files\PC Tools Security\smum32.dll
MOD - [2008/11/06 07:42:57 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcr71.dll
MOD - [2008/11/06 07:42:56 | 000,006,144 | —- | M] (AOL, LLC.) – C:\Program Files\AOL 9.1\idleproc.dll
MOD - [2006/08/25 09:45:56 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/08/04 06:00:00 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – C:\WINDOWS\System32\hidserv.dll – (HidServ)
SRV - File not found [Auto | Stopped] – C:\WINDOWS\System32\6to4v32.dll – (6to4)
SRV - [2010/07/14 21:51:02 | 000,198,608 | —- | M] (Threat Expert Ltd.) [Auto | Running] – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2010/06/11 18:14:22 | 000,312,152 | —- | M] (IObit) [Auto | Running] – C:\Program Files\IObit\IObit Security 360\is360srv.exe – (IS360service)
SRV - [2010/03/15 11:50:36 | 001,142,224 | —- | M] (PC Tools) [Auto | Running] – C:\Program Files\PC Tools Security\pctsSvc.exe – (sdCoreService)
SRV - [2010/03/11 11:09:22 | 000,366,840 | —- | M] (PC Tools) [Auto | Running] – C:\Program Files\PC Tools Security\pctsAuxs.exe – (sdAuxService)
SRV - [2009/07/02 17:36:52 | 000,017,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (LiveUpdate Notice)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (CLTNetCnService)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccSetMgr)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccEvtMgr)
SRV - [2008/05/23 14:51:16 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2008/05/12 11:44:01 | 001,251,720 | —- | M] () [On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe – (Symantec Core LC)
SRV - [2008/04/19 00:50:42 | 000,029,744 | —- | M] (Google) [On_Demand | Stopped] – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe – (GoogleDesktopManager-010708-104812)
SRV - [2008/04/19 00:50:19 | 000,654,848 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe – (BcmSqlStartupSvc)
SRV - [2007/12/27 14:50:12 | 003,192,184 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE – (LiveUpdate)
SRV - [2007/12/27 14:46:30 | 000,055,640 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe – (comHost)
SRV - [2007/12/11 04:39:12 | 000,382,320 | —- | M] (SupportSoft, Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\supportsoft\bin\ssrc.exe – (SupportSoft RemoteAssist)
SRV - [2007/11/08 23:50:10 | 001,552,384 | —- | M] () [Auto | Running] – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe – (tcsd_win32.exe)
SRV - [2007/09/13 15:31:44 | 000,192,512 | —- | M] (Wave Systems Corp.) [On_Demand | Stopped] – C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe – (WaveEnrollmentService)
SRV - [2007/09/07 18:29:04 | 000,737,280 | —- | M] (Wave Systems Corp.) [Auto | Running] – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe – (TdmService)
SRV - [2007/08/31 18:39:18 | 000,486,400 | —- | M] (Wave Systems Corp.) [On_Demand | Stopped] – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe – (SecureStorageService)
SRV - [2007/08/31 11:49:50 | 000,243,064 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2007/07/03 14:53:40 | 000,475,136 | —- | M] (Dell Inc.) [Auto | Running] – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe – (NICCONFIGSVC)
SRV - [2006/10/23 08:50:35 | 000,046,640 | R— | M] (AOL LLC) [Auto | Running] – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\oksobxup.sys – (oksobxup)
DRV - File not found [Kernel | System | Stopped] – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{21C425F4-D933-43C8-9F1D-C785D864EFD2}\MpKslc38d941c.sys – (MpKslc38d941c)
DRV - [2010/06/22 14:52:12 | 000,010,344 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\symlcbrd.sys – (symlcbrd)
DRV - [2010/06/16 12:09:32 | 000,002,304 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\msdemgr.sys – (msdemgr)
DRV - [2010/03/29 10:06:14 | 000,218,592 | —- | M] (PC Tools) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\PCTCore.sys – (PCTCore)
DRV - [2009/07/13 04:00:00 | 000,875,728 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090806.023\NAVEX15.SYS – (NAVEX15)
DRV - [2009/07/13 04:00:00 | 000,087,888 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090806.023\NAVENG.SYS – (NAVENG)
DRV - [2009/06/16 04:00:00 | 000,101,936 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2009/02/25 05:00:00 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2009/02/19 12:31:42 | 000,031,280 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SymIM.sys – (SymIMMP)
DRV - [2009/02/19 12:31:42 | 000,031,280 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SymIM.sys – (SymIM)
DRV - [2009/02/19 12:31:16 | 000,184,496 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI)
DRV - [2009/02/19 12:31:16 | 000,096,560 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMFW.SYS – (SYMFW)
DRV - [2009/02/19 12:31:16 | 000,038,576 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMIDS.SYS – (SYMIDS)
DRV - [2009/02/19 12:31:16 | 000,037,424 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS – (SYMNDIS)
DRV - [2009/02/19 12:31:16 | 000,022,320 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV)
DRV - [2009/02/19 12:31:16 | 000,013,616 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMDNS.SYS – (SYMDNS)
DRV - [2009/02/09 18:59:18 | 000,251,768 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20090730.002\SymIDSCo.sys – (SYMIDSCO)
DRV - [2009/01/08 21:53:46 | 000,124,464 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2008/09/05 14:31:42 | 000,447,024 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys – (SPBBCDrv)
DRV - [2008/07/30 17:42:12 | 000,023,888 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\COH_Mon.sys – (COH_Mon)
DRV - [2007/12/27 14:43:48 | 000,036,056 | —- | M] (Symantec Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\CO_Mon.sys – (CO_Mon)
DRV - [2007/12/05 21:07:36 | 001,222,840 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2007/12/02 19:26:22 | 000,989,952 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DPV.sys – (HSF_DPV)
DRV - [2007/12/02 19:26:20 | 000,731,136 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2007/12/02 19:26:20 | 000,211,200 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWAZL.sys – (HSFHWAZL)
DRV - [2007/11/30 23:57:12 | 000,317,616 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\srtspl.sys – (SRTSPL)
DRV - [2007/11/30 23:57:12 | 000,279,088 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\WINDOWS\system32\drivers\srtsp.sys – (SRTSP)
DRV - [2007/11/30 23:57:12 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\srtspx.sys – (SRTSPX)
DRV - [2007/11/28 17:18:24 | 000,062,208 | —- | M] (O2Micro) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\oz776.sys – (guardian2)
DRV - [2007/10/09 05:17:42 | 001,123,328 | —- | M] (Broadcom Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2007/09/10 10:55:00 | 000,161,280 | —- | M] (Wave Systems Corp.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\WavxDMgr.sys – (WavxDMgr)
DRV - [2007/09/07 10:57:14 | 000,026,608 | —- | M] (Dell Inc) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\PBADRV.sys – (PBADRV)
DRV - [2007/09/06 10:18:40 | 000,018,176 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WaveFDE.sys – (WaveFDE)
DRV - [2007/08/06 17:27:28 | 006,835,744 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2007/07/17 20:46:12 | 000,037,376 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2007/07/17 20:46:10 | 000,056,832 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2007/07/17 20:46:08 | 000,039,936 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2007/07/17 15:16:36 | 000,161,792 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\b57xp32.sys – (b57w2k)
DRV - [2007/05/24 14:59:14 | 000,202,912 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2006/08/18 14:18:08 | 000,009,400 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResM.SYS – (DLADResM)
DRV - [2006/08/18 14:17:46 | 000,035,096 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABMFSM.SYS – (DLABMFSM)
DRV - [2006/08/18 14:17:44 | 000,097,848 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/08/18 14:17:44 | 000,094,648 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/08/18 14:17:42 | 000,026,008 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/08/18 14:17:40 | 000,032,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/08/18 14:17:38 | 000,104,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/08/18 14:17:38 | 000,014,520 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/08/11 12:05:58 | 000,051,768 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\DRVNDDM.SYS – (DRVNDDM)
DRV - [2006/08/11 11:35:18 | 000,012,920 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2006/08/11 11:35:16 | 000,028,184 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_M.SYS – (DLARTL_M)
DRV - [2006/07/21 12:21:26 | 000,099,176 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS – (DRVMCDB)
DRV - [2006/01/19 10:17:38 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrUsbSer.sys – (BrUsbSer)
DRV - [2006/01/19 05:44:46 | 000,053,248 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrSerIf.sys – (BrSerIf)
DRV - [2005/08/12 18:50:46 | 000,016,128 | —- | M] (Dell Inc) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS – (APPDRV)
DRV - [2004/10/15 12:50:20 | 000,015,295 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrScnUsb.sys – (BrScnUsb)
DRV - [2004/08/12 18:45:54 | 000,137,728 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Hdaudbus.sys – (HDAudBus)
DRV - [2004/08/04 00:07:44 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2004/08/04 00:07:44 | 000,041,088 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2004/08/03 23:07:56 | 000,059,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2003/01/10 17:13:04 | 000,033,588 | R— | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 15:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 15:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 15:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 15:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 15:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 14:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 14:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 14:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 14:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 14:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 14:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 14:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 14:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 14:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 14:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Search Defender"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {cb84136f-9c44-433a-9048-c5cd9df1dc16}:2.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..keyword.URL: "http://www.search-results.com/web?o=15868&l;=dis&prt;=PRT&chn;=UN&geo;=US&ver;=UN&q;="


FF - HKLM\software\mozilla\Firefox\extensions\\{1E2593B2-E106-4697-BCE7-A9D30DE05D73}: C:\Program Files\HttpWatch\Firefox\ [2010/02/13 11:35:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\FireFox\ [2010/06/24 16:57:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/21 18:09:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/21 18:09:38 | 000,000,000 | —D | M]

[2009/11/29 17:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Extensions
[2009/11/29 17:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Extensions\[removed]
[2010/10/11 12:46:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\extensions
[2009/10/30 00:12:16 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/15 19:49:53 | 000,004,555 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\aol-search.xml
[2010/06/24 11:10:08 | 000,002,425 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\askcom.xml
[2010/10/11 12:36:23 | 000,002,698 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\search-defender.xml
[2010/10/11 12:46:00 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/13 09:00:04 | 000,028,488 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll
[2010/04/13 09:00:04 | 000,185,240 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll
[2010/04/13 09:00:23 | 000,046,408 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\atmccli.dll
[2009/08/25 09:05:45 | 000,098,712 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2010/04/13 09:00:02 | 000,061,848 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2008/06/30 23:02:00 | 000,663,072 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
[2009/09/29 19:35:55 | 000,221,184 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll

Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (HttpWatch Basic) - {F1F69322-008F-4895-B2BF-AD194219825A} - C:\Program Files\HttpWatch\httpwatchsc.dll (Simtec Limited)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\Toolbar\WebBrowser: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Security\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008..\Run: [AOL Fast Start] C:\Program Files\AOL 9.1\AOL.EXE (AOL, LLC.)
O4 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008..\Run: [NortonUpdateAgent] C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe (Symantec Corporation)
O4 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatch.dll (Simtec Limited)
O9 - Extra 'Tools' menuitem : HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6796.cab (Windows Live Safety Center Base Module)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {6BAB93B7-1917-4214-A7D2-874FA6DB4740} http://o.aolcdn.com/pictures/ap/Resources/…ns.10.6.0.8.cab (AOL Newport Editor Ctrl)
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab (GameHouse Games Player)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - AppInit_DLLs: (c:\windows\system32\hisakite.dll c:\windows\system32\zudalure.dll c:\windows\system32\rovozefa.dll c:\windows\system32\bulimane.dll c:\windows\system32\moriyava.dll c:\windows\system32\supilime.dll c:\windows\system32\bevoweja.dll c:\windows\system32\kiyajeru.dll c:\windows\system32\dehaseha.dll c:\windows\system32\natulevo.dll c:\windows\system32\vomuganu.dll c:\windows\system32\mayonibe.dll c:\windows\system32\dogatidi.dll c:\windows\system32\pekuhedo.dll) - C:\WINDOWS\System32\hisakite.dll File not found
O20 - AppInit_DLLs: (pemobupo.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (waveGina.dll) - C:\WINDOWS\System32\waveGina.dll (Wave Systems Corp.)
O20 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008 Winlogon: Shell - (C:\Documents and Settings\Dedrie Smith\Application Data\hotfix.exe) - C:\Documents and Settings\Dedrie Smith\Application Data\hotfix.exe (Companu de viru)
O20 - Winlogon\Notify\gemsafe: DllName - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll (Gemplus)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O21 - SSODL: bajiwupuh - {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - C:\WINDOWS\System32\teyufeve.dll File not found
O21 - SSODL: fafejuvek - {c66ae819-8c35-4f9f-a643-63045cbebecf} - C:\WINDOWS\System32\moriyava.dll File not found
O21 - SSODL: lolozimav - {289d3c51-2110-4650-8827-bb3d197b98ad} - C:\WINDOWS\System32\teyufeve.dll File not found
O22 - SharedTaskScheduler: {002401d3-541f-4a08-a167-988bcde63d5e} - mujuzedij - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {018b02ca-d120-4bf3-be8d-a5c5d3e0b107} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {0a42816f-86a2-4018-8e75-c7490c653054} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {0b331eaa-ffcb-49bb-aeec-4919f87b373c} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {1cf542fb-1517-4773-b966-ffd3dbab02dc} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {289d3c51-2110-4650-8827-bb3d197b98ad} - jugezatag - C:\WINDOWS\System32\teyufeve.dll File not found
O22 - SharedTaskScheduler: {298bd6e5-7f07-4e5a-b7a0-53082cab9b63} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {34c75cca-3d66-42ae-bf3f-f005b7bc0086} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {429a2580-6151-47fb-af1d-cc581c2bd535} - jugezatag - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {6a1355d4-879e-4d83-b740-d59902b31b6c} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {71a41e06-4419-479b-b44c-12ddf5528c1c} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {95a847ee-8b44-460f-8d4e-6f242ea7682f} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {9675de18-8f52-4612-a8f9-c16451dbbefe} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - tokatiluy - C:\WINDOWS\System32\teyufeve.dll File not found
O22 - SharedTaskScheduler: {b6c16ada-5ae0-431e-8797-578fa2dfd46f} - mujuzedij - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {b7be70e5-57a5-4aeb-a646-cd1061addc8c} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {c66ae819-8c35-4f9f-a643-63045cbebecf} - tokatiluy - C:\WINDOWS\System32\moriyava.dll File not found
O22 - SharedTaskScheduler: {d09ec36b-34df-4f50-a0ec-868f49b6094b} - mujuzedij - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {da73c12d-3a42-4e3d-94f8-418ebe5fd807} - jugezatag - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {f3e2d788-efd6-491f-a8b2-725b06fc5828} - gahurihor - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\WINDOWS\dell.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (wvauth) - C:\WINDOWS\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\phone\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\{a1485048-13f7-11df-a37e-001f3a4cf431}\Shell\Auto\command - "" = E:\launcher.exe – File not found
O33 - MountPoints2\{a1485048-13f7-11df-a37e-001f3a4cf431}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{a1485049-13f7-11df-a37e-001f3a4cf431}\Shell\Auto\command - "" = E:\launcher.exe – File not found
O33 - MountPoints2\{a1485049-13f7-11df-a37e-001f3a4cf431}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/10/13 16:10:50 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
[2010/10/12 20:48:44 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Dedrie Smith\Desktop\HiJackThis.exe
[2010/10/11 20:50:30 | 000,655,360 | —- | C] (Companu de viru) – C:\Documents and Settings\Dedrie Smith\Application Data\hotfix.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/13 16:11:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
[2010/10/13 16:01:21 | 000,000,248 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/10/13 15:49:34 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/10/13 15:46:08 | 000,093,584 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2010/10/13 15:45:30 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/13 15:44:16 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/13 15:44:08 | 2145,521,664 | -HS- | M] () – C:\hiberfil.sys
[2010/10/12 20:49:03 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Dedrie Smith\Desktop\HiJackThis.exe
[2010/10/12 19:06:12 | 000,000,008 | RHS- | M] () – C:\Documents and Settings\Dedrie Smith\ntuser.pol
[2010/10/11 21:40:08 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/10/11 21:19:36 | 000,020,043 | —- | M] () – C:\WINDOWS\System32\nvwsapps.xml
[2010/10/11 20:50:44 | 000,002,256 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\hyghghjhjghjhj.bat
[2010/10/11 20:50:32 | 000,000,144 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\dsfsds.bat
[2010/10/11 20:50:31 | 000,655,360 | —- | M] (Companu de viru) – C:\Documents and Settings\Dedrie Smith\Application Data\hotfix.exe
[2010/10/11 11:29:56 | 000,093,584 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/12 19:01:38 | 000,000,008 | RHS- | C] () – C:\Documents and Settings\Dedrie Smith\ntuser.pol
[2010/10/11 20:50:44 | 000,002,256 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Application Data\hyghghjhjghjhj.bat
[2010/10/11 20:50:31 | 000,000,144 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Application Data\dsfsds.bat
[2010/06/24 16:57:37 | 000,767,928 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/06/16 12:09:32 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\msdemgr.sys
[2009/02/20 23:53:56 | 000,000,135 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Local Settings\Application Data\fusioncache.dat
[2009/01/13 16:40:52 | 014,564,931 | —- | C] () – C:\Program Files\ysitebuilder.exe
[2008/11/28 01:07:47 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/07/17 23:34:22 | 000,000,000 | —- | C] () – C:\Program Files\Firefox Setup 3.0.1.exe
[2008/07/06 14:39:18 | 000,000,811 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2008/07/06 14:39:18 | 000,000,094 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2008/07/06 14:38:18 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2008/07/06 14:38:18 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2008/07/06 14:36:58 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2008/06/22 19:32:45 | 000,018,274 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/06/03 11:58:27 | 000,009,728 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/11 21:34:56 | 000,000,000 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Local Settings\Application Data\WavXMapDrive.bat
[2008/04/19 01:08:35 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/04/19 00:42:15 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/04/19 00:42:15 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/04/19 00:30:19 | 000,080,368 | —- | C] () – C:\WINDOWS\System32\pbadrvdll.dll
[2008/04/19 00:27:42 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\bioapi_mds300.dll
[2008/04/19 00:27:42 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\bioapi100.dll
[2008/04/19 00:23:00 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2008/04/19 00:22:56 | 000,753,664 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2008/04/18 23:55:26 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/04/18 23:55:26 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/04/18 23:55:25 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/04/18 23:55:25 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/04/18 23:55:12 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2008/04/18 23:53:43 | 000,001,122 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2008/02/04 19:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/09/13 15:42:30 | 000,499,712 | —- | C] () – C:\WINDOWS\System32\AmRes_ru.dll
[2007/09/13 15:42:30 | 000,471,040 | —- | C] () – C:\WINDOWS\System32\AmRes_pt-BR.dll
[2007/09/13 15:42:28 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_it.dll
[2007/09/13 15:42:28 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_fr.dll
[2007/09/13 15:42:28 | 000,462,848 | —- | C] () – C:\WINDOWS\System32\AmRes_ko.dll
[2007/09/13 15:42:28 | 000,458,752 | —- | C] () – C:\WINDOWS\System32\AmRes_ja.dll
[2007/09/13 15:42:26 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_es.dll
[2007/09/13 15:42:26 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_de.dll
[2007/09/13 15:42:26 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\AmRes_en.dll
[2007/09/13 15:42:26 | 000,434,176 | —- | C] () – C:\WINDOWS\System32\AmRes_zh-CHT.dll
[2007/09/13 15:36:24 | 000,438,272 | —- | C] () – C:\WINDOWS\System32\AmRes_zh-CHS.dll
[2007/09/12 16:05:08 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_pt.dll
[2007/09/12 16:04:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\Internationalization_zh-CHT.dll
[2007/09/12 16:04:26 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\Internationalization_ko.dll
[2007/09/12 16:04:06 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_es.dll
[2007/09/12 16:03:44 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\Internationalization_ru.dll
[2007/09/12 16:03:24 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\Internationalization_ja.dll
[2007/09/12 16:03:04 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_it.dll
[2007/09/12 16:02:44 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_de.dll
[2007/09/12 16:02:22 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_fr.dll
[2007/09/12 16:02:02 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\Internationalization_zh-CHS.dll
[2007/09/10 10:53:26 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\wxvault.dll
[2007/06/15 11:19:20 | 000,835,584 | —- | C] () – C:\WINDOWS\System32\DemoLicense.dll
[2007/01/03 11:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 11:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 11:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/11/07 05:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/17 00:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/17 00:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2006/08/14 12:02:10 | 000,072,192 | —- | C] () – C:\WINDOWS\System32\xltZlib.dll
[2006/06/12 09:01:16 | 000,348,160 | —- | C] () – C:\WINDOWS\tsp.dll
[2004/09/10 14:34:00 | 000,917,504 | —- | C] () – C:\WINDOWS\System32\lmgr10.dll
[2004/09/10 14:34:00 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ADsSecurity.dll
[2004/08/11 18:24:19 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 18:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 18:07:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\qrbktbal.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\moyhzgde.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\mdkmbdhm.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\kbtlinqq.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\jniyjvsh.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\hudaxxum.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\axjlnrvq.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\aqnlfvxs.sys:changelist
@Alternate Data Stream - 368 bytes -> C:\WINDOWS\System32\drivers\ukixszmw.sys:changelist
@Alternate Data Stream - 368 bytes -> C:\WINDOWS\System32\drivers\pbkutgqb.sys:changelist
@Alternate Data Stream - 2886 bytes -> C:\WINDOWS\System32\drivers\dfvrfjfh.sys:changelist
@Alternate Data Stream - 2394 bytes -> C:\WINDOWS\System32\drivers\hzmbkdfs.sys:changelist
@Alternate Data Stream - 2194 bytes -> C:\WINDOWS\System32\drivers\pzcbqmtc.sys:changelist
@Alternate Data Stream - 2094 bytes -> C:\WINDOWS\System32\drivers\baydmjwe.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\zwewnaus.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\zomwmskw.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\zmtxlczd.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\uhfnajas.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\pykjaewj.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\oybfwpmi.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\diketwvy.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\voakaxjx.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\ukzevqef.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\tgctseaf.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\qhkkhbcn.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\oxogayzn.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\oosdjhyl.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\nltagavr.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\lohomwre.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\kugfpeya.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\ivfhaoiq.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\exmvswjr.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\eabfohna.sys:changelist
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
Thanks again!!

Extras.txt

OTL Extras logfile created on: 10/13/2010 4:12:51 PM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Dedrie Smith\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 62.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.44 Gb Total Space | 30.75 Gb Free Space | 41.30% Space Free | Partition Type: NTFS
Drive E: | 952.19 Mb Total Space | 2.22 Mb Free Space | 0.23% Space Free | Partition Type: FAT

Computer Name: DLSCONSULTING | User Name: Dedrie Smith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_USERS\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01B845D4-B73E-4CF7-A377-94BC7BB4F77B}" = HttpWatch Basic 6.2.39
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"{0C2AF762-0565-4C91-9F55-B8B53BB82A38}" = Microsoft Office Accounting 2008 Equifax Addin
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{177D1318-3E4B-4A7C-A300-AC4E21BE090B}" = Broadcom Management Programs
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{24A494F3-5B5F-4183-9F7D-9CE82812C1FC}" = tsp patch
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{270940EA-C235-40D9-B2AE-2D450356DF8E}" = Microsoft Office Accounting 2008
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}" = Component Framework
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3643EF5F-D28D-4B25-9FA1-8859FC303710}" = Coby Media Manager
"{3A6BE9F4-5FC8-44BB-BE7B-32A29607FEF6}" = Preboot Manager
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40036C98-9777-45C2-9183-304B82B549BA}" = Symantec Real Time Storage Protection Component
"{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{48B3FB4D-CE22-488C-8E9F-24EBB77EAC0F}" = Microsoft Security Essentials
"{4BF18ED6-C888-4BCF-A4AF-AC7A16305BC1}" = GemSafe Standard Edition 5.1
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{55A6283C-638A-4EE0-B491-51118554BDA2}" = Norton Confidential Core
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{5EC5F187-9D2B-4051-8906-88656819A869}" = Dell Drivers MSI
"{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62120008-8E1E-4807-860D-A8B48F8552DB}" = Norton Protection Center
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}" = Norton AntiVirus
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{7A2CF4CC-21A9-461D-85E3-7B4589302F65}" = SymNet
"{7A647B7A-9FE7-44A2-9041-C04528D44EB9}" = NBC Direct Beta
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_SMALLBUSINESSR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_SMALLBUSINESSR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007
"{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9593C6E5-205E-45C3-B785-05CF146CA76A}" = biolsp patch
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9EDA3DD1-130D-4EE1-A3D2-5A3D795CC8C9}" = MFCLOC
"{A093D83F-429A-4AB2-A0CD-1F7E9C7B764A}" = Trusted Drive Manager
"{A0A77CDC-2419-4D5C-AD2C-E09E5926B806}" = Microsoft Antimalware
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABBA2EA4-740E-4052-902B-9CA70B081E3F}" = Dell Embassy Trust Suite by Wave Systems
"{AC76BA86-1033-0000-BA7E-000000000003}" = Adobe Acrobat 8 Standard
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP1
"{B391EECE-DFEA-4FC5-9D40-47FA43E2DBE6}" = Microsoft Office Accounting 2008 PayPal Addin
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B52D7A21-03E5-4C0C-82FA-FD8EB4C92149}" = AxessManager
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1C185CA-C531-49F5-A6FA-B838405A049D}" = Norton Internet Security
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DCC72248-D3D2-4846-8499-A400053A430E}" = TWC User Controls
"{E0F1D3B6-F50E-49AE-A942-FFDFFA16F9A9}" = PhotoStreamer 2
"{E3DF6916-2472-43D9-8B3C-9F2F0AAB01B5}" = Microsoft Office Accounting 2008 Fixed Asset Manager
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton AntiVirus Help
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{EB4DF30B-102B-4F0C-927A-D50E037A325D}" = AuthenTec Fingerprint Sensor Minimum Install
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"{ECC22AFA-B905-4A6A-8072-10F52B9E09B7}" = Wave Infrastructure Installer
"{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"{EF05BA0F-AC15-4D12-AC5C-276225F5E751}" = Gemalto
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F1802FA6-54E9-4B24-BD2A-B50866819795}" = EMBASSY Trust Suite by Wave Systems
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}" = iTunes
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FBEC50B7-537C-4A0E-8B0B-F7A8F8BF13CE}" = upekmsi
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FEC193E4-6C5F-40E9-A249-7D8C8404A9EC}" = NTRU TCG Software Stack
"ActiveTouchMeetingClient" = WebEx
"Adobe Acrobat 8 Standard" = Adobe Acrobat 8.1.2 Standard
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM_6" = AIM 6
"AOL Pictures" = AOL Pictures Tools (version 10.6.0.8)
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"Browser Defender_is1" = Browser Defender [removed]
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP1
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Google Desktop" = Google Desktop
"GoToAssist" = GoToAssist 8.0.0.514
"InstallShield_{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"InstallShield_{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"InstallShield_{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"InstallShield_{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"InstallShield_{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"InstallShield_{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"InstallShield_{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"InstallShield_{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"IObit Security 360_is1" = IObit Security 360
"LimeWire" = LimeWire 5.5.10
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Office Accounting 2008" = Microsoft Office Accounting 2008
"Microsoft Security Essentials" = Microsoft Security Essentials
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.5.11)" = Mozilla Firefox (3.5.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoStreamer 2" = PhotoStreamer 2
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"RealPlayer 12.0" = RealPlayer
"SMALLBUSINESSR" = Microsoft Office Small Business 2007
"Spyware Doctor" = PC Tools AntiVirus Free
"SynTPDeinstKey" = Dell Touchpad
"VLC media player" = VideoLAN VLC media player 0.8.6i
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! SiteBuilder" = Yahoo! SiteBuilder
"YInstHelper" = Yahoo! Install Manager

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting/GoToWebinar 3.0.0.198
"Move Media Player" = Move Media Player
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.7.1

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/11/2010 10:02:20 PM | Computer Name = DLSCONSULTING | Source = MSSecurityEssentials | ID = 5000
Description =

Error - 10/11/2010 10:14:23 PM | Computer Name = DLSCONSULTING | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 2.0.6212.0,
P5 mpsigdwn.dll, P6 2.0.6212.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.

Error - 10/11/2010 10:34:26 PM | Computer Name = DLSCONSULTING | Source = MSSecurityEssentials | ID = 5000
Description =

Error - 10/11/2010 10:38:43 PM | Computer Name = DLSCONSULTING | Source = MSSecurityEssentials | ID = 5000
Description =

Error - 10/12/2010 7:53:01 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x001a3bef.

Error - 10/12/2010 7:53:49 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1001
Description = Fault bucket 1941709896.

Error - 10/12/2010 11:07:44 PM | Computer Name = DLSCONSULTING | Source = MSSecurityEssentials | ID = 5000
Description =

Error - 10/13/2010 12:09:21 AM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 | ID = 2000
Description = Accepted Safe Mode action : Microsoft Office PowerPoint.

Error - 10/13/2010 3:42:51 PM | Computer Name = DLSCONSULTING | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 2.0.6212.0,
P5 mpsigdwn.dll, P6 2.0.6212.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.

Error - 10/13/2010 4:01:16 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module mshtml.dll, version 6.0.2900.3603, fault address 0x000aa610.

[ OSession Events ]
Error - 2/1/2009 3:54:38 AM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 211714
seconds with 960 seconds of active time. This session ended with a crash.

Error - 2/18/2009 1:47:45 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 706
seconds with 660 seconds of active time. This session ended with a crash.

Error - 2/24/2009 3:14:22 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 11411
seconds with 5220 seconds of active time. This session ended with a crash.

Error - 2/25/2009 3:41:54 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1812
seconds with 240 seconds of active time. This session ended with a crash.

Error - 5/11/2009 11:51:31 AM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 2796
seconds with 540 seconds of active time. This session ended with a crash.

Error - 6/18/2009 8:18:53 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 14
seconds with 0 seconds of active time. This session ended with a crash.

Error - 7/11/2010 3:05:25 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 273 seconds with 0 seconds of active time. This session ended with a crash.

Error - 7/11/2010 3:05:36 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 3 seconds with 0 seconds of active time. This session ended with a crash.

Error - 7/11/2010 3:05:55 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 7 seconds with 0 seconds of active time. This session ended with a crash.

Error - 7/11/2010 3:06:03 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 2 seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 10/13/2010 3:35:11 PM | Computer Name = DLSCONSULTING | Source = Service Control Manager | ID = 7000
Description = The DHCP Client service failed to start due to the following error:
%%1053

Error - 10/13/2010 3:35:11 PM | Computer Name = DLSCONSULTING | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Wireless Zero Configuration
service to connect.

Error - 10/13/2010 3:35:11 PM | Computer Name = DLSCONSULTING | Source = Service Control Manager | ID = 7000
Description = The Wireless Zero Configuration service failed to start due to the
following error: %%1053

Error - 10/13/2010 3:35:11 PM | Computer Name = DLSCONSULTING | Source = Service Control Manager | ID = 7023
Description = The Network Security service terminated with the following error:
%%126

Error - 10/13/2010 3:42:48 PM | Computer Name = DLSCONSULTING | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.91.1460.0 Update Source: %%859 Update Stage:
%%852 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803

User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6201.0 Error
code: 0x8024402c Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.

Error - 10/13/2010 3:44:47 PM | Computer Name = DLSCONSULTING | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 10/13/2010 3:44:47 PM | Computer Name = DLSCONSULTING | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 10/13/2010 3:45:33 PM | Computer Name = DLSCONSULTING | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Themes service to connect.

Error - 10/13/2010 3:45:33 PM | Computer Name = DLSCONSULTING | Source = Service Control Manager | ID = 7000
Description = The Themes service failed to start due to the following error: %%1053

Error - 10/13/2010 3:45:33 PM | Computer Name = DLSCONSULTING | Source = Service Control Manager | ID = 7023
Description = The Network Security service terminated with the following error:
%%126


< End of report >
Hello nocompguru :),

Remove P2P software
  • IMPORTANT: I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    LimeWire 5.5.10

  • Our policy as pointed out in the Terms of Use:

    We will not support or allow the discussion of any peer to peer (P2P) applications, except for their removal.

  • Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
  • Go to Control Panel > Add/Remove Programs and uninstall the P2P program(s) listed above (in red).
  • Please remove them before we continue with fixing your computer.
Uninstall these as well:
IObit Security 360
Ask Toolbar


They are unwanted programs.

——————–

You are running more than one Antivirus (AV) softwares:

Microsoft Security Essentials
PC Tools AntiVirus Free
Norton AntiVirus


Although AV is essential for keeping your computer free from viruses, having more than one AV will do more harm than protect your computer. They will not only conflict, but will slow down your computer as well. Did you pay for either one of them? Please keep the paid AV and uninstall the others. Otherwise, you will need to choose in accordance to your preference.

——————–

Is this a business computer? There are many programs suggesting so.

——————–

Check for additional security risks
  • Please download CKScanner© by askey127 and save to your desktop. Click here.
  • Double click on CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File. You will be prompted, click OK.
  • Post the contents of ckfiles.txt in your reply, it is located on your desktop.
——————–

Please post back:
1. fresh OTL logs using the earlier settings
2. the answer to my question about your computer
3. CKScanner log
Thanks for the response… I don't doubt there is peer-to-peer software – my ex-boyfriend "borrowed" my computer often – no telling what the scoundrel downloaded – I don't even know how to use it – but I think I can figure out how to un-install. (I guess I really shouldn't share that kind of information in a public forum) The computer was a business computer – I had tried to start a side business as an HR Consultant – but due to the lack of business I officially shut it down in December 2009 so now it is my personal computer – I'm fine with deleting anything that's associated with the business – if needed – I have everything I need in hard copy should the IRS ever come looking for me. I guess the only thing I might need to keep are my business emails, just in case something were to ever come up. I really appreciate the help – you are quite the guru!
Hello nocompguru :), After your have done the steps I have outlined in my earlier post, please post the OTL logs and CKScanner log in order to continue.
Hello nocompguru :), I usually close the topic after 3 days without any reply, and it has already been 2 days since my last post. Do you still need help? Any problems following my instructions? Need more time? If I do not get any response within the next 24 hours, this topic will be closed.
So sorry that it's taken me a while – I was out of town this weekend. I will definitely do this by tomorrow evening, so yes if I could have a bit more time I would appreciate it very much. Thanks again for your help and patience.
I was able to uninstall IObit Security 360 PC Tools AntiVirus Free Norton AntiVirus But I could not figure out how to install the Ask toolbar…any suggestions? I didn't know if I need to get this done before reposting the OTL logs. Thanks much!
Hello nocompguru :), Have you uninstalled Limewire? If so, skip the Ask Toolbar for now and just post the OTL logs. We will address it later. Then run CKScanner and post the log as well.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI