This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

trojan downloader, win32, droploader

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I started getting a lot of popups. I run firefox and these pop-ups are in IE. I then got a microsoft essentials alert for trojan downloader, trojan win32 and trojan droploader. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 6:34:57.64 on Thu 10/28/2010 Internet Explorer: 8.0.6001.18975 BrowserJavaVersion: 1.6.0_18 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3002.1060 [GMT -4:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss c:\Program Files\Microsoft Security Essentials\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\STacSV.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Hpservice.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\aestsrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Atomic Alarm Clock\timeserv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\CSHelper.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Windows\system32\lxbvcoms.exe C:\Windows\system32\lxdxcoms.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe C:\Windows\SMINST\BLService.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe C:\Program Files\IDT\WDM\sttray.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Lexmark 3600-4600 Series\lxdxMsdMon.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Windows\system32\taskeng.exe C:\Users\Nancy\AppData\Local\Temp\moxecsnawr.exe C:\Users\Nancy\AppData\Local\Temp\moxecsnawr.exe C:\Windows\system32\rundll32.exe C:\Users\Nancy\AppData\Local\Temp\Yh0.exe C:\Windows\system32\rundll32.exe C:\Users\Nancy\AppData\Local\Temp\Yh4.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Users\Nancy\AppData\Local\Temp\Yh2.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Nancy\Downloads\dds.scr C:\Users\Nancy\AppData\Local\Temp\Yh0.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll mURLSearchHooks: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll BHO: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll TB: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe" uRun: [Metropolis] rundll32.exe c:\users\nancy\appdata\local\temp\sshnas21.dll,GetHandle uRun: [U36VRSFLG6] c:\users\nancy\appdata\local\temp\Yh2.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\2.0" mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [USB2Check] RUNDLL32.EXE "c:\windows\system32\PCLECoInst.dll",CheckUSBController mRun: [mumservice] c:\program files\motorola\software update\mumservice.exe mRun: [lxdxmon.exe] "c:\program files\lexmark 3600-4600 series\lxdxmon.exe" mRun: [lxdxamon] "c:\program files\lexmark 3600-4600 series\lxdxamon.exe" mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mExplorerRun: [smoxgbyq] rundll32 "c:\users\nancy\appdata\roaming\C_1255U.dll",hnpmmh StartupFolder: c:\users\nancy\appdata\roaming\micros~1\windows\startm~1\programs\startup\vacati~1.lnk - c:\program files\vacation countdown v1\Vacation_Countdown.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to &Evernote - c:\program files\evernote\evernote3.5\enbar.dll/2000 IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll IE: {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEEE} - c:\program files\evernote\evernote3.5\enbar.dll DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Notify: igfxcui - igfxdev.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\nancy\appdata\roaming\mozilla\firefox\profiles\ignl4m9r.default\ FF - prefs.js: browser.search.selectedEngine - Swag Bucks Customized Web Search FF - prefs.js: browser.startup.homepage - hxxps://login.yahoo.com/config/mail?.src=ym&.intl=us FF - component: c:\program files\siber systems\ai roboform\firefox\components\rfproxy_31.dll FF - component: c:\users\nancy\appdata\roaming\mozilla\firefox\profiles\ignl4m9r.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\FFExternalAlert.dll FF - component: c:\users\nancy\appdata\roaming\mozilla\firefox\profiles\ignl4m9r.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\RadioWMPCore.dll FF - component: c:\users\nancy\appdata\roaming\mozilla\firefox\profiles\ignl4m9r.default\extensions\{e0b8c461-f8fb-49b4-8373-fe32e9252800}\platform\winnt_x86-msvc\components\enbar.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\mozilla firefox\plugins\npArtistScope42.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - plugin: c:\users\nancy\appdata\roaming\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\users\nancy\appdata\roaming\mozilla\firefox\profiles\ignl4m9r.default\extensions\{0c7e3f01-99e9-4095-9bdc-f84724960b57}\plugins\NPCpnMgr.dll FF - plugin: c:\users\nancy\appdata\roaming\mozilla\firefox\profiles\ignl4m9r.default\extensions\{195a3098-0bd5-4e90-ae22-ba1c540afd1e}\plugins\npGarmin.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files\adobe\elements organizer 8.0\PhotoshopElementsFileAgent.exe [2009-9-6 169312] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_e2247046\AEstSrv.exe [2009-3-2 81920] R2 AtomicAlarmClock;Atomic Alarm Clock Time;c:\program files\atomic alarm clock\timeserv.exe [2009-3-30 415744] R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [2009-2-7 266240] R2 hpsrv;HP Service;c:\windows\system32\hpservice.exe [2008-3-18 19456] R2 lxbv_device;lxbv_device;c:\windows\system32\lxbvcoms.exe -service –> c:\windows\system32\lxbvcoms.exe -service [?] R2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe -service –> c:\windows\system32\lxdxcoms.exe -service [?] R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\sminst\BLService.exe [2008-8-22 361808] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-12-1 24652] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808] R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-7-1 193840] R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2008-1-24 52736] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-6-4 113664] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-12-2 42368] S2 lxdxCATSCustConnectService;lxdxCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdxserv.exe [2009-8-13 94208] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] =============== Created Last 30 ================ 2010-10-28 05:57 103,424 a–shr– c:\users\nancy\appdata\roaming\C_1255U.dll 2010-10-28 05:56 –d—– c:\users\nancy\appdata\roaming\1D74787EA28A0C2204A55622B0866299 2010-10-14 06:13 954,752 a——- c:\windows\system32\mfc40.dll 2010-10-14 06:13 954,288 a——- c:\windows\system32\mfc40u.dll 2010-10-14 06:13 867,328 a——- c:\windows\system32\wmpmde.dll 2010-10-14 06:13 531,968 a——- c:\windows\system32\comctl32.dll 2010-09-29 06:21 2,048 a——- c:\windows\system32\tzres.dll ==================== Find3M ==================== 2010-10-19 16:51 222,080 ——– c:\windows\system32\MpSigStub.exe 2010-09-22 06:17 143,360 a——- c:\windows\inf\infstrng.dat 2010-09-22 06:17 51,200 a——- c:\windows\inf\infpub.dat 2010-09-22 06:17 143,360 a——- c:\windows\inf\infstor.dat 2010-09-13 09:56 8,147,456 a——- c:\windows\system32\wmploc.DLL 2010-09-08 02:01 916,480 a——- c:\windows\system32\wininet.dll 2010-09-08 01:57 43,520 a——- c:\windows\system32\licmgr10.dll 2010-09-08 01:56 109,056 a——- c:\windows\system32\iesysprep.dll 2010-09-08 01:56 71,680 a——- c:\windows\system32\iesetup.dll 2010-09-08 00:26 133,632 a——- c:\windows\system32\ieUnatt.exe 2010-09-06 12:20 125,952 a——- c:\windows\system32\srvsvc.dll 2010-09-06 12:19 17,920 a——- c:\windows\system32\netevent.dll 2010-09-06 09:45 304,128 a——- c:\windows\system32\drivers\srv.sys 2010-09-06 09:45 145,408 a——- c:\windows\system32\drivers\srv2.sys 2010-09-06 09:45 102,400 a——- c:\windows\system32\drivers\srvnet.sys 2010-08-31 09:27 2,038,272 a——- c:\windows\system32\win32k.sys 2010-08-26 12:37 157,184 a——- c:\windows\system32\t2embed.dll 2010-08-17 10:11 128,000 a——- c:\windows\system32\spoolsv.exe 2010-08-10 11:53 274,944 a——- c:\windows\system32\schannel.dll 2010-07-24 07:12 1,700 a——- c:\users\nancy\appdata\roaming\wklnhst.dat 2010-03-13 19:08 56 a—h— c:\programdata\ezsidmv.dat 2010-03-13 19:08 56 a—h— c:\progra~2\ezsidmv.dat 2009-11-18 09:53 665,600 a——- c:\windows\inf\drvindex.dat 2009-01-16 10:38 47,360 a——- c:\users\nancy\appdata\roaming\pcouffin.sys 2008-01-20 22:43 174 a–sh— c:\program files\desktop.ini 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2010-02-25 18:48 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat 2010-02-25 18:48 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat 2010-02-25 18:48 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat ============= FINISH: 6:36:11.40 ===============
Hello starwood :welcome:

Before we begin, I would like to make a few things clear so that we can fix your problem as efficiently as possible:
  • Be sure to follow all my instructions carefully! If there is anything you don''t understand, don't hesitate to ask.
  • Please do not do anything or perform other steps unless I have asked you to do so.
  • Please make sure you post all logs I ask you to, and make sure that the entire log gets posted.


Step 1

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan bot paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    C:\Users\Nancy\AppData\Local\Temp\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Step 2

Download the GMER Rootkit Scanner.

  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.


Things I would like to see in your reply:
  • OTL.txt and Extras.txt
  • GMER Log ark.txt
OTL Extras logfile created on: 10/28/2010 10:35:46 AM - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Users\Nancy\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.62 Gb Total Space | 39.94 Gb Free Space | 17.94% Space Free | Partition Type: NTFS
Drive D: | 10.26 Gb Total Space | 1.77 Gb Free Space | 17.24% Space Free | Partition Type: NTFS

Computer Name: NANCY-PC | User Name: Nancy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06CCEEEE-B2FD-4D9B-A6FB-3C399559174B}" = lport=139 | protocol=6 | dir=in | app=system |
"{19B05566-7F85-48AB-9BE4-BA1EF3A7AE7C}" = lport=63331 | protocol=6 | dir=in | name=windows live onecare |
"{2B1769B1-AB79-44CD-A789-48949BEC5ECC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{2FC10A39-CB87-4B1E-9689-1544BFEB22A3}" = rport=138 | protocol=17 | dir=out | app=system |
"{3E7456EE-EBA6-4CC7-A9AA-B50E436ED698}" = rport=445 | protocol=6 | dir=out | app=system |
"{83E1CD29-D477-442D-AF3B-29AAFE3E69A1}" = rport=139 | protocol=6 | dir=out | app=system |
"{95C46074-5F1F-4BA0-8A0B-963425C73422}" = rport=137 | protocol=17 | dir=out | app=system |
"{9959A1C8-999A-4AD6-B19A-D51EAADF29FE}" = lport=138 | protocol=17 | dir=in | app=system |
"{BB1CA5D3-B81B-4246-A9FC-5A0D5610AC7D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{DD41FA77-6448-419F-B4CE-D2928DDE6F64}" = lport=137 | protocol=17 | dir=in | app=system |
"{DE6ED714-1C19-4805-AB83-D3925B7E8C54}" = lport=445 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0491F73D-2C22-400C-97C0-E01D7508864B}" = protocol=17 | dir=in | app=c:\users\nancy\appdata\local\temp\lxdx\wireless\lxdxwpss.exe |
"{0E0B6797-8386-443B-A48B-9574320D844C}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxjswx.exe |
"{17FC5711-33FE-45F2-9E1F-125606D2669E}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{1955615E-9FC7-4FF6-B1DD-41BFBEFF6E30}" = protocol=6 | dir=in | app=c:\windows\system32\lxdxcfg.exe |
"{1C8207B5-AA2B-4621-9DDE-3F3C77C91029}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{1E56F8C6-5ED9-4B53-B38A-CFB603568531}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbvpswx.exe |
"{23313FA4-7520-4DD4-B1C2-50D65DA645FA}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxbvpswx.exe |
"{282D2C7C-C292-42CE-BDD2-9DED70030065}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{2E48C46D-6509-4A4A-B92B-53FD1A8509F8}" = protocol=17 | dir=in | app=c:\program files\lexmark fax solutions\faxctr.exe |
"{35F583FD-05EE-4652-A375-70468EE2BF0E}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxlscn.exe |
"{363CD74F-6396-4C01-889A-2CD4E767269A}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 11\programs\studio.exe |
"{382732BE-9E57-4736-A4BC-C7138E3E47E5}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxpswx.exe |
"{40A1F33F-A32F-465D-8BFC-79D8D3397A8D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4818692E-EA24-4FD1-A157-4D943FC6A46E}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 11\programs\pmsregisterfile.exe |
"{48EC9754-16B9-469B-83D9-A47763880D57}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 11\programs\studio.exe |
"{56683BC5-72BE-41C3-A2C2-8B9FDD8B3F7B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{58F79017-2DCC-4701-9B59-ABB641767F9F}" = protocol=6 | dir=in | app=c:\program files\lexmark fax solutions\faxctr.exe |
"{5E74A649-B32F-401C-8F36-104CA7D9DEB2}" = protocol=17 | dir=in | app=c:\users\nancy\appdata\local\temp\wzse0.tmp\symnrt.exe |
"{6409DDC3-E073-42C8-80D0-5B79D473C804}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\frun.exe |
"{643B3E5E-603E-497B-9B44-090D9FBE6950}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 11\programs\rm.exe |
"{69A8F83C-02E9-43AA-AD9D-1CBFD0AD9F1E}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6A5797E3-A2A1-443C-A1AF-5648FDF571A7}" = protocol=6 | dir=in | app=c:\users\nancy\appdata\local\temp\wzse0.tmp\symnrt.exe |
"{6E55FD26-DDFC-4DBF-80E7-953CCC5D383B}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 11\programs\umi.exe |
"{71D82733-CA8A-4680-9D0A-7D4DD16E7490}" = protocol=6 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{7465A45F-D620-4744-9474-BA7DCE93A0A6}" = protocol=17 | dir=in | app=c:\windows\system32\lxdxcfg.exe |
"{752C1D9F-6F8B-4526-AFA7-85676E5D0DDF}" = protocol=17 | dir=in | app=c:\windows\system32\lxdxcoms.exe |
"{7A105AE8-707E-4B4E-AA76-D7924E7CAB10}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxmon.exe |
"{7C25813C-2D4D-4EAF-BE13-3A3EBA086BBA}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7DF3602D-E85E-4ADD-AB87-3ECE13BA819B}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{7FCD5CCA-274F-4007-9A1A-E508D9B3BAAF}" = protocol=6 | dir=in | app=c:\windows\system32\lxdxcoms.exe |
"{83776BE5-5AE7-4089-8937-5CEF599C8E04}" = protocol=6 | dir=in | app=c:\users\nancy\appdata\local\temp\lxdx\wireless\lxdxwpss.exe |
"{8C18103B-5459-47BE-900C-4542CD5A480B}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{94B22FC1-44D4-40C8-895F-59D5E10BC234}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 11\programs\pmsregisterfile.exe |
"{9B03D075-AB17-4648-8386-B5E800F28EBC}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxtime.exe |
"{A11FB4F5-C2AF-4C0A-93E3-160957BDC3BA}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxlscn.exe |
"{A258EB0F-CBF1-40F4-B4E2-2D3B46F27882}" = protocol=6 | dir=in | app=c:\windows\system32\lxbvcoms.exe |
"{A2E4EC87-9165-496A-8DC3-7F29FB888AE5}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{ABF85EDA-934F-4201-944A-775212FAB6E2}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{AD7A971F-3FB1-4890-BB5C-4267890BBEEB}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{BF5C97BD-EE6A-41E9-92BA-4068F6FAE139}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxpswx.exe |
"{BFE59730-305B-4179-A2F8-13F8F6854D31}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxtime.exe |
"{C23565F8-7F24-4DD7-B87B-4983029AE704}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |
"{C4A38379-8B2E-49B7-A024-B82F344BE82B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{C77A2ABD-87BD-4DA3-88F1-ACF8D81E4C42}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxjswx.exe |
"{C93BD927-C5E9-4669-A7C0-BF5AC62745D8}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\frun.exe |
"{CE743636-5AAD-4B8C-A753-7522D0BAA7F5}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{CEE82779-14D6-4F9C-ABF5-D325FB79F2A4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{D0D5DCD3-F8DF-4DFD-999C-34C5839F990A}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{D49CF06A-D716-41E4-8CBE-D8DECCA7188A}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{DECC8F68-B4DB-4398-9F0A-8FA5E1619193}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxamon.exe |
"{DF1F505B-A0F2-467E-9FD0-3C9BCF91AD5F}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 11\programs\rm.exe |
"{E0321F69-0217-46DB-99E1-85C01A57B4B3}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{E284054B-A59E-4599-B6ED-6C88EA7A6025}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{E66205C7-B72D-4FA3-81A2-5E04575AB04A}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{EC499C7C-C4CA-4A6A-8C07-F770BA6C7F31}" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxmon.exe |
"{EC83CE5C-B0B9-492C-BA5F-3CDEE607B7DC}" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxamon.exe |
"{ECC05825-3FDB-4AA1-AFB2-9A9F1BDA9C0F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{F4CB0A0D-6305-4724-9C8F-A03C0E75D3FC}" = protocol=17 | dir=in | app=c:\windows\system32\lxbvcoms.exe |
"{F546E005-06AC-4A83-8E44-B11CF02FD59A}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 11\programs\umi.exe |
"{FB5B2DFD-BBFA-422F-8D75-C87396196D9C}" = protocol=17 | dir=in | app=c:\program files\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{FF9CF77A-BCAB-4493-B13E-18EE562C1AAB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"TCP Query User{45168E13-390A-4D88-944C-F60DD82DD29B}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{9530B6E8-9C34-467A-BE7D-EF4BED319136}C:\program files\lexmark 3600-4600 series\lxdxmon.exe" = protocol=6 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxmon.exe |
"TCP Query User{D3F7F5BE-6731-4B7A-B31A-4764F0498AAC}C:\windows\system32\spool\drivers\w32x86\3\lxdxpswx.exe" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxpswx.exe |
"TCP Query User{D904A51E-ABC8-48CD-BA1A-937CA0B9EF47}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"UDP Query User{2BF9C700-D30D-4155-A069-50DB782ADE19}C:\program files\itunes\itunes.exe" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"UDP Query User{348A1F2D-CB7B-4D31-A88F-6EB6B965DABB}C:\program files\itunes\itunes.exe" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"UDP Query User{76B422E0-AEAD-44A3-B9B5-DDD9D91605F4}C:\program files\lexmark 3600-4600 series\lxdxmon.exe" = protocol=17 | dir=in | app=c:\program files\lexmark 3600-4600 series\lxdxmon.exe |
"UDP Query User{C5B46627-044D-46DE-A95E-3EAA65FACFA1}C:\windows\system32\spool\drivers\w32x86\3\lxdxpswx.exe" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdxpswx.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
"{110B1ADF-2EAE-4E8F-B501-D2A1E6D8ED9D}" = Studio 11
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}" = Adobe Photoshop Elements 8.0
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 18
"{26A24AE4-039D-4CA4-87B4-2F83216015F0}" = Java™ 6 Update 15
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{280235E3-D1FB-408A-A1D5-C77BA584FBBA}" = BlService Web Update
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{30DAA715-5032-40F9-A0AE-95C9AEBB3E3F}" = HP QuickTouch 1.00 D2
"{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 D1
"{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}" = muvee autoProducer 6.1
"{36BD88D7-8F1A-408E-8810-C267D4C3E524}" = BigOven
"{38EAC694-0D90-445F-8C17-8B50ADFE3162}" = Slingbox Flash Tour
"{395A57A6-E0E1-C599-3A28-19A96682B4C6}" = Adobe Photoshop.com Inspiration Browser
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{45A1BF92-700A-4408-B95E-79F462E3D67D}" = Studio 11 Bonus DVD
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B66BA95-9C4E-4C1C-BD01-E3A66113F0D5}" = Motorola Software Update
"{4C5D15D2-5351-4F05-A96E-56C20554F977}" = RollerCoaster Tycoon 2 Triple Thrill Pack
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{51F96AEC-D902-4434-A0DC-B9692A21AE7C}" = MobileMe Control Panel
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}" = fflink
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{67878E2E-9A34-4374-8F07-A40714B06296}" = BigOven Palm Companion
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B224EF2-1D45-4225-ABE0-E22F69062D81}" = BigOven
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8C0DF485-DB3E-453C-BFB3-4C47E636ECF9}" = Serif WebPlus 10
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{901B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{98C4F0D9-3C09-4BD9-B835-29744B94931A}" = BigOven
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A68AF4D-B8B2-4356-8A57-D0FDE00A26DD}" = BigOven
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A5CE7175-080D-49AC-B5A3-E7E3502428F5}" = HP Wireless Assistant
"{A869A1DA-9571-4287-B170-4A7246994C84}" = Serif WebPlus 10 Resources
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AAD72731-807A-4B79-AE05-9190B7002B7B}" = ProtectSmart Hard Drive Protection
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BB406CEB-6207-4512-9BB2-89950DC9D6B6}_is1" = ConvertXtoDVD 2.2.3.258h
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB54ABA8-D67F-47AD-A76C-2631BADA9FE5}" = Microsoft Works Suite Add-in for Microsoft Word
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D9C8DEF8-D07B-4164-BEF0-6D879A70C212}" = Microsoft Easy Assist v2
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DC2A9072-FB6E-4E0A-BC11-CDF1796A661A}" = BigOven
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{DDC2B636-4F9F-4241-9B15-4DF12C97CF4A}" = Studio 11
"{DE1AF137-C455-494A-A817-EFE44BCCFDEE}" = Works Upgrade
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E0267007-A6FD-4304-8131-346D1CEA6F82}" = BigOven
"{E0783143-EAE2-4047-A8D6-E155523C594C}" = Garmin WebUpdater
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}" = Pinnacle Instant DVD Recorder
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{EFF87108-C9D0-43F1-BEE1-28DA87778F1A}" = Garmin Communicator Plugin
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F48098CD-2D66-4861-85EC-DC1D4D09D5F9}" = HP User Guides 0102
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{F761359C-9CED-45AE-9A51-9D6605CD55C4}" = Evernote
"{F9001C89-8036-4673-9577-E7CD8564807C}" = The Print Shop 20
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{F9AEEC34-CF00-4CBD-9E36-DF9DC4002685}" = Yahoo! Desktop Login
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.7
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"45A7283175C62FAC673F913C1F532C5361F97841" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 8.0" = Adobe Photoshop Elements 8.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AI RoboForm" = AI RoboForm (All Users)
"AIM_6" = AIM 6
"ArtistScope Plugin FX 424.2.0.0" = ArtistScope Plugin FX 42
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"AviSynth" = AviSynth 2.5
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CCleaner" = CCleaner
"CleanUp!" = CleanUp!
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5_is1" = DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.2.3.2
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"Hardware Helper_is1" = Hardware Helper
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"InFlac" = InFlac 1.1.1
"InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Lexmark 3600-4600 Series" = Lexmark 3600-4600 Series
"Lexmark Fax Solutions" = Lexmark Fax Solutions
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Money2005b" = Microsoft Money 2005
"Mouse Manager 1.1.1_is1" = Mouse Manager Version 1.1.1
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"Mozilla Firefox (3.6.11)" = Mozilla Firefox (3.6.11)
"PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.
1" = Adobe Photoshop.com Inspiration Browser
"proDAD-Heroglyph-2.5" = proDAD Heroglyph 2.5
"proDAD-Vitascene-1.0" = proDAD Vitascene 1.0
"Product_Name" = Disney Vacation Planner
"Rugrats Adventure Game 1.0" = Rugrats™ Adventure Game
"screensaver" = screensaver
"Shockwave" = Shockwave
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SpywareBlaster_is1" = SpywareBlaster 4.4
"Swag_Bucks Toolbar" = Swag_Bucks Toolbar
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Videora iPod classic Converter" = Videora iPod classic Converter 5.03
"Videora iPod Converter" = Videora iPod Converter 5.04
"ViewpointMediaPlayer" = Viewpoint Media Player
"VKC180 Photo Viewer_is1" = VKC180 Photo Viewer
"VLC media player" = VLC media player 0.9.8a
"WavePad" = WavePad Sound Editor
"wdcruise2_is1" = wdcruise2
"WebPost" = Microsoft Web Publishing Wizard 1.52
"WildTangent hp Master Uninstall" = My HP Games
"Winamp" = Winamp
"WinRAR archiver" = WinRAR archiver
"Wootalyzer" = Wootalyzer!
"Works2005Setup" = Microsoft Works 2005 Setup Launcher
"YouTube Downloader App" = YouTube Downloader App 3.00

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"uTorrent" = µTorrent
"Vacation Countdown v1" = Vacation_Countdown
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/26/2010 8:16:11 AM | Computer Name = Nancy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1123

Error - 5/26/2010 8:16:12 AM | Computer Name = Nancy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/26/2010 8:16:12 AM | Computer Name = Nancy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2231

Error - 5/26/2010 8:16:12 AM | Computer Name = Nancy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2231

Error - 5/26/2010 8:16:13 AM | Computer Name = Nancy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/26/2010 8:16:13 AM | Computer Name = Nancy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3229

Error - 5/26/2010 8:16:13 AM | Computer Name = Nancy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3229

Error - 5/26/2010 8:24:28 AM | Computer Name = Nancy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/26/2010 8:24:31 AM | Computer Name = Nancy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 498220

Error - 5/26/2010 8:24:31 AM | Computer Name = Nancy-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 498220

[ Media Center Events ]
Error - 7/3/2009 5:28:38 PM | Computer Name = Nancy-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ OSession Events ]
Error - 6/24/2010 7:29:55 PM | Computer Name = Nancy-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6535.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 104
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 10/28/2010 5:24:14 AM | Computer Name = Nancy-PC | Source = HTTP | ID = 15021
Description =

Error - 10/28/2010 5:24:14 AM | Computer Name = Nancy-PC | Source = HTTP | ID = 15021
Description =

Error - 10/28/2010 5:24:44 AM | Computer Name = Nancy-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 10/28/2010 5:24:44 AM | Computer Name = Nancy-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 10/28/2010 5:24:44 AM | Computer Name = Nancy-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 10/28/2010 5:24:44 AM | Computer Name = Nancy-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 10/28/2010 5:24:44 AM | Computer Name = Nancy-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 10/28/2010 5:25:57 AM | Computer Name = Nancy-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 10/28/2010 5:25:57 AM | Computer Name = Nancy-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 10/28/2010 8:54:33 AM | Computer Name = Nancy-PC | Source = DCOM | ID = 10010
Description =


< End of report >
OTL logfile created on: 10/28/2010 10:35:46 AM - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Users\Nancy\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.62 Gb Total Space | 39.94 Gb Free Space | 17.94% Space Free | Partition Type: NTFS
Drive D: | 10.26 Gb Total Space | 1.77 Gb Free Space | 17.24% Space Free | Partition Type: NTFS

Computer Name: NANCY-PC | User Name: Nancy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/10/28 10:33:08 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Nancy\Downloads\OTL.exe
PRC - [2010/10/28 05:57:39 | 000,241,664 | —- | M] (CJSC Computing Forces) – C:\Users\Nancy\AppData\Local\Temp\Yh4.exe
PRC - [2010/10/28 05:57:20 | 000,262,144 | —- | M] (CJSC Computing Forces) – C:\Users\Nancy\AppData\Local\Temp\Yh2.exe
PRC - [2010/10/28 05:57:11 | 000,258,048 | —- | M] (CJSC Computing Forces) – C:\Users\Nancy\AppData\Local\Temp\Yh0.exe
PRC - [2010/10/28 05:56:36 | 000,011,812 | —- | M] () – C:\Users\Nancy\AppData\Local\Temp\moxecsnawr.exe
PRC - [2010/10/17 06:22:50 | 000,160,328 | —- | M] (Siber Systems) – C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
PRC - [2010/09/01 10:16:38 | 004,120,000 | —- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) – C:\Program Files\Evernote\Evernote3.5\Evernote.exe
PRC - [2010/08/13 12:58:56 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2010/03/25 21:40:42 | 000,203,312 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
PRC - [2010/03/18 11:19:26 | 000,207,360 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/02/04 01:28:02 | 000,025,256 | —- | M] () – C:\Program Files\Lexmark 3600-4600 Series\lxdxmsdmon.exe
PRC - [2010/02/04 01:27:55 | 000,672,424 | —- | M] () – C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe
PRC - [2009/10/16 13:10:34 | 000,589,824 | —- | M] ( ) – C:\Windows\System32\lxdxcoms.exe
PRC - [2009/09/06 07:06:20 | 000,169,312 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
PRC - [2009/07/21 22:33:32 | 000,458,844 | —- | M] (IDT, Inc.) – C:\Program Files\IDT\WDM\sttray.exe
PRC - [2009/07/21 22:33:32 | 000,221,266 | —- | M] (IDT, Inc.) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\stacsv.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/03/02 18:43:08 | 000,081,920 | —- | M] (Andrea Electronics Corporation) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\AEstSrv.exe
PRC - [2009/02/07 08:56:47 | 000,266,240 | —- | M] () – C:\Windows\System32\CSHelper.exe
PRC - [2008/09/29 13:19:22 | 000,415,744 | —- | M] () – C:\Program Files\Atomic Alarm Clock\timeserv.exe
PRC - [2008/08/22 16:32:06 | 000,361,808 | —- | M] () – C:\Windows\SMINST\BLService.exe
PRC - [2008/04/15 21:54:42 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/15 21:54:40 | 000,178,712 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007/04/25 14:18:48 | 000,537,520 | —- | M] ( ) – C:\Windows\System32\lxbvcoms.exe
PRC - [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe


========== Modules (SafeList) ==========

MOD - [2010/10/28 10:33:08 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Nancy\Downloads\OTL.exe
MOD - [2010/08/31 11:43:52 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/08/13 12:58:56 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/03/25 21:40:44 | 000,017,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
SRV - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [Auto | Running] – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2009/11/16 13:46:57 | 000,867,080 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2009/10/16 13:10:34 | 000,589,824 | —- | M] ( ) [Auto | Running] – C:\Windows\System32\lxdxcoms.exe – (lxdx_device)
SRV - [2009/10/16 13:00:50 | 000,094,208 | —- | M] () [Auto | Stopped] – C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxdxserv.exe – (lxdxCATSCustConnectService)
SRV - [2009/09/24 21:27:04 | 000,793,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\FntCache.dll – (FontCache)
SRV - [2009/09/06 07:06:20 | 000,169,312 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor8.0)
SRV - [2009/07/21 22:33:32 | 000,221,266 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\stacsv.exe – (STacSV)
SRV - [2009/03/02 18:43:08 | 000,081,920 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\AEstSrv.exe – (AESTFilters)
SRV - [2009/02/07 08:56:47 | 000,266,240 | —- | M] () [Auto | Running] – C:\Windows\System32\CSHelper.exe – (CSHelper)
SRV - [2008/09/29 13:19:22 | 000,415,744 | —- | M] () [Auto | Running] – C:\Program Files\Atomic Alarm Clock\timeserv.exe – (AtomicAlarmClock)
SRV - [2008/08/22 16:32:06 | 000,361,808 | —- | M] () [Auto | Running] – C:\Windows\SMINST\BLService.exe – (Recovery Service for Windows)
SRV - [2008/04/15 21:54:42 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2008/01/20 22:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/04/25 14:18:48 | 000,537,520 | —- | M] ( ) [Auto | Running] – C:\Windows\System32\lxbvcoms.exe – (lxbv_device)
SRV - [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto | Running] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2005/02/09 11:59:00 | 000,014,165 | —- | M] (Pinnacle Systems GmbH) [Auto | Stopped] – C:\Windows\System32\drivers\Pclepci.sys – (PCLEPCI)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\PalmUSBD.sys – (PalmUSBD)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\iPodDrv.sys – (iPodDrv)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\ComboFix\catchme.sys – (catchme)
DRV - [2010/03/25 21:30:22 | 000,042,368 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\MpNWMon.sys – (MpNWMon)
DRV - [2009/07/21 22:33:32 | 000,409,088 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\stwrt.sys – (STHDA)
DRV - [2009/05/25 06:50:44 | 000,164,864 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Rtlh86.sys – (RTL8169)
DRV - [2009/04/11 00:42:54 | 000,073,216 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2009/03/26 08:00:02 | 000,064,000 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\RTSTOR.sys – (RTSTOR)
DRV - [2008/10/23 02:16:28 | 001,331,192 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XX)
DRV - [2008/10/23 02:16:28 | 001,331,192 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XV)
DRV - [2008/06/12 14:43:16 | 002,381,312 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\igdkmd32.sys – (igfx)
DRV - [2008/06/04 13:54:22 | 000,113,664 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV - [2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\iaStor.sys – (iaStor)
DRV - [2008/03/28 02:06:00 | 000,199,472 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\SynTP.sys – (SynTP)
DRV - [2008/03/27 16:12:12 | 000,024,424 | —- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\hpdskflt.sys – (hpdskflt)
DRV - [2008/03/27 16:11:34 | 000,034,664 | —- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Accelerometer.sys – (Accelerometer)
DRV - [2008/01/24 09:23:12 | 000,052,736 | —- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\enecir.sys – (enecir)
DRV - [2008/01/20 22:23:27 | 000,386,616 | —- | M] (LSI Corporation, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\megasr.sys – (MegaSR)
DRV - [2008/01/20 22:23:27 | 000,149,560 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2008/01/20 22:23:27 | 000,031,288 | —- | M] (LSI Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2008/01/20 22:23:26 | 000,101,432 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2008/01/20 22:23:26 | 000,074,808 | —- | M] (Silicon Integrated Systems) [Kernel | Boot | Running] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2008/01/20 22:23:26 | 000,040,504 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2008/01/20 22:23:25 | 000,300,600 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2008/01/20 22:23:25 | 000,089,656 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2008/01/20 22:23:24 | 001,122,360 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2008/01/20 22:23:24 | 000,118,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2008/01/20 22:23:24 | 000,079,928 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2008/01/20 22:23:23 | 000,654,336 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTCNXT3.SYS – (winachsf)
DRV - [2008/01/20 22:23:23 | 000,235,064 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2008/01/20 22:23:23 | 000,130,616 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2008/01/20 22:23:23 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2008/01/20 22:23:23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2008/01/20 22:23:23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2008/01/20 22:23:23 | 000,079,416 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2008/01/20 22:23:22 | 000,987,648 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTDPV3.SYS – (HSF_DPV)
DRV - [2008/01/20 22:23:22 | 000,342,584 | —- | M] (Emulex) [Kernel | Boot | Running] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2008/01/20 22:23:22 | 000,200,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTAZL3.SYS – (HSFHWAZL)
DRV - [2008/01/20 22:23:21 | 000,422,968 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2008/01/20 22:23:21 | 000,102,968 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2008/01/20 22:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2008/01/20 22:23:20 | 000,238,648 | —- | M] (ULi Electronics Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2008/01/20 22:23:00 | 000,020,024 | —- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2008/01/20 22:23:00 | 000,019,000 | —- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2008/01/20 22:23:00 | 000,017,464 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2007/07/11 13:30:22 | 000,007,168 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\HpqRemHid.sys – (HpqRemHid)
DRV - [2007/06/18 20:12:04 | 000,016,768 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HpqKbFiltr.sys – (HpqKbFiltr)
DRV - [2007/01/04 09:07:00 | 000,171,520 | —- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\MarvinBus.sys – (MarvinBus)
DRV - [2006/12/12 11:16:06 | 000,022,528 | —- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emAudio.sys – (emAudio)
DRV - [2006/11/02 05:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 05:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 05:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 05:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Boot | Running] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 05:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 05:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 05:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 05:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 05:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 05:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 05:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 04:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 04:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 04:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 04:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 04:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 04:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 03:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2006/11/02 03:30:56 | 000,429,056 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvm60x32.sys – (NVENETFD)
DRV - [2005/12/21 09:14:52 | 000,100,957 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emDevice.sys – (DCamUSBEMPIA)
DRV - [2005/12/21 09:14:52 | 000,005,245 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emFilter.sys – (FiltUSBEMPIA)
DRV - [2005/12/21 09:14:52 | 000,004,493 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emScan.sys – (ScanUSBEMPIA)
DRV - [2005/06/24 18:36:16 | 000,039,036 | —- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lgusbmodem.sys – (USBModem)
DRV - [2005/05/26 11:01:36 | 000,038,144 | —- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lgusbdiag.sys – (UsbDiag)
DRV - [2005/05/26 11:01:18 | 000,021,344 | —- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lgusbbus.sys – (usbbus)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\..\URLSearchHook: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Swag Bucks Customized Web Search"
FF - prefs.js..browser.startup.homepage: "https://login.yahoo.com/config/mail?.src=ym&.intl=us"
FF - prefs.js..extensions.enabledItems: {097d3191-e6fa-4728-9826-b533d755359d}:0.7.11
FF - prefs.js..extensions.enabledItems: {0C7E3F01-99E9-4095-9BDC-F84724960B57}:[removed]
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..extensions.enabledItems: {E0B8C461-F8FB-49b4-8373-FE32E9252800}:4.0.0.106602
FF - prefs.js..extensions.enabledItems: {6e84150a-d526-41f1-a480-a67d3fed910d}:[removed]
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {a92aadf8-193f-4a62-8740-5cce81775afc}:1.0.7
FF - prefs.js..extensions.enabledItems: [removed]:1.7
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.10.1
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.2
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.1.0
FF - prefs.js..extensions.enabledItems: {ff356687-aa08-463d-a46c-11c451824939}:5.0.0


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/30 15:49:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2008/12/01 19:47:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/22 05:29:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/22 05:29:45 | 000,000,000 | —D | M]

[2008/12/01 12:04:41 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Mozilla\Extensions
[2010/10/27 11:04:56 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions
[2010/01/18 09:05:27 | 000,000,000 | —D | M] (All-in-One Sidebar) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d}
[2009/02/06 08:51:07 | 000,000,000 | —D | M] (Coupon Manager) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{0C7E3F01-99E9-4095-9BDC-F84724960B57}
[2010/10/03 18:18:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2008/12/02 07:10:45 | 000,000,000 | —D | M] (Adblock) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2010/10/28 06:14:37 | 000,000,000 | —D | M] (AddThis) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2010/01/26 10:06:26 | 000,000,000 | —D | M] (IE View) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2010/10/24 07:51:34 | 000,000,000 | —D | M] (NoScript) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/08/19 09:32:41 | 000,000,000 | —D | M] (Swag Bucks Toolbar) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
[2010/02/07 10:14:32 | 000,000,000 | —D | M] (Woot Watcher) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{a92aadf8-193f-4a62-8740-5cce81775afc}
[2010/10/24 07:51:34 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/10/28 06:14:37 | 000,000,000 | —D | M] (Evernote Web Clipper) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}
[2010/03/16 10:35:49 | 000,000,000 | —D | M] (Red Cats (blue flavor)) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{ff356687-aa08-463d-a46c-11c451824939}
[2010/05/13 10:45:15 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\[removed]
[2010/01/23 07:42:37 | 000,000,652 | —- | M] () – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\searchplugins\aol-search.xml
[2009/09/01 12:24:10 | 000,000,882 | —- | M] () – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\searchplugins\conduit.xml
[2009/05/25 10:02:54 | 000,002,357 | —- | M] () – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\searchplugins\photobucket.xml
[2010/09/10 05:58:10 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/01/07 13:16:58 | 000,609,280 | —- | M] (ArtistScope) – C:\Program Files\Mozilla Firefox\plugins\npArtistScope42.dll
[2010/04/11 08:38:52 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
[2009/11/19 17:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/11/19 17:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2010/07/12 12:33:56 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2010/08/27 07:08:43 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Swag Bucks Toolbar) - {8BDEA9D6-6F62-45EB-8EE9-8A81AF0D2F94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [lxdxamon] C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe ()
O4 - HKLM..\Run: [lxdxmon.exe] C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
O4 - HKLM..\Run: [mumservice] C:\Program Files\Motorola\Software Update\mumservice.exe (Motorola)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [USB2Check] C:\Windows\System32\PCLECoInst.DLL (Pinnacle Systems)
O4 - HKCU..\Run: [Metropolis] C:\Users\Nancy\AppData\Local\Temp\sshnas21.DLL File not found
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [U36VRSFLG6] C:\Users\Nancy\AppData\Local\Temp\Yh2.exe (CJSC Computing Forces)
O4 - Startup: C:\Users\Nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Vacation_Countdown.lnk = C:\Program Files\Vacation Countdown v1\Vacation_Countdown.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: smoxgbyq = rundll32 "C:\Users\Nancy\AppData\Roaming\C_1255U.dll",hnpmmh ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to &Evernote - C:\Program Files\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Nancy\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Nancy\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/31 12:48:42 | 000,000,169 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.iac2 - C:\Windows\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msaudio1 - msaud32.acm File not found
Drivers32: msacm.msg723 - msg723.acm File not found
Drivers32: msacm.sl_anet - sl_anet.acm File not found
Drivers32: msacm.trspch - tssoft32.acm File not found
Drivers32: msacm.voxacm160 - vct3216.acm File not found
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.DRAW - DVIDEO.DLL File not found
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - frapsvid.dll File not found
Drivers32: VIDC.I420 - C:\Windows\System32\emYUV.dll (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\Windows\System32\ir32_32.dll (Intel® Corporation)
Drivers32: vidc.iv32 - C:\Windows\System32\ir32_32.dll (Intel® Corporation)
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.M261 - msh261.drv File not found
Drivers32: vidc.M263 - msh263.drv File not found
Drivers32: VIDC.MJPG - C:\Windows\System32\pvmjpg30.dll (Pegasus Imaging Corporation)
Drivers32: VIDC.MSUD - msulvc05.dll File not found
Drivers32: VIDC.VP40 - vp4vfw.dll File not found
Drivers32: vidc.VP60 - vp6vfw.dll File not found
Drivers32: vidc.VP61 - vp6vfw.dll File not found
Drivers32: vidc.VP62 - vp6vfw.dll File not found
Drivers32: vidc.VP70 - vp7vfw.dll File not found
Drivers32: VIDC.WMV3 - wmv9vcm.dll File not found
Drivers32: vidc.X264 - x264vfw.dll File not found
Drivers32: vidc.yv12 - yv12vfw.dll File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/10/28 05:56:17 | 000,000,000 | —D | C] – C:\Users\Nancy\AppData\Roaming\1D74787EA28A0C2204A55622B0866299
[2010/10/14 06:14:48 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2010/10/14 06:14:29 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2010/10/14 06:14:13 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/10/14 06:14:09 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/10/14 06:14:09 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/10/14 06:14:09 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/10/14 06:14:07 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/10/14 06:14:07 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/10/14 06:14:06 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/10/14 06:14:06 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/10/14 06:14:06 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/10/14 06:14:06 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/10/14 06:14:06 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/10/14 06:14:05 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/10/14 06:14:05 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/10/14 06:14:04 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/10/14 06:14:04 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/10/14 06:14:04 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/10/14 06:14:04 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/10/14 06:14:04 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/10/14 06:14:02 | 000,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2010/10/14 06:14:00 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/10/14 06:13:59 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2010/10/14 06:13:58 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2010/10/14 06:13:56 | 000,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2010/10/09 07:04:45 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/10/09 07:04:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/10/09 07:04:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/09/29 06:21:00 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/09/22 06:11:34 | 000,409,600 | —- | C] ( ) – C:\Windows\System32\lxdxcoin.dll
[2009/08/13 08:23:00 | 000,438,272 | —- | C] ( ) – C:\Windows\System32\LXDXhcp.dll
[2009/08/13 08:22:59 | 000,843,776 | —- | C] ( ) – C:\Windows\System32\lxdxusb1.dll
[2009/08/13 08:22:59 | 000,364,544 | —- | C] ( ) – C:\Windows\System32\lxdxinpa.dll
[2009/08/13 08:22:59 | 000,339,968 | —- | C] ( ) – C:\Windows\System32\lxdxiesc.dll
[2009/08/13 08:22:58 | 001,105,920 | —- | C] ( ) – C:\Windows\System32\lxdxserv.dll
[2009/08/13 08:22:58 | 000,647,168 | —- | C] ( ) – C:\Windows\System32\lxdxpmui.dll
[2009/08/13 08:22:58 | 000,569,344 | —- | C] ( ) – C:\Windows\System32\lxdxlmpm.dll
[2009/08/13 08:22:58 | 000,053,248 | —- | C] ( ) – C:\Windows\System32\lxdxprox.dll
[2009/08/13 08:22:56 | 000,663,552 | —- | C] ( ) – C:\Windows\System32\lxdxhbn3.dll
[2009/08/13 08:22:54 | 000,376,832 | —- | C] ( ) – C:\Windows\System32\lxdxcomm.dll
[2009/08/13 08:22:53 | 000,851,968 | —- | C] ( ) – C:\Windows\System32\lxdxcomc.dll
[2009/01/16 10:29:48 | 000,047,360 | —- | C] (VSO Software) – C:\Users\Nancy\AppData\Roaming\pcouffin.sys
[2007/04/04 07:40:30 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxbvpmui.dll
[2007/04/04 07:39:22 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxbvserv.dll
[2007/04/04 07:34:14 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxbvcomm.dll
[2007/04/04 07:32:50 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbvlmpm.dll
[2007/04/04 07:31:40 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbviesc.dll
[2007/04/04 07:29:30 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxbvpplc.dll
[2007/04/04 07:28:44 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxbvcomc.dll
[2007/04/04 07:28:12 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxbvprox.dll
[2007/04/04 07:22:26 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxbvinpa.dll
[2007/04/04 07:21:52 | 000,995,328 | —- | C] ( ) – C:\Windows\System32\lxbvusb1.dll
[2007/04/04 07:18:20 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxbvhbn3.dll

========== Files - Modified Within 30 Days ==========

[2010/10/28 10:38:27 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{4589B50F-0A1A-4793-AFDB-E1E44D61A7E4}.job
[2010/10/28 10:27:09 | 000,000,286 | -H– | M] () – C:\Windows\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/10/28 10:20:22 | 000,000,286 | -H– | M] () – C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/10/28 10:05:01 | 000,000,286 | -H– | M] () – C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/10/28 09:24:10 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/28 09:24:10 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/28 08:09:03 | 000,000,349 | —- | M] () – C:\Users\Public\Documents\PCLECHAL.INI
[2010/10/28 06:22:07 | 000,001,816 | —- | M] () – C:\Users\Nancy\Documents\cc_20101028_062205.reg
[2010/10/28 06:21:56 | 000,000,082 | —- | M] () – C:\Users\Nancy\Documents\cc_20101028_062155.reg
[2010/10/28 05:57:10 | 000,103,424 | RHS- | M] () – C:\Users\Nancy\AppData\Roaming\C_1255U.dll
[2010/10/28 05:25:39 | 000,000,284 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2010/10/28 05:24:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/28 05:24:02 | 3149,090,816 | -HS- | M] () – C:\hiberfil.sys
[2010/10/27 10:55:08 | 000,000,322 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForNancy.job
[2010/10/22 05:29:11 | 000,008,391 | —- | M] () – C:\Windows\System32\hpasset.xml
[2010/10/19 16:51:33 | 000,222,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/10/18 08:46:54 | 000,634,088 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/10/18 08:46:54 | 000,117,244 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/10/16 13:38:42 | 000,011,786 | —- | M] () – C:\Users\Nancy\Documents\cc_20101016_133839.reg
[2010/10/15 07:39:43 | 002,691,440 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/15 03:02:11 | 000,008,391 | —- | M] () – C:\Windows\System32\hpasset.xml.bkp
[2010/10/13 06:19:45 | 000,000,942 | —- | M] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/10/13 06:09:32 | 000,018,622 | —- | M] () – C:\Users\Nancy\Documents\cc_20101013_060924.reg
[2010/10/13 06:07:22 | 000,000,804 | —- | M] () – C:\Users\Nancy\Desktop\CCleaner.lnk
[2010/10/08 07:12:27 | 000,001,887 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/10/04 17:43:45 | 000,101,888 | —- | M] () – C:\Users\Nancy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== Files Created - No Company Name ==========

[2010/10/28 07:37:09 | 000,000,286 | -H– | C] () – C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/10/28 06:22:06 | 000,001,816 | —- | C] () – C:\Users\Nancy\Documents\cc_20101028_062205.reg
[2010/10/28 06:21:56 | 000,000,082 | —- | C] () – C:\Users\Nancy\Documents\cc_20101028_062155.reg
[2010/10/28 05:57:42 | 000,000,286 | -H– | C] () – C:\Windows\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/10/28 05:57:24 | 000,000,286 | -H– | C] () – C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/10/28 05:57:10 | 000,103,424 | RHS- | C] () – C:\Users\Nancy\AppData\Roaming\C_1255U.dll
[2010/10/16 13:38:40 | 000,011,786 | —- | C] () – C:\Users\Nancy\Documents\cc_20101016_133839.reg
[2010/10/13 06:09:28 | 000,018,622 | —- | C] () – C:\Users\Nancy\Documents\cc_20101013_060924.reg
[2010/10/08 07:12:27 | 000,001,887 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/09/22 06:32:43 | 000,000,248 | —- | C] () – C:\ProgramData\lxdxDiagnostics.log
[2010/09/22 06:14:37 | 000,782,336 | —- | C] () – C:\Windows\System32\lxdxdrs.dll
[2010/09/22 06:14:37 | 000,081,920 | —- | C] () – C:\Windows\System32\lxdxcaps.dll
[2010/09/21 18:54:09 | 000,000,000 | —- | C] () – C:\ProgramData\UpdaterLog.txt
[2010/08/02 15:28:55 | 000,000,127 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010/08/02 15:20:26 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/03/13 19:08:26 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/10/02 17:35:39 | 000,021,840 | —- | C] () – C:\Windows\System32\SIntfNT.dll
[2009/10/02 17:35:39 | 000,017,212 | —- | C] () – C:\Windows\System32\SIntf32.dll
[2009/10/02 17:35:39 | 000,012,067 | —- | C] () – C:\Windows\System32\SIntf16.dll
[2009/10/02 17:32:51 | 000,000,115 | —- | C] () – C:\Windows\disney.ini
[2009/09/08 08:44:02 | 000,208,896 | —- | C] () – C:\Windows\System32\lxdxgrd.dll
[2009/08/13 08:28:19 | 000,040,960 | —- | C] () – C:\Windows\System32\lxdxvs.dll
[2009/08/13 08:26:47 | 000,069,632 | —- | C] () – C:\Windows\System32\lxdxcnv4.dll
[2009/08/13 08:25:51 | 000,045,056 | —- | C] () – C:\Windows\System32\LXF3PMON.DLL
[2009/08/13 08:25:51 | 000,032,768 | —- | C] () – C:\Windows\System32\LXF3FXPU.DLL
[2009/08/13 08:25:30 | 000,053,248 | —- | C] () – C:\Windows\System32\lxf3oem.dll
[2009/08/13 08:25:30 | 000,012,288 | —- | C] () – C:\Windows\System32\LXF3PMRC.DLL
[2009/08/13 08:23:19 | 000,000,044 | —- | C] () – C:\Windows\System32\lxdxrwrd.ini
[2009/08/13 08:23:00 | 000,348,160 | —- | C] () – C:\Windows\System32\LXDXinst.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/06/16 09:38:24 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/04/24 08:06:09 | 000,120,200 | —- | C] () – C:\Windows\System32\DLLDEV32i.dll
[2009/04/24 08:05:40 | 000,005,937 | —- | C] () – C:\Windows\mgxoschk.ini
[2009/03/31 13:41:32 | 000,000,024 | —- | C] () – C:\ProgramData\__FileUploader.log
[2009/03/31 13:32:39 | 000,000,017 | —- | C] () – C:\Windows\MovingPicture.ini
[2009/03/31 12:33:54 | 000,196,096 | —- | C] () – C:\Windows\System32\macd32.dll
[2009/03/31 12:33:54 | 000,138,752 | —- | C] () – C:\Windows\System32\mase32.dll
[2009/03/31 12:33:54 | 000,136,192 | —- | C] () – C:\Windows\System32\mamc32.dll
[2009/03/31 12:33:54 | 000,057,856 | —- | C] () – C:\Windows\System32\masd32.dll
[2009/03/31 12:33:54 | 000,027,648 | —- | C] () – C:\Windows\System32\ma32.dll
[2009/03/30 08:07:10 | 000,000,511 | —- | C] () – C:\Users\Nancy\AppData\Roaming\alarms.ini
[2009/03/30 08:06:24 | 000,000,812 | —- | C] () – C:\Users\Nancy\AppData\Roaming\AtomicAlarmClock.ini
[2009/03/05 06:54:58 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/02/24 09:18:22 | 000,000,680 | —- | C] () – C:\Users\Nancy\AppData\Local\d3d9caps.dat
[2009/02/12 18:40:08 | 000,000,321 | —- | C] () – C:\Windows\System32\XMLConfig_SYSID.ini
[2009/01/18 17:10:07 | 000,012,288 | —- | C] () – C:\Windows\impborl.dll
[2009/01/18 08:34:55 | 000,000,094 | —- | C] () – C:\Windows\family.ini
[2009/01/18 08:00:44 | 000,000,000 | —- | C] () – C:\Windows\QuickInstall.INI
[2009/01/16 10:35:23 | 000,001,041 | —- | C] () – C:\Users\Nancy\AppData\Roaming\vso_ts_preview.xml
[2009/01/16 10:30:22 | 000,000,034 | —- | C] () – C:\Users\Nancy\AppData\Roaming\pcouffin.log
[2009/01/16 10:29:48 | 000,007,887 | —- | C] () – C:\Users\Nancy\AppData\Roaming\pcouffin.cat
[2009/01/16 10:29:48 | 000,001,144 | —- | C] () – C:\Users\Nancy\AppData\Roaming\pcouffin.inf
[2008/12/18 14:45:31 | 000,000,050 | —- | C] () – C:\Windows\coowiz20.ini
[2008/12/05 10:46:05 | 000,000,466 | —- | C] () – C:\Windows\Lexstat.ini
[2008/12/03 09:42:04 | 000,001,700 | —- | C] () – C:\Users\Nancy\AppData\Roaming\wklnhst.dat
[2008/12/03 09:36:23 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/12/02 06:40:09 | 000,101,888 | —- | C] () – C:\Users\Nancy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/01 23:28:41 | 000,000,000 | —- | C] () – C:\Users\Nancy\AppData\Local\QSwitch.txt
[2008/12/01 23:28:41 | 000,000,000 | —- | C] () – C:\Users\Nancy\AppData\Local\DSwitch.txt
[2008/12/01 23:28:41 | 000,000,000 | —- | C] () – C:\Users\Nancy\AppData\Local\AtStart.txt
[2008/07/01 04:28:04 | 000,000,736 | —- | C] () – C:\ProgramData\hpzinstall.log
[2008/06/12 14:59:22 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1502.dll
[2008/06/04 13:54:12 | 000,004,608 | —- | C] () – C:\Windows\System32\HdmiCoin.dll
[2007/04/24 07:47:28 | 000,413,696 | —- | C] () – C:\Windows\System32\lxbvutil.dll
[2007/02/22 14:32:00 | 000,344,064 | —- | C] () – C:\Windows\System32\lxbvcoin.dll
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 05:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2005/10/25 23:12:10 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbvvs.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/03/31 12:48:42 | 000,000,169 | —- | M] () – C:\AUTOEXEC.BAT
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2010/08/27 07:19:23 | 000,027,776 | —- | M] () – C:\ComboFix.txt
[2006/09/18 17:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/10/28 05:24:02 | 3149,090,816 | -HS- | M] () – C:\hiberfil.sys
[2008/12/02 09:16:40 | 003,914,220 | —- | M] () – C:\HuskyInstallerLog.txt
[2009/01/15 10:53:36 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/12/01 23:20:14 | 000,000,366 | -H– | M] () – C:\IPH.PH
[2009/01/15 10:49:37 | 000,000,156 | —- | M] () – C:\lxbv.log
[2009/01/15 10:53:36 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/02/18 08:24:38 | 000,417,792 | —- | M] (Invenda Corporation) – C:\NPcol305.dll
[2010/10/28 05:24:01 | 3462,676,480 | -HS- | M] () – C:\pagefile.sys
[2009/01/05 11:27:02 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 23:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 23:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 23:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< C:\Users\Nancy\AppData\Local\Temp\*.* >
[2010/10/28 10:37:06 | 000,120,868 | —- | M] () – C:\Users\Nancy\AppData\Local\Temp\a.dat
[2010/10/28 07:13:20 | 000,398,744 | R— | M] (Coupons, Inc.) – C:\Users\Nancy\AppData\Local\Temp\cpnprt2.cid
[2010/10/27 18:09:36 | 000,000,002 | —- | M] () – C:\Users\Nancy\AppData\Local\Temp\ehmsas.txt
[2010/10/28 05:56:36 | 000,011,812 | —- | M] () – C:\Users\Nancy\AppData\Local\Temp\moxecsnawr.exe
[2010/10/28 06:32:23 | 000,031,832 | —- | M] () – C:\Users\Nancy\AppData\Local\Temp\Nancy.bmp
[2010/10/28 05:57:11 | 000,307,200 | —- | M] (CJSC Computing Forces) – C:\Users\Nancy\AppData\Local\Temp\sshnas21.dll_old
[2010/10/28 05:57:11 | 000,258,048 | —- | M] (CJSC Computing Forces) – C:\Users\Nancy\AppData\Local\Temp\Yh0.exe
[2010/10/28 05:57:20 | 000,262,144 | —- | M] (CJSC Computing Forces) – C:\Users\Nancy\AppData\Local\Temp\Yh2.exe
[2010/10/28 05:57:39 | 000,241,664 | —- | M] (CJSC Computing Forces) – C:\Users\Nancy\AppData\Local\Temp\Yh4.exe
[6 C:\Users\Nancy\AppData\Local\Temp\*.tmp files -> C:\Users\Nancy\AppData\Local\Temp\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-15 11:34:07

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >


I'm still working on Gmer
hi

Step 1

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O4 - HKCU..\Run: [Metropolis] C:\Users\Nancy\AppData\Local\Temp\sshnas21.DLL File not found
    O4 - HKCU..\Run: [U36VRSFLG6] C:\Users\Nancy\AppData\Local\Temp\Yh2.exe (CJSC Computing Forces)
    [2010/10/28 10:27:09 | 000,000,286 | -H– | M] () – C:\Windows\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
    [2010/10/28 10:20:22 | 000,000,286 | -H– | M] () – C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
    [2010/10/28 10:05:01 | 000,000,286 | -H– | M] () – C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
    [2010/10/28 05:57:10 | 000,103,424 | RHS- | M] () – C:\Users\Nancy\AppData\Roaming\C_1255U.dll
    [2009/04/24 08:05:40 | 000,005,937 | —- | C] () – C:\Windows\mgxoschk.ini
    [2010/10/28 10:37:06 | 000,120,868 | —- | M] () – C:\Users\Nancy\AppData\Local\Temp\a.dat
    [2010/10/28 05:56:36 | 000,011,812 | —- | M] () – C:\Users\Nancy\AppData\Local\Temp\moxecsnawr.exe
    [2010/10/28 05:57:11 | 000,307,200 | —- | M] (CJSC Computing Forces) – C:\Users\Nancy\AppData\Local\Temp\sshnas21.dll_old
    [2010/10/28 05:57:11 | 000,258,048 | —- | M] (CJSC Computing Forces) – C:\Users\Nancy\AppData\Local\Temp\Yh0.exe
    [2010/10/28 05:57:20 | 000,262,144 | —- | M] (CJSC Computing Forces) – C:\Users\Nancy\AppData\Local\Temp\Yh2.exe
    [2010/10/28 05:57:39 | 000,241,664 | —- | M] (CJSC Computing Forces) – C:\Users\Nancy\AppData\Local\Temp\Yh4.exe
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Step 2

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

Step 3

Things I would like to see in your reply:
  • OTL log
  • MBAM log
  • Combofix log located in C:\Combofix.txt
I did get an error message on rebooting about a .dll not found.

OTL logfile created on: 10/28/2010 12:44:01 PM - Run 2
OTL by OldTimer - Version 3.2.17.1 Folder = c:\Users\Nancy\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 53.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.62 Gb Total Space | 39.56 Gb Free Space | 17.77% Space Free | Partition Type: NTFS
Drive D: | 10.26 Gb Total Space | 1.77 Gb Free Space | 17.24% Space Free | Partition Type: NTFS

Computer Name: NANCY-PC | User Name: Nancy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/10/28 10:33:08 | 000,575,488 | —- | M] (OldTimer Tools) – c:\Users\Nancy\Downloads\OTL.exe
PRC - [2010/10/17 06:22:50 | 000,160,328 | —- | M] (Siber Systems) – C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
PRC - [2010/09/15 04:34:02 | 001,094,224 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/09/01 10:16:38 | 004,120,000 | —- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) – C:\Program Files\Evernote\Evernote3.5\Evernote.exe
PRC - [2010/08/13 12:58:56 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/04/29 15:39:32 | 001,090,952 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2010/03/18 11:19:26 | 000,207,360 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/02/04 01:28:02 | 000,025,256 | —- | M] () – C:\Program Files\Lexmark 3600-4600 Series\lxdxmsdmon.exe
PRC - [2010/02/04 01:27:55 | 000,672,424 | —- | M] () – C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe
PRC - [2009/10/16 13:10:34 | 000,589,824 | —- | M] ( ) – C:\Windows\System32\lxdxcoms.exe
PRC - [2009/09/06 07:06:20 | 000,169,312 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
PRC - [2009/07/21 22:33:32 | 000,458,844 | —- | M] (IDT, Inc.) – C:\Program Files\IDT\WDM\sttray.exe
PRC - [2009/07/21 22:33:32 | 000,221,266 | —- | M] (IDT, Inc.) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\stacsv.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/03/02 18:43:08 | 000,081,920 | —- | M] (Andrea Electronics Corporation) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\AEstSrv.exe
PRC - [2009/02/07 08:56:47 | 000,266,240 | —- | M] () – C:\Windows\System32\CSHelper.exe
PRC - [2008/09/29 13:19:22 | 000,415,744 | —- | M] () – C:\Program Files\Atomic Alarm Clock\timeserv.exe
PRC - [2008/08/22 16:32:06 | 000,361,808 | —- | M] () – C:\Windows\SMINST\BLService.exe
PRC - [2008/04/15 21:54:42 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/15 21:54:40 | 000,178,712 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007/04/25 14:18:48 | 000,537,520 | —- | M] ( ) – C:\Windows\System32\lxbvcoms.exe
PRC - [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe


========== Modules (SafeList) ==========

MOD - [2010/10/28 10:33:08 | 000,575,488 | —- | M] (OldTimer Tools) – c:\Users\Nancy\Downloads\OTL.exe
MOD - [2010/08/31 11:43:52 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/08/13 12:58:56 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/03/25 21:40:44 | 000,017,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
SRV - [2010/03/18 11:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [Auto | Running] – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2009/11/16 13:46:57 | 000,867,080 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2009/10/16 13:10:34 | 000,589,824 | —- | M] ( ) [Auto | Running] – C:\Windows\System32\lxdxcoms.exe – (lxdx_device)
SRV - [2009/10/16 13:00:50 | 000,094,208 | —- | M] () [Auto | Stopped] – C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxdxserv.exe – (lxdxCATSCustConnectService)
SRV - [2009/09/24 21:27:04 | 000,793,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\FntCache.dll – (FontCache)
SRV - [2009/09/06 07:06:20 | 000,169,312 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor8.0)
SRV - [2009/08/24 07:36:45 | 000,377,344 | —- | M] (Microsoft Corporation) [On_Demand | Running] – winhttp.dll – (WinHttpAutoProxySvc)
SRV - [2009/07/21 22:33:32 | 000,221,266 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\stacsv.exe – (STacSV)
SRV - [2009/03/02 18:43:08 | 000,081,920 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\AEstSrv.exe – (AESTFilters)
SRV - [2009/02/07 08:56:47 | 000,266,240 | —- | M] () [Auto | Running] – C:\Windows\System32\CSHelper.exe – (CSHelper)
SRV - [2008/09/29 13:19:22 | 000,415,744 | —- | M] () [Auto | Running] – C:\Program Files\Atomic Alarm Clock\timeserv.exe – (AtomicAlarmClock)
SRV - [2008/08/22 16:32:06 | 000,361,808 | —- | M] () [Auto | Running] – C:\Windows\SMINST\BLService.exe – (Recovery Service for Windows)
SRV - [2008/04/15 21:54:42 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2008/01/20 22:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/04/25 14:18:48 | 000,537,520 | —- | M] ( ) [Auto | Running] – C:\Windows\System32\lxbvcoms.exe – (lxbv_device)
SRV - [2007/01/04 17:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto | Running] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2005/02/09 11:59:00 | 000,014,165 | —- | M] (Pinnacle Systems GmbH) [Auto | Stopped] – C:\Windows\System32\drivers\Pclepci.sys – (PCLEPCI)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\PalmUSBD.sys – (PalmUSBD)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\iPodDrv.sys – (iPodDrv)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\System32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\ComboFix\catchme.sys – (catchme)
DRV - [2010/03/25 21:30:22 | 000,042,368 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Running] – C:\Windows\System32\drivers\MpNWMon.sys – (MpNWMon)
DRV - [2009/07/21 22:33:32 | 000,409,088 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\stwrt.sys – (STHDA)
DRV - [2009/05/25 06:50:44 | 000,164,864 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Rtlh86.sys – (RTL8169)
DRV - [2009/04/11 00:42:54 | 000,073,216 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2009/03/26 08:00:02 | 000,064,000 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\RTSTOR.sys – (RTSTOR)
DRV - [2008/10/23 02:16:28 | 001,331,192 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XX)
DRV - [2008/10/23 02:16:28 | 001,331,192 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\BCMWL6.SYS – (BCM43XV)
DRV - [2008/06/12 14:43:16 | 002,381,312 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\igdkmd32.sys – (igfx)
DRV - [2008/06/04 13:54:22 | 000,113,664 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV - [2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\iaStor.sys – (iaStor)
DRV - [2008/03/28 02:06:00 | 000,199,472 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\SynTP.sys – (SynTP)
DRV - [2008/03/27 16:12:12 | 000,024,424 | —- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\hpdskflt.sys – (hpdskflt)
DRV - [2008/03/27 16:11:34 | 000,034,664 | —- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Accelerometer.sys – (Accelerometer)
DRV - [2008/01/24 09:23:12 | 000,052,736 | —- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\enecir.sys – (enecir)
DRV - [2008/01/20 22:23:27 | 000,386,616 | —- | M] (LSI Corporation, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\megasr.sys – (MegaSR)
DRV - [2008/01/20 22:23:27 | 000,149,560 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2008/01/20 22:23:27 | 000,031,288 | —- | M] (LSI Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2008/01/20 22:23:26 | 000,101,432 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2008/01/20 22:23:26 | 000,074,808 | —- | M] (Silicon Integrated Systems) [Kernel | Boot | Running] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2008/01/20 22:23:26 | 000,040,504 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2008/01/20 22:23:25 | 000,300,600 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2008/01/20 22:23:25 | 000,089,656 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2008/01/20 22:23:24 | 001,122,360 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2008/01/20 22:23:24 | 000,118,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2008/01/20 22:23:24 | 000,079,928 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2008/01/20 22:23:23 | 000,654,336 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTCNXT3.SYS – (winachsf)
DRV - [2008/01/20 22:23:23 | 000,235,064 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2008/01/20 22:23:23 | 000,130,616 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2008/01/20 22:23:23 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2008/01/20 22:23:23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2008/01/20 22:23:23 | 000,096,312 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2008/01/20 22:23:23 | 000,079,416 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2008/01/20 22:23:22 | 000,987,648 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTDPV3.SYS – (HSF_DPV)
DRV - [2008/01/20 22:23:22 | 000,342,584 | —- | M] (Emulex) [Kernel | Boot | Running] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2008/01/20 22:23:22 | 000,200,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\VSTAZL3.SYS – (HSFHWAZL)
DRV - [2008/01/20 22:23:21 | 000,422,968 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2008/01/20 22:23:21 | 000,102,968 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2008/01/20 22:23:21 | 000,045,112 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2008/01/20 22:23:20 | 000,238,648 | —- | M] (ULi Electronics Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2008/01/20 22:23:00 | 000,020,024 | —- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2008/01/20 22:23:00 | 000,019,000 | —- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2008/01/20 22:23:00 | 000,017,464 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2007/07/11 13:30:22 | 000,007,168 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\HpqRemHid.sys – (HpqRemHid)
DRV - [2007/06/18 20:12:04 | 000,016,768 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HpqKbFiltr.sys – (HpqKbFiltr)
DRV - [2007/01/04 09:07:00 | 000,171,520 | —- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\MarvinBus.sys – (MarvinBus)
DRV - [2006/12/12 11:16:06 | 000,022,528 | —- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emAudio.sys – (emAudio)
DRV - [2006/11/02 05:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 05:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 05:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 05:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Boot | Running] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 05:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 05:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 05:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Boot | Running] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 05:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 05:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 05:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 05:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 04:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 04:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 04:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 04:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 04:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 04:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 03:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2006/11/02 03:30:56 | 000,429,056 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvm60x32.sys – (NVENETFD)
DRV - [2005/12/21 09:14:52 | 000,100,957 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emDevice.sys – (DCamUSBEMPIA)
DRV - [2005/12/21 09:14:52 | 000,005,245 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emFilter.sys – (FiltUSBEMPIA)
DRV - [2005/12/21 09:14:52 | 000,004,493 | —- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\emScan.sys – (ScanUSBEMPIA)
DRV - [2005/06/24 18:36:16 | 000,039,036 | —- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lgusbmodem.sys – (USBModem)
DRV - [2005/05/26 11:01:36 | 000,038,144 | —- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lgusbdiag.sys – (UsbDiag)
DRV - [2005/05/26 11:01:18 | 000,021,344 | —- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\lgusbbus.sys – (usbbus)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKLM\..\URLSearchHook: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Swag Bucks Customized Web Search"
FF - prefs.js..browser.startup.homepage: "https://login.yahoo.com/config/mail?.src=ym&.intl=us"
FF - prefs.js..extensions.enabledItems: {097d3191-e6fa-4728-9826-b533d755359d}:0.7.11
FF - prefs.js..extensions.enabledItems: {0C7E3F01-99E9-4095-9BDC-F84724960B57}:[removed]
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..extensions.enabledItems: {E0B8C461-F8FB-49b4-8373-FE32E9252800}:4.0.0.106602
FF - prefs.js..extensions.enabledItems: {6e84150a-d526-41f1-a480-a67d3fed910d}:[removed]
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {a92aadf8-193f-4a62-8740-5cce81775afc}:1.0.7
FF - prefs.js..extensions.enabledItems: [removed]:1.7
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.10.1
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.2
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.1.0
FF - prefs.js..extensions.enabledItems: {ff356687-aa08-463d-a46c-11c451824939}:5.0.0


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/30 15:49:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2008/12/01 19:47:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/22 05:29:45 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/22 05:29:45 | 000,000,000 | —D | M]

[2008/12/01 12:04:41 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Mozilla\Extensions
[2010/10/28 11:15:56 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions
[2010/01/18 09:05:27 | 000,000,000 | —D | M] (All-in-One Sidebar) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d}
[2009/02/06 08:51:07 | 000,000,000 | —D | M] (Coupon Manager) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{0C7E3F01-99E9-4095-9BDC-F84724960B57}
[2010/10/03 18:18:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2008/12/02 07:10:45 | 000,000,000 | —D | M] (Adblock) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2010/10/28 06:14:37 | 000,000,000 | —D | M] (AddThis) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2010/01/26 10:06:26 | 000,000,000 | —D | M] (IE View) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2010/10/24 07:51:34 | 000,000,000 | —D | M] (NoScript) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/08/19 09:32:41 | 000,000,000 | —D | M] (Swag Bucks Toolbar) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
[2010/02/07 10:14:32 | 000,000,000 | —D | M] (Woot Watcher) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{a92aadf8-193f-4a62-8740-5cce81775afc}
[2010/10/24 07:51:34 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/10/28 06:14:37 | 000,000,000 | —D | M] (Evernote Web Clipper) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}
[2010/03/16 10:35:49 | 000,000,000 | —D | M] (Red Cats (blue flavor)) – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{ff356687-aa08-463d-a46c-11c451824939}
[2010/05/13 10:45:15 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\[removed]
[2010/01/23 07:42:37 | 000,000,652 | —- | M] () – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\searchplugins\aol-search.xml
[2009/09/01 12:24:10 | 000,000,882 | —- | M] () – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\searchplugins\conduit.xml
[2009/05/25 10:02:54 | 000,002,357 | —- | M] () – C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\searchplugins\photobucket.xml
[2010/09/10 05:58:10 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/01/07 13:16:58 | 000,609,280 | —- | M] (ArtistScope) – C:\Program Files\Mozilla Firefox\plugins\npArtistScope42.dll
[2010/04/11 08:38:52 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
[2009/11/19 17:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/11/19 17:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2010/07/12 12:33:56 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2010/10/28 12:30:16 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Swag Bucks Toolbar) - {8BDEA9D6-6F62-45EB-8EE9-8A81AF0D2F94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [lxdxamon] C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe ()
O4 - HKLM..\Run: [lxdxmon.exe] C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
O4 - HKLM..\Run: [mumservice] C:\Program Files\Motorola\Software Update\mumservice.exe (Motorola)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [USB2Check] C:\Windows\System32\PCLECoInst.DLL (Pinnacle Systems)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Users\Nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Vacation_Countdown.lnk = C:\Program Files\Vacation Countdown v1\Vacation_Countdown.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: smoxgbyq = rundll32 "C:\Users\Nancy\AppData\Roaming\C_1255U.dll",hnpmmh File not found
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to &Evernote - C:\Program Files\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Nancy\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Nancy\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/31 12:48:42 | 000,000,169 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/10/28 12:30:12 | 000,000,000 | —D | C] – C:\_OTL
[2010/10/28 05:56:17 | 000,000,000 | —D | C] – C:\Users\Nancy\AppData\Roaming\1D74787EA28A0C2204A55622B0866299
[2010/09/22 06:11:34 | 000,409,600 | —- | C] ( ) – C:\Windows\System32\lxdxcoin.dll
[2009/08/13 08:23:00 | 000,438,272 | —- | C] ( ) – C:\Windows\System32\LXDXhcp.dll
[2009/08/13 08:22:59 | 000,843,776 | —- | C] ( ) – C:\Windows\System32\lxdxusb1.dll
[2009/08/13 08:22:59 | 000,364,544 | —- | C] ( ) – C:\Windows\System32\lxdxinpa.dll
[2009/08/13 08:22:59 | 000,339,968 | —- | C] ( ) – C:\Windows\System32\lxdxiesc.dll
[2009/08/13 08:22:58 | 001,105,920 | —- | C] ( ) – C:\Windows\System32\lxdxserv.dll
[2009/08/13 08:22:58 | 000,647,168 | —- | C] ( ) – C:\Windows\System32\lxdxpmui.dll
[2009/08/13 08:22:58 | 000,569,344 | —- | C] ( ) – C:\Windows\System32\lxdxlmpm.dll
[2009/08/13 08:22:58 | 000,053,248 | —- | C] ( ) – C:\Windows\System32\lxdxprox.dll
[2009/08/13 08:22:56 | 000,663,552 | —- | C] ( ) – C:\Windows\System32\lxdxhbn3.dll
[2009/08/13 08:22:54 | 000,376,832 | —- | C] ( ) – C:\Windows\System32\lxdxcomm.dll
[2009/08/13 08:22:53 | 000,851,968 | —- | C] ( ) – C:\Windows\System32\lxdxcomc.dll
[2009/01/16 10:29:48 | 000,047,360 | —- | C] (VSO Software) – C:\Users\Nancy\AppData\Roaming\pcouffin.sys
[2007/04/04 07:40:30 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxbvpmui.dll
[2007/04/04 07:39:22 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxbvserv.dll
[2007/04/04 07:34:14 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxbvcomm.dll
[2007/04/04 07:32:50 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbvlmpm.dll
[2007/04/04 07:31:40 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbviesc.dll
[2007/04/04 07:29:30 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxbvpplc.dll
[2007/04/04 07:28:44 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxbvcomc.dll
[2007/04/04 07:28:12 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxbvprox.dll
[2007/04/04 07:22:26 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxbvinpa.dll
[2007/04/04 07:21:52 | 000,995,328 | —- | C] ( ) – C:\Windows\System32\lxbvusb1.dll
[2007/04/04 07:18:20 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxbvhbn3.dll

========== Files - Modified Within 30 Days ==========

[2010/10/28 12:43:35 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{4589B50F-0A1A-4793-AFDB-E1E44D61A7E4}.job
[2010/10/28 12:42:19 | 000,000,349 | —- | M] () – C:\Users\Public\Documents\PCLECHAL.INI
[2010/10/28 12:37:26 | 000,000,284 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2010/10/28 12:34:41 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/28 12:34:41 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/28 12:34:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/28 12:34:22 | 3149,090,816 | -HS- | M] () – C:\hiberfil.sys
[2010/10/28 12:30:16 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2010/10/28 06:22:07 | 000,001,816 | —- | M] () – C:\Users\Nancy\Documents\cc_20101028_062205.reg
[2010/10/28 06:21:56 | 000,000,082 | —- | M] () – C:\Users\Nancy\Documents\cc_20101028_062155.reg
[2010/10/27 10:55:08 | 000,000,322 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForNancy.job
[2010/10/22 05:29:11 | 000,008,391 | —- | M] () – C:\Windows\System32\hpasset.xml
[2010/10/18 08:46:54 | 000,634,088 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/10/18 08:46:54 | 000,117,244 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/10/16 13:38:42 | 000,011,786 | —- | M] () – C:\Users\Nancy\Documents\cc_20101016_133839.reg
[2010/10/15 07:39:43 | 002,691,440 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/10/15 03:02:11 | 000,008,391 | —- | M] () – C:\Windows\System32\hpasset.xml.bkp
[2010/10/13 06:19:45 | 000,000,942 | —- | M] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/10/13 06:09:32 | 000,018,622 | —- | M] () – C:\Users\Nancy\Documents\cc_20101013_060924.reg
[2010/10/13 06:07:22 | 000,000,804 | —- | M] () – C:\Users\Nancy\Desktop\CCleaner.lnk
[2010/10/08 07:12:27 | 000,001,887 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/10/04 17:43:45 | 000,101,888 | —- | M] () – C:\Users\Nancy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== Files Created - No Company Name ==========

[2010/10/28 06:22:06 | 000,001,816 | —- | C] () – C:\Users\Nancy\Documents\cc_20101028_062205.reg
[2010/10/28 06:21:56 | 000,000,082 | —- | C] () – C:\Users\Nancy\Documents\cc_20101028_062155.reg
[2010/10/16 13:38:40 | 000,011,786 | —- | C] () – C:\Users\Nancy\Documents\cc_20101016_133839.reg
[2010/10/13 06:09:28 | 000,018,622 | —- | C] () – C:\Users\Nancy\Documents\cc_20101013_060924.reg
[2010/10/08 07:12:27 | 000,001,887 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/09/22 06:32:43 | 000,000,248 | —- | C] () – C:\ProgramData\lxdxDiagnostics.log
[2010/09/22 06:14:37 | 000,782,336 | —- | C] () – C:\Windows\System32\lxdxdrs.dll
[2010/09/22 06:14:37 | 000,081,920 | —- | C] () – C:\Windows\System32\lxdxcaps.dll
[2010/09/21 18:54:09 | 000,000,000 | —- | C] () – C:\ProgramData\UpdaterLog.txt
[2010/08/02 15:28:55 | 000,000,127 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010/08/02 15:20:26 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/03/13 19:08:26 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/10/02 17:35:39 | 000,021,840 | —- | C] () – C:\Windows\System32\SIntfNT.dll
[2009/10/02 17:35:39 | 000,017,212 | —- | C] () – C:\Windows\System32\SIntf32.dll
[2009/10/02 17:35:39 | 000,012,067 | —- | C] () – C:\Windows\System32\SIntf16.dll
[2009/10/02 17:32:51 | 000,000,115 | —- | C] () – C:\Windows\disney.ini
[2009/09/08 08:44:02 | 000,208,896 | —- | C] () – C:\Windows\System32\lxdxgrd.dll
[2009/08/13 08:28:19 | 000,040,960 | —- | C] () – C:\Windows\System32\lxdxvs.dll
[2009/08/13 08:26:47 | 000,069,632 | —- | C] () – C:\Windows\System32\lxdxcnv4.dll
[2009/08/13 08:25:51 | 000,045,056 | —- | C] () – C:\Windows\System32\LXF3PMON.DLL
[2009/08/13 08:25:51 | 000,032,768 | —- | C] () – C:\Windows\System32\LXF3FXPU.DLL
[2009/08/13 08:25:30 | 000,053,248 | —- | C] () – C:\Windows\System32\lxf3oem.dll
[2009/08/13 08:25:30 | 000,012,288 | —- | C] () – C:\Windows\System32\LXF3PMRC.DLL
[2009/08/13 08:23:19 | 000,000,044 | —- | C] () – C:\Windows\System32\lxdxrwrd.ini
[2009/08/13 08:23:00 | 000,348,160 | —- | C] () – C:\Windows\System32\LXDXinst.dll
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/06/16 09:38:24 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/04/24 08:06:09 | 000,120,200 | —- | C] () – C:\Windows\System32\DLLDEV32i.dll
[2009/03/31 13:41:32 | 000,000,024 | —- | C] () – C:\ProgramData\__FileUploader.log
[2009/03/31 13:32:39 | 000,000,017 | —- | C] () – C:\Windows\MovingPicture.ini
[2009/03/31 12:33:54 | 000,196,096 | —- | C] () – C:\Windows\System32\macd32.dll
[2009/03/31 12:33:54 | 000,138,752 | —- | C] () – C:\Windows\System32\mase32.dll
[2009/03/31 12:33:54 | 000,136,192 | —- | C] () – C:\Windows\System32\mamc32.dll
[2009/03/31 12:33:54 | 000,057,856 | —- | C] () – C:\Windows\System32\masd32.dll
[2009/03/31 12:33:54 | 000,027,648 | —- | C] () – C:\Windows\System32\ma32.dll
[2009/03/30 08:07:10 | 000,000,511 | —- | C] () – C:\Users\Nancy\AppData\Roaming\alarms.ini
[2009/03/30 08:06:24 | 000,000,812 | —- | C] () – C:\Users\Nancy\AppData\Roaming\AtomicAlarmClock.ini
[2009/03/05 06:54:58 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2009/02/24 09:18:22 | 000,000,680 | —- | C] () – C:\Users\Nancy\AppData\Local\d3d9caps.dat
[2009/02/12 18:40:08 | 000,000,321 | —- | C] () – C:\Windows\System32\XMLConfig_SYSID.ini
[2009/01/18 17:10:07 | 000,012,288 | —- | C] () – C:\Windows\impborl.dll
[2009/01/18 08:34:55 | 000,000,094 | —- | C] () – C:\Windows\family.ini
[2009/01/18 08:00:44 | 000,000,000 | —- | C] () – C:\Windows\QuickInstall.INI
[2009/01/16 10:35:23 | 000,001,041 | —- | C] () – C:\Users\Nancy\AppData\Roaming\vso_ts_preview.xml
[2009/01/16 10:30:22 | 000,000,034 | —- | C] () – C:\Users\Nancy\AppData\Roaming\pcouffin.log
[2009/01/16 10:29:48 | 000,007,887 | —- | C] () – C:\Users\Nancy\AppData\Roaming\pcouffin.cat
[2009/01/16 10:29:48 | 000,001,144 | —- | C] () – C:\Users\Nancy\AppData\Roaming\pcouffin.inf
[2008/12/18 14:45:31 | 000,000,050 | —- | C] () – C:\Windows\coowiz20.ini
[2008/12/05 10:46:05 | 000,000,466 | —- | C] () – C:\Windows\Lexstat.ini
[2008/12/03 09:42:04 | 000,001,700 | —- | C] () – C:\Users\Nancy\AppData\Roaming\wklnhst.dat
[2008/12/03 09:36:23 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2008/12/02 06:40:09 | 000,101,888 | —- | C] () – C:\Users\Nancy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/01 23:28:41 | 000,000,000 | —- | C] () – C:\Users\Nancy\AppData\Local\QSwitch.txt
[2008/12/01 23:28:41 | 000,000,000 | —- | C] () – C:\Users\Nancy\AppData\Local\DSwitch.txt
[2008/12/01 23:28:41 | 000,000,000 | —- | C] () – C:\Users\Nancy\AppData\Local\AtStart.txt
[2008/07/01 04:28:04 | 000,000,736 | —- | C] () – C:\ProgramData\hpzinstall.log
[2008/06/12 14:59:22 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1502.dll
[2008/06/04 13:54:12 | 000,004,608 | —- | C] () – C:\Windows\System32\HdmiCoin.dll
[2007/04/24 07:47:28 | 000,413,696 | —- | C] () – C:\Windows\System32\lxbvutil.dll
[2007/02/22 14:32:00 | 000,344,064 | —- | C] () – C:\Windows\System32\lxbvcoin.dll
[2006/11/02 08:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 05:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2005/10/25 23:12:10 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbvvs.dll

========== LOP Check ==========

[2010/10/28 05:56:18 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\1D74787EA28A0C2204A55622B0866299
[2010/07/24 17:13:33 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Audacity
[2009/12/21 10:45:45 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Auslogics
[2010/04/11 08:38:52 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\E-centives
[2010/06/13 08:04:34 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Facebook
[2009/01/05 11:50:45 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\FFTS
[2010/10/03 18:18:19 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\GARMIN
[2009/05/21 06:36:48 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\GoodSync
[2009/12/04 17:28:51 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\HandBrake
[2009/01/18 08:34:55 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\HotSync
[2008/12/02 09:22:23 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Leadertech
[2009/08/13 08:52:04 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Lexmark Productivity Studio
[2009/04/21 17:15:48 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\MAGIX
[2010/07/24 18:54:50 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\NCH Swift Sound
[2009/11/16 14:56:06 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.
1
[2009/03/31 13:31:41 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\proDAD
[2008/12/16 14:05:10 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Red Kawa
[2010/09/12 08:34:54 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Regensoft
[2009/01/11 19:16:30 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Serif
[2009/12/25 11:00:16 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Skinux
[2009/01/09 20:20:47 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Template
[2010/08/18 17:57:50 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\uTorrent
[2009/12/27 09:00:24 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\Vso
[2008/12/03 10:37:40 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\WildTangent
[2010/10/20 16:08:02 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\wootalyzer
[2010/01/22 08:35:02 | 000,000,000 | —D | M] – C:\Users\Nancy\AppData\Roaming\ZiggyTV
[2010/10/28 12:33:25 | 000,032,632 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/10/28 12:43:35 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{4589B50F-0A1A-4793-AFDB-E1E44D61A7E4}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34

< End of report >

I'm running malwarebytes now.
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4977 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18975 10/28/2010 1:00:11 PM mbam-log-2010-10-28 (13-00-11).txt Scan type: Quick scan Objects scanned: 147144 Time elapsed: 10 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\U36VRSFLG6 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
it is c:users\nancy\appdata\roaming\c_12554.dll is missing. And when I ran combofix I got a pop-up saying pev.exe stopped working.

ComboFix 10-10-27.A3 - Nancy 10/28/2010 15:07:48.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3002.1305 [GMT -4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-09-28 to 2010-10-28 )))))))))))))))))))))))))))))))
.

2010-10-28 19:14 . 2010-10-28 19:14 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-10-28 19:14 . 2010-10-28 19:14 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-10-28 16:30 . 2010-10-28 16:30 ——– d—–w- C:\_OTL
2010-10-28 09:56 . 2010-10-28 09:56 ——– d—–w- c:\users\Nancy\AppData\Roaming\1D74787EA28A0C2204A55622B0866299
2010-10-28 09:34 . 2010-10-07 23:21 6146896 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3B532966-3ABA-404A-BFA5-BEA1F87FFFA5}\mpengine.dll
2010-10-14 10:13 . 2010-08-31 15:46 954752 —-a-w- c:\windows\system32\mfc40.dll
2010-10-14 10:13 . 2010-08-31 15:46 954288 —-a-w- c:\windows\system32\mfc40u.dll
2010-10-14 10:13 . 2010-08-20 16:05 867328 —-a-w- c:\windows\system32\wmpmde.dll
2010-10-14 10:13 . 2010-08-31 15:44 531968 —-a-w- c:\windows\system32\comctl32.dll
2010-09-29 10:21 . 2010-06-22 13:30 2048 —-a-w- c:\windows\system32\tzres.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 20:51 . 2010-05-29 10:25 222080 ——w- c:\windows\system32\MpSigStub.exe
2010-10-07 23:21 . 2010-05-30 12:13 6146896 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2010-09-08 15:17 . 2010-09-08 15:17 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 15:17 . 2010-09-08 15:17 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-08-23 11:48 . 2010-08-23 11:48 388096 —-a-r- c:\users\Nancy\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-17 14:11 . 2010-09-15 09:33 128000 —-a-w- c:\windows\system32\spoolsv.exe
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}"= "c:\program files\Swag_Bucks\tbSwa1.dll" [2010-09-16 2735200]

[HKEY_CLASSES_ROOT\clsid\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}]
2010-09-16 09:57 2735200 —-a-w- c:\program files\Swag_Bucks\tbSwa1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}"= "c:\program files\Swag_Bucks\tbSwa1.dll" [2010-09-16 2735200]

[HKEY_CLASSES_ROOT\clsid\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{8BDEA9D6-6F62-45EB-8EE9-8A81AF0D2F94}"= "c:\program files\Swag_Bucks\tbSwa1.dll" [2010-09-16 2735200]

[HKEY_CLASSES_ROOT\clsid\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2010-10-17 160328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-18 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-18 145944]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-24 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-02 554288]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"USB2Check"="c:\windows\system32\PCLECoInst.dll" [2006-11-06 81920]
"mumservice"="c:\program files\Motorola\Software Update\mumservice.exe" [2009-05-19 996608]
"lxdxmon.exe"="c:\program files\Lexmark 3600-4600 Series\lxdxmon.exe" [2010-02-04 672424]
"lxdxamon"="c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe" [2010-02-04 16040]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-22 458844]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

c:\users\Nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Vacation_Countdown.lnk - c:\program files\Vacation Countdown v1\Vacation_Countdown.exe [2009-1-9 701866]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 03:07 932288 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-03-17 01:58 47392 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
2008-06-13 16:00 320168 —-a-w- c:\program files\Lexmark Fax Solutions\fm3032.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 19:39 1090952 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoshopElements8SyncAgent]
2009-09-06 11:07 1893728 —-a-w- c:\program files\Adobe\Elements Organizer 8.0\ElementsOrganizerSyncAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 20:07 2260480 ——w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R2 AtomicAlarmClock;Atomic Alarm Clock Time;c:\program files\Atomic Alarm Clock\timeserv.exe [2008-09-29 415744]
R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [2009-02-07 266240]
R2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [x]
R2 lxdxCATSCustConnectService;lxdxCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxdxserv.exe [2009-10-16 94208]
S2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-09-06 169312]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_e2247046\aestsrv.exe [2009-03-02 81920]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-19 19456]
S2 lxbv_device;lxbv_device;c:\windows\system32\lxbvcoms.exe [2007-04-25 537520]
S2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe [2009-10-16 589824]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-08-22 361808]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-02-07 193840]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-01-24 52736]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-06-04 113664]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-26 42368]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-10-27 c:\windows\Tasks\HPCeeScheduleForNancy.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-07-01 03:03]

2010-10-28 c:\windows\Tasks\User_Feed_Synchronization-{4589B50F-0A1A-4793-AFDB-E1E44D61A7E4}.job
- c:\windows\system32\msfeedssync.exe [2010-10-14 04:25]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
IE: Add to &Evernote - c:\program files\Evernote\Evernote3.5\enbar.dll/2000
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{E0B8C461-F8FB-49b4-8373-FE32E92528A6} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEEE} - c:\program files\Evernote\Evernote3.5\enbar.dll
FF - ProfilePath - c:\users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\
FF - prefs.js: browser.search.selectedEngine - Swag Bucks Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxps://login.yahoo.com/config/mail?.src=ym&.intl=us
FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll
FF - component: c:\users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\FFExternalAlert.dll
FF - component: c:\users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\RadioWMPCore.dll
FF - component: c:\users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}\platform\WINNT_x86-msvc\components\enbar.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npArtistScope42.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\users\Nancy\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{0C7E3F01-99E9-4095-9BDC-F84724960B57}\plugins\NPCpnMgr.dll
FF - plugin: c:\users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\ignl4m9r.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

HKLM-Explorer_Run-smoxgbyq - c:\users\Nancy\AppData\Roaming\C_1255U.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-28 15:14
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\TEMP\TMP00000044DFE5D4078B7DB725 524288 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-868099793-2633419675-3989385434-1000\Software\Skype\Installer]
@DACL=(02 0000)
"LaunchAfter"=dword:00000001
"FFDefault"=dword:00000001
"IEDefault"=dword:00000000
"GTDefault"=dword:00000001
"ChromeDefault"=dword:00000001
"DonwloadLastModified"="Wed, 10 Mar 2010 07:26 GMT"
"DownloadContentLength"=dword:012f3600
"DownloadETag"="12150"

[HKEY_USERS\S-1-5-21-868099793-2633419675-3989385434-1000\Software\Skype\Toolbars]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-10-28 15:17:13
ComboFix-quarantined-files.txt 2010-10-28 19:16
ComboFix2.txt 2010-08-27 11:19

Pre-Run: 42,436,202,496 bytes free
Post-Run: 42,386,837,504 bytes free

- - End Of File - - 79A48A2336709B717565379A00F7683C
hi

Step 1

Update MalwareBytes AntiMalware and Run a Quick Scan.
Post the log it produces

Step 2

Please download JavaRa to your desktop and unzip it to it's own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

Next

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


Things i would like to see in your reply:
  • Malwarebytes Results.
  • Kaspersky WebScanner Report
  • Update on how your computer is running
I'm not sure which java I should be downloading. I'm under Java SE Runtime Environment 6u22 for Windows, and they have windows offline installation and windows kernel installation. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4986 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18975 10/29/2010 5:28:17 AM mbam-log-2010-10-29 (05-28-17).txt Scan type: Quick scan Objects scanned: 146905 Time elapsed: 12 minute(s), 42 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
I'm going to rerun malware after kaspersky because just got another microsoft essentials warning about trojan downloader win32: genome.I. It seemed to come up with java.
I can't run Kaspersky. It was running all morning. I went out and when I came back it had gone from 32% to 8%. My windows side bar is also not working. The items are not loading.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI