This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected computer: really slow, IE opens random windows

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi oxomania,

We cleaned out quite a few temporary caches that Windows uses which may account for some of the slowness on startup. When is the last time you did a defragmentation of the hard drive?

If you leave the notice from Security Center on the screen for a brief period of time does it go away if you do absolutly nothing?

Since part of the registry is user specific, User Jeff's problems may just be in his account. We'll take a look with OTL though we may need to switch to his account later to get a better picture.

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the box beside Scan all users
  • In the Extra Registry section change it to All
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please post both logs produced.

Thanks
Good Morning oldman960,

The computer started-up faster today. The Security Center warning did not pop up. The Anti-virus button doesn't go from off to on when I click it, but does eventually. I'll wait the next time if happens as see if it goes on by itself. As far as I know, the hard drive has never been defragmented.

The OTL logs follow.

Thanks for your help.

OTL.Txt

OTL logfile created on: 1/7/2011 6:20:51 AM - Run 2
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Bob\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.00 Mb Total Physical Memory | 94.00 Mb Available Physical Memory | 19.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.27 Gb Total Space | 43.46 Gb Free Space | 60.98% Space Free | Partition Type: NTFS

Computer Name: DELL | User Name: Bob | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Bob\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DoScan.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
PRC - C:\Program Files\SanDisk\SanDisk TransferMate\SD Monitor.exe (SanDisk)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd.exe (Hewlett-Packard)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Bob\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (Lbd) – C:\WINDOWS\System32\DRIVERS\Lbd.sys File not found
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys File not found
DRV - (catchme) – C:\DOCUME~1\Bob\LOCALS~1\Temp\catchme.sys File not found
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110101.005\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\eengine\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110101.005\NAVENG.SYS (Symantec Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (PID_08A0) QuickCam IM(PID_08A0) – C:\WINDOWS\system32\drivers\LV302AV.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/mywaybiz
IE - HKU\.DEFAULT\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/mywaybiz
IE - HKU\S-1-5-18\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-891965163-2004648151-1109723374-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKU\S-1-5-21-891965163-2004648151-1109723374-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-891965163-2004648151-1109723374-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/03 16:36:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/05 19:17:10 | 000,000,000 | —D | M]

[2010/04/03 16:36:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Bob\Application Data\Mozilla\Extensions
[2010/04/03 16:36:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\wfi801px.default\extensions
[2011/01/05 19:17:12 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/01/05 19:17:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/10/22 16:45:01 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/12 18:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/12/30 11:54:25 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O3 - HKU\S-1-5-21-891965163-2004648151-1109723374-1006\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe File not found
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled [2010/04/02 22:24:58 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk = C:\Program Files\SanDisk\SanDisk TransferMate\SD Monitor.exe (SanDisk)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-891965163-2004648151-1109723374-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-891965163-2004648151-1109723374-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-891965163-2004648151-1109723374-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-891965163-2004648151-1109723374-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll File not found
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll File not found
O15 - HKU\S-1-5-21-891965163-2004648151-1109723374-1006\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE} http://www.ritzpix.com/net/Uploader/LPUploader45.cab (Image Uploader Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} http://www.kodakgallery.com/downloads/BUM/…_2/axofupld.cab (Kodak Gallery Easy Upload Manager Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Bob\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Bob\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/02/23 13:39:12 | 000,000,398 | —- | M] () - C:\AUTOEXEC.UP – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/05 20:09:23 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/01/05 20:04:40 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Bob\Desktop\OTL.exe
[2011/01/05 19:17:10 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/01/05 19:17:10 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/01/05 19:17:10 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/01/05 19:17:10 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/31 13:25:15 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2010/12/31 13:24:19 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2010/12/30 17:25:17 | 000,000,000 | —D | C] – C:\ComboFix
[2010/12/30 17:23:03 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/12/30 10:45:59 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/12/30 10:11:47 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/12/30 10:11:46 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/12/30 10:11:46 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/12/30 10:11:46 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/12/30 10:11:22 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/12/30 09:51:05 | 000,000,000 | —D | C] – C:\Qoobox
[2010/12/28 10:11:26 | 000,000,000 | —D | C] – C:\_OTL
[2010/12/27 10:08:38 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Bob\Desktop\HiJackThis.exe
[2010/12/26 21:57:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Bob\Application Data\Malwarebytes
[2010/12/26 21:57:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Bob\Local Settings\Application Data\Symantec
[2010/12/25 16:06:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/12/20 23:04:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Symantec Client Security
[2010/12/20 23:04:11 | 000,107,696 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/12/20 23:04:11 | 000,087,808 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2010/12/20 23:00:36 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2010/12/20 23:00:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2010/12/20 23:00:07 | 000,000,000 | —D | C] – C:\Program Files\Symantec AntiVirus
[2010/12/20 23:00:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Symantec
[2010/12/20 18:21:22 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:21:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2010/12/20 18:21:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/12/20 18:21:14 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/20 18:21:14 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/12 23:46:26 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\AdobeUM
[2010/12/12 23:46:25 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe

========== Files - Modified Within 30 Days ==========

[2011/01/07 06:11:17 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/07 06:11:15 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/07 06:08:52 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/07 06:08:48 | 526,536,704 | -HS- | M] () – C:\hiberfil.sys
[2011/01/06 20:49:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/05 20:04:44 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bob\Desktop\OTL.exe
[2011/01/04 21:44:14 | 000,007,405 | —- | M] () – C:\Documents and Settings\Bob\My Documents\Symantec Log 01-04-11.csv
[2011/01/02 20:10:37 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/01 13:27:45 | 000,258,248 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/31 15:31:18 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/12/30 13:39:19 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/12/30 11:54:25 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/12/30 10:46:09 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2010/12/30 10:09:18 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/12/30 09:42:46 | 004,011,645 | R— | M] () – C:\Documents and Settings\Bob\Desktop\ComboFix.exe
[2010/12/27 14:59:30 | 000,296,448 | —- | M] () – C:\Documents and Settings\Bob\Desktop\k6vyjkpp.exe
[2010/12/27 10:09:08 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Bob\Desktop\HiJackThis.exe
[2010/12/25 09:47:23 | 000,098,392 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/12/21 05:14:23 | 000,000,000 | —- | M] () – C:\WINDOWS\vpc32.INI
[2010/12/20 21:29:10 | 000,243,552 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/17 19:46:37 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/12/17 19:46:37 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/12/10 11:16:10 | 000,014,739 | —- | M] () – C:\WINDOWS\System32\12543.js

========== Files Created - No Company Name ==========

[2011/01/04 21:44:14 | 000,007,405 | —- | C] () – C:\Documents and Settings\Bob\My Documents\Symantec Log 01-04-11.csv
[2010/12/30 10:46:09 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/12/30 10:46:02 | 000,260,272 | RHS- | C] () – C:\cmldr
[2010/12/30 10:11:47 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/12/30 10:11:47 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/12/30 10:11:46 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/12/30 10:11:46 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/12/30 10:11:46 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/12/30 09:42:38 | 004,011,645 | R— | C] () – C:\Documents and Settings\Bob\Desktop\ComboFix.exe
[2010/12/28 10:13:12 | 526,536,704 | -HS- | C] () – C:\hiberfil.sys
[2010/12/27 14:59:26 | 000,296,448 | —- | C] () – C:\Documents and Settings\Bob\Desktop\k6vyjkpp.exe
[2010/12/21 05:14:23 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2010/12/20 18:21:24 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/17 19:46:37 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/12/17 19:46:37 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/04/02 21:52:32 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2009/06/14 19:03:02 | 000,000,786 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/06/14 19:01:52 | 000,565,248 | R— | C] () – C:\WINDOWS\System32\hpotscl.dll
[2008/03/20 15:09:30 | 000,212,992 | —- | C] () – C:\WINDOWS\System32\HA_Registration.dll
[2008/03/20 15:09:29 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\HA_Inet.dll
[2008/03/20 15:09:29 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\HA_Error.dll
[2007/10/06 14:47:57 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/06/24 19:02:38 | 000,009,255 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2006/02/20 17:48:34 | 000,003,822 | —- | C] () – C:\Documents and Settings\Bob\Application Data\wklnhst.dat
[2005/12/30 12:55:55 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/12/27 04:45:58 | 000,015,872 | —- | C] () – C:\Documents and Settings\Bob\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/08/01 17:57:27 | 000,000,058 | —- | C] () – C:\WINDOWS\OSA.INI
[2005/07/31 13:16:47 | 000,001,357 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2005/07/07 08:24:29 | 000,061,678 | —- | C] () – C:\Documents and Settings\Bob\Application Data\PFP120JPR.{PB
[2005/07/07 08:24:29 | 000,012,358 | —- | C] () – C:\Documents and Settings\Bob\Application Data\PFP120JCM.{PB
[2005/06/12 05:36:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/06/12 05:32:41 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/06/12 05:06:08 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2005/06/12 05:05:52 | 000,000,375 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/04/09 16:04:54 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 12:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 12:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 11:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1999/01/27 12:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 06:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2008/11/24 13:59:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2010/12/25 16:21:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2007/12/23 11:17:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/11/24 13:59:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/04/02 21:24:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Bob\Application Data\Aim
[2010/03/07 10:14:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Bob\Application Data\CallingID
[2010/03/07 10:53:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Bob\Application Data\comcasttb
[2008/11/15 19:10:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Bob\Application Data\GARMIN
[2005/12/25 19:02:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Bob\Application Data\Leadertech
[2007/04/15 10:43:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Bob\Application Data\Viewpoint
[2005/08/18 11:49:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Diana\Application Data\Aim
[2008/11/24 14:00:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\acccore
[2005/08/01 17:09:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\Aim
[2009/03/29 20:41:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\Leadertech
[2007/04/14 11:26:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Jeff\Application Data\Viewpoint
[2007/04/16 22:33:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Lindsay\Application Data\acccore
[2005/06/17 21:02:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Lindsay\Application Data\Aim
[2008/07/16 08:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Lindsay\Application Data\HorizonWimba
[2005/06/22 14:12:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Lindsay\Application Data\Leadertech
[2007/01/02 19:35:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Lindsay\Application Data\Snapfish
[2007/04/15 11:39:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Lindsay\Application Data\Viewpoint
[2010/12/30 10:09:18 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========



< End of report >

Extras.Txt

OTL Extras logfile created on: 1/7/2011 6:20:51 AM - Run 2
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\Bob\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.00 Mb Total Physical Memory | 94.00 Mb Available Physical Memory | 19.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.27 Gb Total Space | 43.46 Gb Free Space | 60.98% Space Free | Partition Type: NTFS

Computer Name: DELL | User Name: Bob | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] – C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\WINDOWS\System32\ieframe.dll (Microsoft Corporation)
.js [@ = JSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] – "%1" %*
batfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] – "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
cmdfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] – "%1" %*
cmdfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] – %SystemRoot%\System32\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – C:\WINDOWS\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile – C:\WINDOWS\system32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] – C:\WINDOWS\system32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile – C:\WINDOWS\system32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] – C:\WINDOWS\system32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] – C:\WINDOWS\system32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
regfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
txtfile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] – %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile – C:\WINDOWS\system32\Notepad.exe %1 (Microsoft Corporation)
vbefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] – C:\WINDOWS\system32\Notepad.exe /p %1 (Microsoft Corporation)
vbsfile – C:\WINDOWS\system32\Notepad.exe %1 (Microsoft Corporation)
vbsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] – C:\WINDOWS\system32\Notepad.exe /p %1 (Microsoft Corporation)
wsffile – C:\WINDOWS\system32\Notepad.exe %1 (Microsoft Corporation)
wsffile [open] – C:\WINDOWS\system32\WScript.exe "%1" %* (Microsoft Corporation)
wsffile [print] – C:\WINDOWS\system32\Notepad.exe /p %1 (Microsoft Corporation)
wshfile [open] – C:\WINDOWS\system32\WScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL LLC)
"C:\Program Files\Common Files\AOL\1172199279\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1172199279\EE\AOLServiceHost.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1172199279\EE\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1172199279\EE\aolsoftware.exe:*:Enabled:AOL Services – (America Online, Inc.)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0456ebd7-5f67-4ab6-852e-63781e3f389c}" = Macromedia Flash Player
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0FABD3D7-3036-4e78-B29D-58957ADB0A12}" = HP PSC & OfficeJet 3.5
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{133CD5EF-A4A1-442a-8D50-910B5DEF76BD}" = 4200_Help
"{14374619-0900-4056-BA06-C87C900AF9E6}" = QuickBooks Simple Start Special Edition
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F7473D9-6C0B-4F5A-8FA4-AB8AD78CBE54}" = DocProc
"{24570352-E284-4987-9774-0741395426CA}" = DAS-II Scoring Assistant
"{24C8FBF7-26C6-48ca-834B-A4E5C09E362F}" = AiO_Scan
"{257EC58E-03FD-472B-A9B6-93F23A3C4CB0}" = Scan
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 23
"{29B50D30-EAFC-4cea-9F76-3A0E3729E9B0}" = SkinsHP1
"{300D9EF4-2721-4cb4-A6C3-FB2337CFEA2D}" = AIOMinimal
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{34611BCF-3157-405b-A34E-879C7DC79142}" = 4200
"{34957B51-9676-41CE-9E52-44AE91B73F1C}" = HP Software Update
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold
"{415B8A4E-0EA2-4C69-975C-EEE07B837FD7}" = Unload
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4192EAC0-6B36-4723-B216-D0E86E7757AC}" = Jasc Paint Shop Photo Album 5
"{48242276-DB89-42e8-9678-BD4280D7B99A}" = Copy
"{492724FC-3B26-46B4-824F-3CE2722D9AA0}" = Apple Software Update
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{57C7C46A-D35D-492d-A328-4F8C9B5B4B52}" = PrintScreen
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{595D0DE8-C38A-4432-B851-47DECC1A99BD}" = HP Unload DLL Patch
"{601C6E14-DF1E-4113-A8C8-F9DB90CB0D88}" = SanDisk TransferMate
"{63F2408D-A675-4d97-A256-70EACB6B9B4A}" = AiOSoftware
"{68A2A8FC-2CA0-4b6c-BE09-CC7ABE2A8DDC}" = 4200Trb
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{723C033E-63EA-4227-BAB2-0AA8693C16EB}" = Director
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}" = EarthLink setup files
"{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}" = Jasc Paint Shop Pro Studio, Dell Editon
"{78D891EF-9E2D-4FC8-A71F-E6F897BA1B21}" = Symantec AntiVirus
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81DD5688-695A-4c1d-AE7D-368BF857725A}" = TrayApp
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch® Jukebox
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}" = QuickTime
"{967D588C-9B96-40C9-A222-DCD6922563CA}" = Apple Mobile Device Support
"{9A0DCD97-9648-45ed-A52C-133C728AB2FF}" = 4200Tour
"{9B03C535-3AEA-4ef2-B326-0A01A2207034}" = CreativeProjects
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}" = Dell Picture Studio v3.0
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{AF226123-1A6F-4ec1-8DEF-E35E7A0D0127}" = Fax
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{BC339BFD-F550-471a-8D26-4D08126C62F7}" = SkinsHP2
"{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB54ABA8-D67F-47AD-A76C-2631BADA9FE5}" = Microsoft Works Suite Add-in for Microsoft Word
"{CBE3E0AF-73BB-4c21-8B96-B09E003EDE7F}" = QuickProjects
"{D186329B-1B4D-408D-ABEC-EA5CE1F182C9}" = Overland
"{DE1AF137-C455-494A-A817-EFE44BCCFDEE}" = Works Upgrade
"{E0219810-16E4-437D-9165-93D7B22524F9}" = iTunes
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{E8BFBD0A-8002-4dc9-869C-E495FA9DCE7A}" = PhotoGallery
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F6970FBD-809A-4C51-BAB3-D94A04C6C8E7}" = Garmin Communicator Plugin
"{FBBF532A-47AC-457d-AC06-0D3163D8911E}" = WebReg
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"GRE POWERPREP" = GRE POWERPREP
"HP Photo & Imaging" = HP Image Zone 3.5
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OfotoEZUpload" = KODAK EASYSHARE Gallery Upload ActiveX Control
"PROSet" = Intel® PRO Network Adapters and Drivers
"QcDrv" = Logitech® Camera Driver
"RealPlayer 6.0" = RealPlayer Basic
"Snood 4_is1" = Snood 4
"StreetPlugin" = Learn2 Player (Uninstall Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WJ III Compuscore and Profiles Program 2.0" = WJ III Compuscore and Profiles Program 2.0
"Works2005Setup" = Microsoft Works 2005 Setup Launcher
"Yahoo! Messenger Explorer Bar" = Yahoo! Messenger Explorer Bar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/5/2011 10:06:58 PM | Computer Name = DELL | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Process Action Taken: Blocked Actor Process:
C:\Documents and Settings\Bob\Desktop\OTL.exe (PID 2724) Time: Wednesday, January
05, 2011 8:06:58 PM

Error - 1/5/2011 10:06:58 PM | Computer Name = DELL | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Thread Action Taken: Blocked Actor Process:
C:\Documents and Settings\Bob\Desktop\OTL.exe (PID 2724) Time: Wednesday, January
05, 2011 8:06:58 PM

Error - 1/5/2011 10:06:58 PM | Computer Name = DELL | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Process Action Taken: Blocked Actor Process:
C:\Documents and Settings\Bob\Desktop\OTL.exe (PID 2724) Time: Wednesday, January
05, 2011 8:06:58 PM

Error - 1/5/2011 10:06:58 PM | Computer Name = DELL | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Thread Action Taken: Blocked Actor Process:
C:\Documents and Settings\Bob\Desktop\OTL.exe (PID 2724) Time: Wednesday, January
05, 2011 8:06:58 PM

Error - 1/5/2011 10:06:58 PM | Computer Name = DELL | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Thread Action Taken: Blocked Actor Process:
C:\Documents and Settings\Bob\Desktop\OTL.exe (PID 2724) Time: Wednesday, January
05, 2011 8:06:58 PM

Error - 1/5/2011 10:06:58 PM | Computer Name = DELL | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Thread Action Taken: Blocked Actor Process:
C:\Documents and Settings\Bob\Desktop\OTL.exe (PID 2724) Time: Wednesday, January
05, 2011 8:06:58 PM

Error - 1/5/2011 10:06:58 PM | Computer Name = DELL | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Thread Action Taken: Blocked Actor Process:
C:\Documents and Settings\Bob\Desktop\OTL.exe (PID 2724) Time: Wednesday, January
05, 2011 8:06:58 PM

Error - 1/5/2011 10:06:58 PM | Computer Name = DELL | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Thread Action Taken: Blocked Actor Process:
C:\Documents and Settings\Bob\Desktop\OTL.exe (PID 2724) Time: Wednesday, January
05, 2011 8:06:58 PM

Error - 1/5/2011 10:06:58 PM | Computer Name = DELL | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Thread Action Taken: Blocked Actor Process:
C:\Documents and Settings\Bob\Desktop\OTL.exe (PID 2724) Time: Wednesday, January
05, 2011 8:06:58 PM

Error - 1/5/2011 10:06:58 PM | Computer Name = DELL | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Thread Action Taken: Blocked Actor Process:
C:\Documents and Settings\Bob\Desktop\OTL.exe (PID 2724) Time: Wednesday, January
05, 2011 8:06:58 PM

[ System Events ]
Error - 1/6/2011 8:53:35 AM | Computer Name = DELL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/6/2011 8:53:35 AM | Computer Name = DELL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/6/2011 8:53:35 AM | Computer Name = DELL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/6/2011 8:53:35 AM | Computer Name = DELL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/6/2011 8:53:35 AM | Computer Name = DELL | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/6/2011 8:55:43 AM | Computer Name = DELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 1/6/2011 9:00:55 PM | Computer Name = DELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 1/6/2011 11:31:41 PM | Computer Name = DELL | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/6/2011 11:31:41 PM | Computer Name = DELL | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/7/2011 8:09:25 AM | Computer Name = DELL | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd


< End of report >
Hi oxomania,

The faster startup would be a result of windows recreating it's caches. Do you use this program, Ad-Aware Email Scanner for Outlook? If not you can uninstall it.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
DRV - (Lbd) – C:\WINDOWS\System32\DRIVERS\Lbd.sys File not found
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys File not found
DRV - (catchme) – C:\DOCUME~1\Bob\LOCALS~1\Temp\catchme.sys File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe File not found
[2010/12/10 11:16:10 | 000,014,739 | —- | M] () – C:\WINDOWS\System32\12543.js
[2010/12/30 10:09:18 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"=-

:commands
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log .

There isn't much showing from user Jeff's account. We can finish up with this account then look a bit closer at Jeff's. If the account you are using seems ok we'll clean up the tools and carry on.

Thanks
Hi oldman960, The computer started up pretty well and I saw no Windows Security message. I opened it and the anti-virus was on. I uninstalled teh Ad-Aware program. There are probably others to remove as well. I ran OTL and got an error messager the first time. The log is below. Thanks Error: Unable to interpret <[createrestorepoint]> in the current context! OTL by OldTimer - Version 3.2.20.1 log created on 01072011_174117 I restarted OTL and ran a second time without the error message. The log follows. ========== SERVICES/DRIVERS ========== ========== OTL ========== Error: No service named Lbd was found to stop! Service\Driver key Lbd not found. File C:\WINDOWS\System32\DRIVERS\Lbd.sys File not found not found. Error: No service named Lavasoft Kernexplorer was found to stop! Service\Driver key Lavasoft Kernexplorer not found. File C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys File not found not found. Error: No service named catchme was found to stop! Service\Driver key catchme not found. File C:\DOCUME~1\Bob\LOCALS~1\Temp\catchme.sys File not found not found. Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched not found. File C:\WINDOWS\System32\12543.js not found. File C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job not found. ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\AvgUninstallURL not found. ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) OTL by OldTimer - Version 3.2.20.1 log created on 01072011_174320
Hi oxomania,

Not sure why OTL gave you that error message but between the 2 runs the entire fix was successful.

If the Jeff account is still having problems once you have finished with the instructions in this post please log into that account and download OTL to the desktop and run a scan. Post both logs and we'll see what we can do.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • Flash_Disinfector.exe
  • TDSSkiller.zip
  • TDSSkiller.exe
  • GMER (k6vyjkpp.exe)
You can also delete the TDSKiller log from the C:\ drive.


Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall



Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep MBAM updated and use it regularly.


Updates and upgrades

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Acrobat - Reader 6.0.2 Updateand Adobe Reader 6.0.1 in that order. Be sure to move any PDF documents to another folder first though.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

For a Resident antispyware (there are others) I suggest eother

Windows Defender OR Winpatrol

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware,IMO)


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.

-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879


Please post back if you have any problems.
Hi oldman960, I have deleted the files listed and updated Adobe. I am still working on your recommendations, but wanted to let you know the computer is working much better. Thanks so much for your help. Sincerely, oxomania

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI