This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Blue Screen - Referred from Microsoft Windows Area

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Post -

I get a stop error on blue screen 0X00000050

Page_fault_in_nopaged_area

_____________________________________________

Reply

There are a few possibilities here with this error:

Blue Screen- 'STOP 0x00000050 (PAGE FAULT IN NON PAGED AREA)'
http://windows.ittoolbox.com/groups/techni…ed_area-2171868

You may have a malicious driver:
http://support.microsoft.com/?kbid=894278&sd;=RMVP

Possibly a malicious display driver:
http://en.allexperts.com/q/Windows-XP-3282…00050-error.htm

My number 1 suspect is a malicious driver.

Firstly though, before going to any of the above links, go to Device Manager:
1. Go to Start / right click on "my computer" / click on "manage" / click on "Device Manager"
If there are any red, black or yellow warnings, you have a driver problem for sure.
If so, right click on the device and choose "properties" / click on driver / click on un-install driver / re-start
2. Go to MS updates and choose "custom". Download the correct driver which should show up there as "optional downloads".

Cheers,
Lee
______________________________________________________
My Post

No Warnings in Device Manager
_______________________________________________________
Reply

Ok, that's might be good, but just because nothing shows up in the Device Manager, does not mean there is no malicious driver in your PC.

I don't know what security you have installed, but you should run a check with your anti-virus and also an anti-Malware program. If you don't have one
you can download "Malwarebytes" from here: http://www.malwarebytes.org/mbam.php
Download it to your desktop and when installing make sure any added extras like toolbars offered are un-ticked.

If a Virus is found, I would open a thread in the Melware section here. If a malicious driver is found after these checks, I would follow the instruction in the 2nd. link in my original post, or take the problem to the Melware section where the experts there can guide you.

The error you are receiving usually refers to a malicious driver (usually the display driver), but there can be other reasons for that error too and that is why I originally gave you those 3 links, so you could better define your problem.

Cheers,
Lee
___________________________________________________

My Post

Here is my Malware bytes log….I run it regularly and surely haven't seen this many items!!! Before I do a memory test, I will wait for you to look at it and advise. The memory diagnostic you describe is kinda confusing

My system is a Dell Optiplex GX620 Running XP Home SP3 4 GB Ram on 2 sticks Pentium D Processor 2.80 GHz.

Thanks for your help

________________________________________________________________________________
_

Reply

Look in Add and Remove Programs (from Control Panel) and see if you have a program called (or something like) Perfect Optimizer installed. If so, uninstall it.

You had a lot of infected areas of your computer and I suspect MalwareBytes will not have removed it all. I think it would be a good idea for you to go to the Spyware / Malware / Virus Removal forum area, read the info there and follow the posted directions. Once you receive a clean bill of health, come back here if you have any additional questions or concerns or it turns out not to be a malware problem.

Please be patient as that is a very busy area. If you do not receive a response in 3 days, post a message here: http://forums.whatthetech.com/What_Do_If_Y…ays_t78698.html

It would still be a good idea to run the memory test though.

*****Note - I Uninstalled Perfect Optimizer

________________________________________________________________
OTL Posts follow:


OTL logfile created on: 1/19/2011 9:56:50 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\Donald Bishop\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 75.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 81.95 Gb Free Space | 55.01% Space Free | Partition Type: NTFS
Drive E: | 465.64 Gb Total Space | 430.08 Gb Free Space | 92.36% Space Free | Partition Type: FAT32
Drive F: | 3.73 Gb Total Space | 3.66 Gb Free Space | 98.26% Space Free | Partition Type: FAT32
Drive G: | 3.77 Gb Total Space | 1.96 Gb Free Space | 51.95% Space Free | Partition Type: FAT32

Computer Name: BISHOPS | User Name: Donald Bishop | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Siber Systems\GoodSync\GoodSync.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\YoWindow\yowindow.exe (Repkasoft)
PRC - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBW32.EXE (Intuit Inc.)
PRC - C:\Documents and Settings\Donald Bishop\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe ()
PRC - C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe ()
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe (Intuit, Inc.)
PRC - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe (SonicWALL, Inc.)
PRC - C:\Program Files\DYMO\DYMO Label Software\DLSService.exe (Sanford, L.P.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe (Intuit)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\logishrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Mozilla Sunbird\sunbird.exe (Mozilla)
PRC - C:\Program Files\Creative\Software Update 3\SoftAuto.exe (Creative Technology Ltd)
PRC - C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (Blue Onion Software)
PRC - C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe (Creative Technology Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
PRC - C:\Program Files\Warecentral\PrintKey-Pro\PKey_Pro.exe (WareCentral.com)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
PRC - C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe (Linksys, a Division of Cisco Systems, Inc.)
PRC - C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\Video\FxSvr2.exe (Logitech Inc.)
PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
PRC - C:\WINDOWS\system32\LVCOMSX.EXE (Logitech Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\J River\Media Center 15\Plugins\msscript.ocx (Microsoft Corporation)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\MlfHook.dll ()
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll (Microsoft Corporation)
MOD - C:\Program Files\Logitech\SetPoint\lgscroll.dll (Logitech, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (Media Center 15 Service) – C:\Program Files\J River\Media Center 15\JRService.exe (J. River, Inc.)
SRV - (QBVSS) – C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe ()
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ioloSystemService) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (ioloFileInfoList) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (ZuneWlanCfgSvc) – C:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (WMZuneComm) – C:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (QuickBooksDB21) – C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe (Intuit, Inc.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (LBTServ) – C:\Program Files\Common Files\logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (NMSAccessU) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (CTDevice_Srv) – C:\Program Files\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (TSP) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (kl1) – C:\WINDOWS\System32\DRIVERS\kl1.sys (Kaspersky Lab)
DRV - (ggsemc) – C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) – C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LUsbFilt) – C:\WINDOWS\system32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (se3eobex) – C:\WINDOWS\system32\drivers\se3eobex.sys (MCCI Corporation)
DRV - (se3emgmt) Sony Ericsson Device 062 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\se3emgmt.sys (MCCI Corporation)
DRV - (se3emdm) – C:\WINDOWS\system32\drivers\se3emdm.sys (MCCI Corporation)
DRV - (se3emdfl) – C:\WINDOWS\system32\drivers\se3emdfl.sys (MCCI Corporation)
DRV - (se3ebus) Sony Ericsson Device 062 (WDM) – C:\WINDOWS\system32\drivers\se3ebus.sys (MCCI Corporation)
DRV - (elagopro) – C:\WINDOWS\system32\drivers\elagopro.sys (Gteko Ltd.)
DRV - (elaunidr) – C:\WINDOWS\system32\drivers\elaunidr.sys (Gteko Ltd.)
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (PID_08A0) QuickCam IM(PID_08A0) – C:\WINDOWS\system32\drivers\LV302AV.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PfModNT.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*;*.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=proxy-server:8080;https=proxy-server:8080

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig"
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:[removed]
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:7.1.5
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:[removed]
FF - prefs.js..extensions.enabledItems: {29852C08-1E91-4889-A6BF-C77F91D6A8F3}:1.8.69
FF - prefs.js..network.proxy.http: "proxy-server"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.no_proxies_on: "ams-server*,*.local"
FF - prefs.js..network.proxy.ssl: "proxy-server"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/11/20 10:34:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/12/15 22:47:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/13 18:10:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/12 22:58:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Sunbird 0.9\extensions\\Components: C:\Program Files\Mozilla Sunbird\components [2010/12/07 21:06:07 | 000,000,000 | —D | M]

[2010/10/12 19:02:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions
[2008/05/09 15:54:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions\[removed]
[2009/06/29 11:18:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions\[removed]
[2010/06/18 22:27:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Extensions\[removed]
[2011/01/19 07:30:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions
[2010/11/30 23:03:58 | 000,000,000 | —D | M] (Winamp Toolbar) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2011/01/16 00:28:54 | 000,000,000 | —D | M] ("LittleFox") – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}
[2010/10/15 18:20:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2010/10/12 21:19:29 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/01/12 22:50:11 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/01/19 08:22:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions
[2009/05/31 19:16:40 | 000,000,000 | —D | M] (Toolbar Buttons) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions\{03B08592-E5B4-45ff-A0BE-C1D975458688}
[2009/05/31 20:07:42 | 000,000,000 | —D | M] (MinimizeToTray–0.9 Compatible) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions\{31513E58-F253-47ad-86DB-D5F21E901234}
[2009/05/31 16:39:56 | 000,000,000 | —D | M] (FoxClocks) – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Sunbird\Profiles\bqqwlbyt.default\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2011/01/05 22:59:29 | 000,001,820 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\searchplugins\bing.xml
[2010/12/01 07:42:28 | 000,001,196 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\searchplugins\winamp-search.xml
[2010/10/12 19:01:24 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/11/20 10:34:29 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/12/15 22:47:09 | 000,000,000 | —D | M] (Roboform Toolbar for Firefox) – C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\FIREFOX
[2010/11/30 09:11:52 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2009/12/07 20:15:44 | 000,360,824 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 12430 more lines…
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (FoxyTunes Toolbar Helper) - {784D8FBC-4165-4D88-90FB-62907ACDD045} - C:\Program Files\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll (FoxyTunes Ltd)
O2 - BHO: (ZoneAlarm Toolbar Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - No CLSID value found.
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll (Cooliris Inc.)
O3 - HKLM\..\Toolbar: (FoxyTunes Toolbar) - {1D1901C3-F72A-46f3-9DBB-0AAA0DEEF6DF} - C:\Program Files\FoxyTunes\ForInternetExplorer\components\IE\FoxyTunesForIE.dll (FoxyTunes Ltd)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DLSService] C:\Program Files\DYMO\DYMO Label Software\DLSService.exe (Sanford, L.P.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Logitech Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [DeskDriveStartup] C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe (Blue Onion Software)
O4 - HKCU..\Run: [EasyLinkAdvisor] C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe (Linksys, a Division of Cisco Systems, Inc.)
O4 - HKCU..\Run: [fsm] File not found
O4 - HKCU..\Run: [GoodSync] C:\Program Files\Siber Systems\GoodSync\GoodSync.exe ()
O4 - HKCU..\Run: [MRC] C:\Program Files\PC Tune-Up\PCTuneUp.exe (Large Software)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SoftAuto.exe] C:\Program Files\Creative\Software Update 3\SoftAuto.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [SystemExplorer] File not found
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKLM..\RunOnce: [SMRequiresRestart] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\PrintKey-Pro.lnk = C:\WINDOWS\Installer\{5EFA4EA3-0604-458C-A06D-485F6B2724C9}\NewShortcut2_6999F52849E742A78F6F4501EF3B5A3A.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\QuickBooks Web Connector.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\QuickBooks_Standard_21.lnk = C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBW32.EXE (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SystemExplorerDisabled [2011/01/18 23:36:38 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\CNET TechTracker.lnk = C:\Documents and Settings\Donald Bishop\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe ()
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\Mozilla Sunbird.lnk = C:\Program Files\Mozilla Sunbird\sunbird.exe (Mozilla)
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\Donald Bishop\Start Menu\Programs\StartUp\YoWindow.lnk = C:\Program Files\YoWindow\yowindow.exe (Repkasoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Winamp; Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll (VisualWare)
O9 - Extra 'Tools' menuitem : VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute Lite Edition\vrie.dll (VisualWare)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll (Cooliris Inc.)
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Reg Error: Key error.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Reg Error: Key error.)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (Reg Error: Key error.)
O16 - DPF: {16F67783-7E72-4C39-99C4-4780A8335484} http://www.syncmyride.com/Own/Modules/Uplo…pplets/sync.cab (SyncXfer Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (Reg Error: Key error.)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1266388971562 (WUWebControl Class)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (Reg Error: Key error.)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://www.creative.com/softwareupdate/su/…101/CTSUEng.cab (Reg Error: Key error.)
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Key error.)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} http://www.shockwave.com/content/bigcityad…BGamePlayer.cab (Jolly Bear Games Player)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (Reg Error: Key error.)
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} http://www.worldwinner.com/games/v45/royal/royal.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://clubgames.pogo.com/online2/pogop/be…aploader_v6.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su/…15106/CTPID.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll (Reg Error: Key error.)
O16 - DPF: PackageCab http://ak.imgag.com/imgag/cp/install/AxCtp2.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - Reg Error: Key error. File not found
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - Reg Error: Key error. File not found
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/DONALD~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Dell.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Dell.bmp
O27 - HKLM IFEO\wupdmgr.exe: Debugger - ntsd– File not found
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/10/11 17:47:36 | 000,000,000 | —D | M] - E:\autorun – [ FAT32 ]
O33 - MountPoints2\{087ac0d9-0c84-11e0-a04a-00188b10f9c2}\Shell\AutoRun\command - "" = M:\slacker.synclauncher.exe
O33 - MountPoints2\{087ac0d9-0c84-11e0-a04a-00188b10f9c2}\Shell\slacker\command - "" = M:\slacker.synclauncher.exe
O34 - HKLM BootExecute: ("autocheck autochk *") - File not found
O34 - HKLM BootExecute: (autocheck smrgdf C:\Documents and Settings\Donald Bishop\Application Data\iolo\) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (63908374630105088)

========== Files/Folders - Created Within 30 Days ==========

[2011/01/19 21:34:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Desktop\you_Infected_t106388_files
[2011/01/19 21:31:23 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Donald Bishop\Desktop\HiJackThis.exe
[2011/01/19 21:30:10 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe
[2011/01/19 08:13:13 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Donald Bishop\Recent
[2011/01/18 23:36:38 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SystemExplorerDisabled
[2011/01/15 08:06:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\RoboForm
[2011/01/15 08:02:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Application Data\RoboForm
[2011/01/14 17:32:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TurboTax 2010
[2011/01/14 07:42:08 | 000,000,000 | -HSD | C] – C:\Qui9AD.tmp
[2011/01/14 07:42:08 | 000,000,000 | -HSD | C] – C:\Qui9AC.tmp
[2011/01/14 07:42:08 | 000,000,000 | -HSD | C] – C:\Qui9AB.tmp
[2011/01/12 22:52:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/01/08 00:34:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Start Menu\Programs\Revo Uninstaller
[2011/01/07 07:33:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\GoodSync
[2011/01/03 20:10:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Intuit_Inc
[2010/12/25 13:11:27 | 000,000,000 | —D | C] – C:\Program Files\Research In Motion Limited
[2010/12/23 15:48:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\Application Data\Blackberry Desktop
[2010/12/22 23:32:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Donald Bishop\My Documents\BlackBerry
[2010/08/31 17:04:19 | 008,134,344 | —- | C] (LastPass) – C:\Program Files\Common Files\lpuninstall.exe
[2003/12/09 13:16:52 | 000,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[11 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/19 22:02:00 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{6FE87274-923A-474F-880B-FB60BED54A8F}.job
[2011/01/19 21:56:04 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/19 21:35:21 | 000,000,294 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515941520-1664358963-1588231850-1006.job
[2011/01/19 21:35:17 | 000,000,302 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-515941520-1664358963-1588231850-1006.job
[2011/01/19 21:34:29 | 000,069,432 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\you_Infected_t106388.html
[2011/01/19 21:31:36 | 000,359,929 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\dds.scr
[2011/01/19 21:31:25 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Donald Bishop\Desktop\HiJackThis.exe
[2011/01/19 21:30:13 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe
[2011/01/19 21:24:01 | 000,001,010 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515941520-1664358963-1588231850-1006UA.job
[2011/01/19 20:16:50 | 000,054,016 | —- | M] () – C:\WINDOWS\System32\drivers\htgxohfg.sys
[2011/01/19 14:28:11 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/01/19 13:10:40 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{4E88510E-6616-4593-BDF4-A4DC733FBF4C}.job
[2011/01/19 09:00:00 | 000,000,334 | —- | M] () – C:\WINDOWS\tasks\GoodSync - Quicken.job
[2011/01/19 08:56:02 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/19 08:27:10 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2011/01/19 08:11:44 | 000,002,351 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PrintKey-Pro.lnk
[2011/01/19 08:11:34 | 000,000,205 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\SONY STICK (F).lnk
[2011/01/19 08:11:34 | 000,000,204 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\MUVO T200 (G).lnk
[2011/01/19 08:11:33 | 000,000,202 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\My Book (E).lnk
[2011/01/19 08:09:27 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/19 08:07:07 | 000,000,802 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/01/19 03:38:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\PC Pitstop Disk MD - Daily E.job
[2011/01/18 20:37:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/18 20:35:42 | 000,000,120 | -H– | M] () – C:\WINDOWS\popcreg.dat
[2011/01/18 20:35:42 | 000,000,044 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2011/01/18 20:03:43 | 000,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/01/18 20:03:11 | 000,000,110 | —- | M] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2011/01/18 19:38:25 | 000,332,280 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/17 22:24:08 | 000,000,958 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-515941520-1664358963-1588231850-1006Core.job
[2011/01/17 22:04:28 | 000,041,472 | —- | M] () – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/17 12:23:09 | 000,002,411 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\TurboTax 2010.lnk
[2011/01/17 10:34:15 | 000,009,594 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\BP.xlsx
[2011/01/17 09:10:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/01/15 15:44:24 | 000,069,916 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2011/01/14 12:03:42 | 000,000,306 | —- | M] () – C:\WINDOWS\tasks\Defraggler Volume E Task.job
[2011/01/13 17:07:50 | 000,566,417 | —- | M] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2011-01-13).ipd
[2011/01/13 11:15:08 | 000,000,306 | —- | M] () – C:\WINDOWS\tasks\Defraggler Volume C Task.job
[2011/01/08 01:28:04 | 000,001,956 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\BlackBerry Desktop Software.lnk
[2011/01/07 07:33:54 | 000,001,738 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\GoodSync.lnk
[2011/01/03 17:19:37 | 000,002,205 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Safari.lnk
[2011/01/02 12:00:48 | 002,279,985 | —- | M] () – C:\Documents and Settings\Donald Bishop\Desktop\Chevy Malibu.pdf
[2010/12/28 21:08:24 | 000,001,542 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/12/25 07:43:47 | 000,002,533 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2010/12/23 20:58:01 | 000,341,123 | —- | M] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23)-1.ipd
[2010/12/23 19:55:04 | 000,336,184 | —- | M] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23).ipd
[2010/12/22 22:41:03 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[11 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/19 21:34:19 | 000,069,432 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\you_Infected_t106388.html
[2011/01/19 21:31:35 | 000,359,929 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\dds.scr
[2011/01/19 20:16:50 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\htgxohfg.sys
[2011/01/19 08:11:34 | 000,000,204 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\MUVO T200 (G).lnk
[2011/01/19 08:11:33 | 000,000,205 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\SONY STICK (F).lnk
[2011/01/19 08:11:32 | 000,000,202 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\My Book (E).lnk
[2011/01/19 08:07:58 | 000,196,736 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/19 07:13:59 | 000,000,294 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515941520-1664358963-1588231850-1006.job
[2011/01/14 17:32:40 | 000,002,411 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\TurboTax 2010.lnk
[2011/01/13 17:07:50 | 000,566,417 | —- | C] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2011-01-13).ipd
[2011/01/08 01:28:04 | 000,001,956 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\BlackBerry Desktop Software.lnk
[2011/01/02 23:14:26 | 000,002,205 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Safari.lnk
[2011/01/02 12:00:48 | 002,279,985 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\Chevy Malibu.pdf
[2010/12/31 10:24:04 | 000,009,594 | —- | C] () – C:\Documents and Settings\Donald Bishop\Desktop\BP.xlsx
[2010/12/28 21:08:23 | 000,001,542 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/12/24 14:37:57 | 000,001,620 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/12/23 20:58:00 | 000,341,123 | —- | C] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23)-1.ipd
[2010/12/23 19:55:04 | 000,336,184 | —- | C] () – C:\Documents and Settings\Donald Bishop\My Documents\LoaderBackup-(2010-12-23).ipd
[2010/12/22 22:41:03 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_RimUsb_01009.Wdf
[2010/12/20 21:38:06 | 000,002,772 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Rim.Desktop.Exception.log
[2010/12/20 21:36:29 | 000,003,315 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Rim.Desktop.HttpServerSetup.log
[2010/12/03 19:38:54 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\PreferencePane
[2010/12/03 19:38:54 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Plugins
[2010/12/03 19:38:54 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT
[2010/12/03 19:36:39 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Pop Flute
[2010/12/03 19:36:38 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Plug-In Settings
[2010/12/03 19:36:38 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2010/08/17 22:08:09 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/08/06 21:53:34 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/10/05 09:43:43 | 000,000,133 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2009/07/27 21:02:41 | 000,055,809 | —- | C] () – C:\WINDOWS\CP-FPCOS100.dll
[2009/07/06 16:16:35 | 000,008,086 | RHS- | C] () – C:\Program Files\uninstall.log
[2009/05/31 18:06:46 | 000,013,020 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\Comma Separated Values (Windows).CAL
[2009/05/08 06:34:43 | 008,673,792 | —- | C] () – C:\Documents and Settings\All Users\Application Data\atscie.msi
[2008/12/12 14:04:46 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2008/12/12 14:03:00 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2008/10/30 16:03:23 | 000,000,110 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2008/04/15 21:46:29 | 000,018,790 | —- | C] () – C:\WINDOWS\System32\ddmon.dll
[2008/04/03 22:32:06 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2008/02/11 08:39:26 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008/02/11 08:39:18 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008/02/08 12:53:46 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\OnlineScannerLang.dll
[2008/02/04 17:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/12/21 00:40:51 | 000,002,711 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2007/11/17 17:55:09 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2007/10/07 14:32:50 | 000,000,166 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2007/08/04 16:26:03 | 000,000,513 | —- | C] () – C:\WINDOWS\pu32i.ini
[2007/07/27 13:49:02 | 000,225,355 | —- | C] () – C:\WINDOWS\System32\lnod32apiW.dll
[2007/07/27 13:49:02 | 000,196,683 | —- | C] () – C:\WINDOWS\System32\lnod32apiA.dll
[2007/04/02 22:43:38 | 000,000,000 | —- | C] () – C:\WINDOWS\Hammerhead.INI
[2007/03/13 17:30:02 | 000,003,102 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/03/10 15:02:41 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007/03/10 14:52:59 | 000,039,790 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/01/27 12:22:29 | 000,092,672 | —- | C] () – C:\WINDOWS\System32\DymoQBInst.dll
[2007/01/27 12:20:45 | 000,000,056 | —- | C] () – C:\WINDOWS\Addrfixr.ini
[2007/01/27 12:20:45 | 000,000,036 | —- | C] () – C:\WINDOWS\iltwain.ini
[2007/01/27 12:20:27 | 000,007,803 | —- | C] () – C:\WINDOWS\System32\dymourl.ini
[2007/01/27 12:18:31 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\DYMOCFG.DLL
[2007/01/27 12:18:31 | 000,002,560 | —- | C] () – C:\WINDOWS\System32\lmmonres.dll
[2007/01/03 10:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 10:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 10:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/15 23:44:07 | 000,000,136 | —- | C] () – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\fusioncache.dat
[2006/12/15 17:51:18 | 000,000,982 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\.googlewebacchosts
[2006/12/10 19:04:37 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/03 01:34:49 | 000,041,472 | —- | C] () – C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/02 23:42:47 | 000,000,088 | —- | C] () – C:\WINDOWS\gbsaver.ini
[2006/12/02 22:31:25 | 000,327,680 | —- | C] () – C:\WINDOWS\System32\dfxg14.dll
[2006/12/02 18:06:09 | 000,000,006 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\dm.ini
[2006/12/02 18:06:08 | 000,000,676 | —- | C] () – C:\Documents and Settings\Donald Bishop\Application Data\AdobeDLM.log
[2006/12/02 16:50:42 | 000,000,170 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/12/02 16:46:56 | 000,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/12/02 16:15:20 | 000,009,255 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2006/12/02 15:13:23 | 000,002,582 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/12/02 13:51:58 | 000,000,549 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2006/12/02 13:37:31 | 000,000,038 | —- | C] () – C:\WINDOWS\System32\w3url.dll
[2006/12/02 13:01:24 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/11/28 15:06:28 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/11/28 14:44:06 | 000,000,391 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/09/18 13:37:50 | 000,000,530 | —- | C] () – C:\WINDOWS\System32\tx12_ic.ini
[2006/09/18 13:37:48 | 000,667,280 | —- | C] () – C:\WINDOWS\System32\tx12.dll
[2006/05/02 17:38:24 | 000,000,748 | —- | C] () – C:\WINDOWS\SetBrowser.ini
[2005/12/05 18:25:22 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\lnod32umc.dll
[2005/12/05 11:37:10 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lnod32upd.dll
[2004/08/10 13:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:57:52 | 000,004,481 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 12:51:10 | 000,025,741 | —- | C] () – C:\WINDOWS\System32\aavr3h.dll
[2004/08/10 12:51:10 | 000,015,365 | —- | C] () – C:\WINDOWS\System32\llbstp.dll
[2004/08/04 05:00:00 | 000,018,705 | —- | C] () – C:\WINDOWS\System32\nusvg7cc.dll
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1999/01/27 13:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll
[1997/06/13 07:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2010/08/31 16:23:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2008/12/12 13:53:52 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2006/12/02 19:13:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2009/05/17 18:00:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2009/07/06 16:16:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DYMO
[2010/12/03 19:38:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2010/03/15 21:11:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EUFJFLUFYG
[2010/10/10 21:51:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FileCure
[2010/09/01 06:55:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2009/07/13 15:54:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoodSync
[2010/12/03 19:36:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Guides
[2010/12/03 19:38:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hybrid Chords
[2008/12/05 18:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Insight Software
[2006/12/28 20:06:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
[2010/10/31 15:19:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/01/19 00:35:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2007/11/13 15:59:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2007/09/07 06:52:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Karen's Power Tools
[2009/11/05 18:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
[2007/10/21 12:32:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/12/01 17:34:40 | 000,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Memeo
[2007/08/27 08:36:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MipKukSoft
[2009/04/21 22:14:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2010/12/03 19:37:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2009/11/15 11:09:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2010/07/06 20:27:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OrbNetworks
[2010/10/10 21:50:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/03/09 17:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2009/07/26 23:03:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/04/04 22:23:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2011/01/08 01:27:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2006/12/02 15:57:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2008/12/12 14:02:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/10/30 16:18:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2011/01/03 21:55:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2009/07/11 09:59:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2007/12/20 09:11:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/07/29 23:03:00 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\System Restore
[2009/06/22 17:09:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/28 16:38:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2010/12/03 19:38:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2009/04/27 14:50:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/01/22 18:49:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VMGJFLUFYG
[2009/06/25 21:35:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WindSolutions
[2007/10/26 07:21:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YAHOO
[2010/12/10 18:09:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YoWindow
[2010/05/22 08:08:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/10 16:06:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/19 13:19:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/10/11 18:41:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{F29F2260-20C9-49D5-9651-71A8580940BF}
[2009/01/03 17:04:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{F40E9D30-5DFC-4B21-BFDB-A5CDEE6440A6}
[2009/01/03 17:03:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~0
[2009/10/19 15:07:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~1
[2007/06/02 16:33:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\.purple
[2008/05/20 17:11:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\acccore
[2010/10/30 16:44:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Amazon
[2011/01/16 20:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Blackberry Desktop
[2008/10/31 06:26:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Buddi
[2009/01/02 14:37:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Canon
[2010/08/17 22:01:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\CBS Interactive
[2010/06/15 06:49:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\CheckPoint
[2009/08/21 17:20:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/11/14 01:32:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\com.Multiply.AutoUploader.C7DF09F73C2059D294831784007C5F0856677385.1
[2009/06/25 21:32:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\CopyTransPhoto
[2009/05/07 06:39:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Dealio
[2010/09/25 21:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\DriverCure
[2010/06/27 16:50:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\eMusic
[2008/12/28 00:42:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Facebook
[2008/07/29 23:03:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\FireShot
[2008/03/24 21:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Flock
[2006/12/02 16:08:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\FotoWire
[2010/06/15 20:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\FoxyTunes
[2010/06/14 11:23:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\GARMIN
[2011/01/19 00:43:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\GoodSync
[2007/06/01 18:19:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\gtk-2.0
[2007/01/08 18:42:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\ICAClient
[2009/06/19 21:42:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\iLike
[2007/10/07 13:45:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Image Zone Express
[2010/10/19 16:54:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\iolo
[2010/08/06 21:41:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\J River
[2007/08/27 08:38:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Kybtec Software
[2007/03/16 06:57:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Launchy
[2009/06/30 16:09:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Leadertech
[2009/05/31 15:18:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\MailFrontier
[2007/08/27 18:29:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\MipKukSoft
[2007/10/16 21:56:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\MSNInstaller
[2006/12/02 14:02:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Musicmatch
[2008/12/12 14:47:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\NewSoft
[2009/05/30 07:49:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\OfficeUpdate12
[2007/10/12 16:01:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Opera
[2010/09/25 21:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\ParetoLogic
[2009/01/02 16:08:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Pogo Games
[2010/02/05 07:49:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Portalarium
[2007/10/07 12:48:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Printer Info Cache
[2010/12/20 21:39:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Research In Motion
[2007/12/08 17:46:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\RoadRunner
[2011/01/15 08:02:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\RoboForm
[2008/12/12 14:02:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\ScanSoft
[2009/05/07 06:40:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Search Settings
[2007/07/17 06:35:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\SlimBrowser
[2008/05/21 22:03:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Snapfish
[2010/06/18 22:27:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Songbird2
[2007/11/17 17:53:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Teleca
[2007/09/24 15:44:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\TomTom
[2007/07/19 17:21:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Uniblue
[2008/07/10 20:25:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\Windows Desktop Search
[2009/06/25 21:30:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\WindSolutions
[2010/05/28 06:02:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\WinPatrol
[2010/12/10 18:11:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Donald Bishop\Application Data\YoWindow
[2011/01/17 09:10:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/01/13 11:15:08 | 000,000,306 | —- | M] () – C:\WINDOWS\Tasks\Defraggler Volume C Task.job
[2011/01/14 12:03:42 | 000,000,306 | —- | M] () – C:\WINDOWS\Tasks\Defraggler Volume E Task.job
[2011/01/19 09:00:00 | 000,000,334 | —- | M] () – C:\WINDOWS\Tasks\GoodSync - Quicken.job
[2011/01/19 03:38:00 | 000,000,340 | —- | M] () – C:\WINDOWS\Tasks\PC Pitstop Disk MD - Daily E.job
[2007/07/21 03:26:00 | 000,000,320 | —- | M] () – C:\WINDOWS\Tasks\PC Pitstop Disk MD - Once E.job
[2011/01/19 13:10:40 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{4E88510E-6616-4593-BDF4-A4DC733FBF4C}.job
[2011/01/19 22:02:00 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{6FE87274-923A-474F-880B-FB60BED54A8F}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/29 21:50:17 | 000,000,282 | -HS- | M] () – C:\boot.ini
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/04/28 15:55:01 | 000,031,861 | —- | M] () – C:\ComboFix.txt
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/11/28 14:45:30 | 000,004,478 | RH– | M] () – C:\dell.sdr
[2008/10/31 18:45:10 | 000,000,051 | —- | M] () – C:\EventLOG.txt
[2010/11/12 14:17:29 | 000,000,081 | —- | M] () – C:\FDeClient_Start.log
[2010/02/17 00:38:47 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2010/08/12 06:37:56 | 000,000,255 | —- | M] () – C:\INSTALL.LOG
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2010/09/07 22:28:44 | 000,001,375 | -H– | M] () – C:\IPH.PH
[2009/04/26 16:10:37 | 000,006,608 | —- | M] () – C:\JavaRa.log
[2006/12/02 16:06:42 | 000,000,183 | —- | M] () – C:\LogiSetup.log
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/07/17 20:00:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/01/19 08:09:12 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/05/31 14:08:51 | 000,000,805 | —- | M] () – C:\rollback.ini
[2006/12/07 07:26:42 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2007/03/16 06:16:59 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2007/03/17 18:59:23 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2007/03/23 23:07:35 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2007/04/16 23:02:21 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2007/04/20 16:17:08 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2007/04/21 16:18:54 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2007/04/28 23:51:16 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2010/03/27 12:21:57 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2006/12/07 07:26:42 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2007/03/16 06:16:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2007/03/17 18:59:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2007/03/23 23:07:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2007/04/16 23:02:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2007/04/20 16:17:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2007/04/21 16:18:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2007/04/28 23:51:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/03/27 12:21:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2007/07/23 22:03:57 | 000,000,033 | —- | M] () – C:\wizard.txt
[2009/04/20 22:21:36 | 000,000,152 | —- | M] () – C:\YServer.txt
[11 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/02/17 00:54:16 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/16 00:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8Z.DLL
[2007/04/16 00:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8Z.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/10/14 22:41:46 | 000,072,192 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2008/07/18 13:34:32 | 000,586,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2007/07/28 15:13:13 | 000,001,610 | -H– | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2009/07/06 16:19:54 | 000,008,086 | RHS- | M] () – C:\Program Files\uninstall.log

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/02/16 19:31:05 | 004,194,304 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/02/16 21:50:47 | 000,262,144 | —- | M] () – C:\WINDOWS\system32\config\security.sav
[2010/02/16 19:31:05 | 048,758,784 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/02/16 19:31:05 | 006,553,600 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/07/06 16:20:01 | 000,000,226 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Create & Print Home.url
[2010/02/17 20:15:14 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/12/02 12:24:50 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/06/14 16:37:14 | 000,000,077 | —- | M] () – C:\Documents and Settings\Donald Bishop\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/01/19 21:31:25 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Donald Bishop\Desktop\HiJackThis.exe
[2011/01/19 21:30:13 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Donald Bishop\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >
[2010/08/31 17:04:24 | 008,134,344 | —- | M] (LastPass) – C:\Program Files\Common Files\lpuninstall.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-13 03:14:37

========== Alternate Data Streams ==========

@Alternate Data Stream - 185 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2D0C22DC
@Alternate Data Stream - 168 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0A41BE14
@Alternate Data Stream - 160 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4EFDF5FB
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:588B60C7
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AE9A3E83
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29

< End of report >


OTL Extras logfile created on: 1/19/2011 9:56:50 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\Donald Bishop\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 75.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 81.95 Gb Free Space | 55.01% Space Free | Partition Type: NTFS
Drive E: | 465.64 Gb Total Space | 430.08 Gb Free Space | 92.36% Space Free | Partition Type: FAT32
Drive F: | 3.73 Gb Total Space | 3.66 Gb Free Space | 98.26% Space Free | Partition Type: FAT32
Drive G: | 3.77 Gb Total Space | 1.96 Gb Free Space | 51.95% Space Free | Partition Type: FAT32

Computer Name: BISHOPS | User Name: Donald Bishop | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.hta [@ = htafile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – Reg Error: Key error.
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM
"C:\Program Files\Intuit\QuickBooks Enterprise Solutions 9.0\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks Enterprise Solutions 9.0\QBDBMgrN.exe:*:Enabled:QuickBooks Enterprise 9.0 Data Manager
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:TrueVector Service – (Check Point Software Technologies LTD)
"C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Winamp Remote\bin\Orb.exe" = C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb – (Orb Networks, Inc.)
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" = C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray – (Orb Networks)
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe" = C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client – (Orb Networks)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL Inc.)
"C:\Documents and Settings\Donald Bishop\My Documents\Downloads\MediaPlayer_Setup.exe" = C:\Documents and Settings\Donald Bishop\My Documents\Downloads\MediaPlayer_Setup.exe:*:Enabled:Media Player
"C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBDBMgrN.exe:*:Enabled:QuickBooks Enterprise 11.0 Data Manager – (Intuit, Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{03DF638A-D61C-4893-B8B9-845900C03163}" = TurboTax 2010 wnyiper
"{058B32E2-6310-4359-B2D4-1988390C3B83}" = Broadcom Advanced Control Suite
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{061BBC42-C5A9-4F82-AD24-EAE562968D0B}" = QuickBooks
"{0700E22B-A440-40A5-BD20-04BF618CA0F9}" = QuickBooks Enterprise Solutions: Retail Edition 10.0
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX310_series" = Canon MX310 series
"{11E0AC7D-6840-4F67-865F-EE1C13D28C38}" = QuickBooks Enterprise Solutions: Retail Edition 11.0
"{1EFCFB56-B8BB-4834-AE8E-29EE73FF8611}" = QuickBooks
"{237CD223-1B9D-47E8-A76C-E478B83CCEA2}" = File Uploader
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 21
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2C4E2E4E-A7C9-4CCB-BF03-FE6EBD5D4AB7}" = Windows Mobile Device Updater Component
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{321F110F-E26B-4E33-8F13-30A8C79DB687}" = Desk Drive
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3560CE5A-C4EF-4DB0-9ECC-BA035FE309C5}" = MSN Toolbar
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{37C5A56A-00EA-347B-B7A1-5628BED56702}" = Google Talk Plugin
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3AC785C0-EAA2-012B-AE3B-000000000000}" = TurboTax 2009 wneiper
"{3B8186F0-EAA2-012B-AE69-000000000000}" = TurboTax 2009 wnyiper
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{428102E6-8A39-48B9-8389-847F5A44A600}" = MSXML 4.0
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{50A0893D-47D8-48E0-A7E8-44BCD7E4422E}" = Microsoft SQL Server Native Client
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{53C398FE-CD56-412E-B3C7-B27F4B8B07D1}" = Microsoft IntelliType Pro 5.3
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{54BB0384-1C33-488F-A95B-877E480D3EDC}" = MSXML 4.0
"{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1" = iolo technologies' System Mechanic
"{5658CE44-2822-45C9-A5C0-F93AB4682BBF}" = Document eSort Components
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{598420E8-E9F9-4FAE-9B6C-599FDF2F611A}" = BlackBerry App World Browser Plugin
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5EFA4EA3-0604-458C-A06D-485F6B2724C9}" = PrintKey-Pro v1.05
"{5FE545A1-D215-4216-9189-E7B39C9D1CC1}" = Quicken 2011
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.9
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{7006ED29-58F2-40C3-AE87-039287AD20B6}" = Zune
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73006B34-9743-4A39-AC37-38EDFCEB6DCE}" = Adobe Product/Adobe Studio Update 10/2001
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113269180}" = Mahjong Garden Deluxe
"{830C1687-F55F-45C1-AD2B-405824DC65DB}" = Network Recording Player
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84A78614-0E4B-4A4E-BA8C-2B0A05A08E4E}" = BlackBerry Desktop Software 6.0.1
"{86604C06-DA30-425E-AECE-47304FE81C45}" = Creative Software Update
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9021848E-F315-44C7-8D45-3B16162AA73A}" = TurboTax 2010 wneiper
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91190409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Publisher 2003
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-004E-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector 32-bit
"{95140000-007C-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Facebook 32-bit
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B335897-6FBC-46B4-94B9-C159DF25AD51}" = Mastering Intuit QuickBooks Enterprise Solutions 11.0
"{9F9BE2A8-2FA2-438E-934B-6F237B641167}" = Cooliris for Internet Explorer
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A1960A82-DB70-474D-A86B-FA74466103C6}" = Drivers Install For Linksys Easylink Advisor
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B26B00DA-2E5D-4CF2-83C5-911198C0F009}" = GoodSync
"{B2F3DBD9-A9D2-4838-B45D-C917DAB32BC3}" = ScanSoft OmniPage SE 4
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0D2F614-5CE5-4DCB-8678-E5C9AF7044F8}" = Microsoft SQL Server VSS Writer
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5}" = Microsoft Outlook Personal Folders Backup
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D64DCF1C-7A95-49A4-BAFA-C42B5CF6B8B6}" = Works Suite OS Pack
"{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}" = U3Launcher
"{DBA8B9E1-C6FF-4624-9598-73D3B41A0904}" = Microsoft Digital Image Pro 9
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F007CBCE-D714-4C0B-8CE9-9B0D78116468}" = ViewNX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F18046C5-1C4E-4BE1-A3D6-A6F970E2E8E8}" = ArcSoft Panorama Maker 5
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FA0092C2-C0FE-40DA-A79E-E4C0FCA129F9}" = Intuit Entitlement Client
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 4.65
"Add-Remove Manager_is1" = Add-Remove Manager
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AI RoboForm" = RoboForm 7-1-6 (All Users)
"AIM_7" = AIM 7
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"Audit Support Center" = Audit Support Center 1.0
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"Bejeweled Blitz" = Bejeweled Blitz
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0.1
"Canon MX310 series User Registration" = Canon MX310 series User Registration
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"CleanUp!" = CleanUp!
"Clickster-Pro223" = Clickster-Pro
"Clickster-Pro224" = Clickster-Pro
"Clickster-Pro2241" = Clickster-Pro
"Creative Media Lite" = Creative Media Lite
"Defraggler" = Defraggler
"DYMO Label Software" = DYMO Label Software
"DYMO Label v.8" = DYMO Label v.8
"DYMO QuickBooks Add-In" = DYMO QuickBooks Add-In
"EasyLinkAdvisor" = Linksys EasyLink Advisor 1.6 (0033)
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"ESET Online Scanner" = ESET Online Scanner v3
"EsetOnlineScanner" = ESET Online Scanner
"ffdshow_is1" = ffdshow [rev 3154] [2009-12-09]
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"FoxyTunesForInternetExplorer" = FoxyTunes for Internet Explorer
"Google Updater" = Google Updater
"Google Video Uploader" = Google Video Uploader
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Logitech Print Service" = Logitech Print Service
"Logitech Resource Center" = Logitech Resource Center
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mastering Intuit QuickBooks Enterprise Solutions 11.0" = Mastering Intuit QuickBooks Enterprise Solutions 11.0
"Media Center 12" = Media Center 12
"Media Center 15" = Media Center 15
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"Mozilla Sunbird (0.9)" = Mozilla Sunbird (0.9)
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"MP3 Player Recovery Tool_is1" = MP3 Player Recovery Tool
"MP3 WAV Converter 4.13" = MP3 WAV Converter 4.13
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"MSNINST" = MSN
"MuVo Driver" = MuVo Driver
"MuVoT200UG" = Creative MuVo T200 User's Guide
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Orb" = Winamp Remote
"PC Matic_is1" = PC Matic 1.0.0.0
"PC Pitstop Disk MD_is1" = PC Pitstop Disk MD 2.0
"PC Pitstop Optimize2_is1" = PC Pitstop Optimize2 2.0
"PC Tune-Up" = PC Tune-Up
"PictureIt_v9" = Microsoft Digital Image Pro 9
"QcDrv" = Logitech® Camera Driver
"RealPlayer 12.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.91
"SearchAssist" = SearchAssist
"Shockwave" = Shockwave
"ShortKeys 2" = ShortKeys 2
"ShortKeys 3" = ShortKeys 3
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Songbird-release-1800" = Songbird 1.8.0 (Build 1800)
"STANDARDR" = Microsoft Office Standard 2007
"TomTom HOME" = TomTom HOME 2.7.6.2056
"TurboTax 2009" = TurboTax 2009
"TurboTax 2010" = TurboTax 2010
"Unlocker" = Unlocker 1.8.9
"Update Service" = Update Service
"VisualRoute Lite Edition" = VisualRoute Lite Edition
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2003Setup" = Microsoft Works 2003 Setup Launcher
"Yahoo! Widget Engine" = Yahoo! Widgets
"yowindow" = YoWindow
"ZoneAlarm Security Suite" = ZoneAlarm Security Suite
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker
"Zune" = Zune
"Zynga Toolbar" = Zynga Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Chromium" = Chromium
"CNET TechTracker" = CNET TechTracker
"GmailPopTroubleshooter" = Gmail POP Troubleshooter
"LastPass" = LastPass (uninstall only)
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/19/2011 1:45:57 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 1/19/2011 8:17:49 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 1/19/2011 8:17:49 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 1/19/2011 8:17:49 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 1/19/2011 8:21:15 AM | Computer Name = BISHOPS | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog

Error - 1/19/2011 9:13:55 AM | Computer Name = BISHOPS | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog

Error - 1/19/2011 9:14:34 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 1/19/2011 9:14:34 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 1/19/2011 9:14:34 AM | Computer Name = BISHOPS | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 1/19/2011 9:23:34 PM | Computer Name = BISHOPS | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Windows Application,
SystemIndex Catalog

[ OSession Events ]
Error - 10/9/2008 3:19:31 PM | Computer Name = BISHOPS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6323.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.

Error - 1/14/2011 1:52:08 AM | Computer Name = BISHOPS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 164
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 1/19/2011 1:41:04 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7023
Description = The Windows Media Player Network Sharing Service service terminated
with the following error: %%1008

Error - 1/19/2011 1:41:06 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 1/19/2011 2:22:37 AM | Computer Name = BISHOPS | Source = Print | ID = 23
Description = Printer WebEx Document Loader failed to initialize because a suitable
PageManager PDF Writer driver could not be found.

Error - 1/19/2011 2:22:57 AM | Computer Name = BISHOPS | Source = WMPNetworkSvc | ID = 866297
Description = Service 'WMPNetworkSvc' did not start correctly because the registry
could not be updated due to error '0x80070006'. If possible, reinstall Windows
Media Player.

Error - 1/19/2011 2:23:06 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7023
Description = The Windows Media Player Network Sharing Service service terminated
with the following error: %%1008

Error - 1/19/2011 2:23:13 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 1/19/2011 9:10:16 AM | Computer Name = BISHOPS | Source = Print | ID = 23
Description = Printer WebEx Document Loader failed to initialize because a suitable
PageManager PDF Writer driver could not be found.

Error - 1/19/2011 9:11:25 AM | Computer Name = BISHOPS | Source = WMPNetworkSvc | ID = 866297
Description = Service 'WMPNetworkSvc' did not start correctly because the registry
could not be updated due to error '0x80070006'. If possible, reinstall Windows
Media Player.

Error - 1/19/2011 9:11:40 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7023
Description = The Windows Media Player Network Sharing Service service terminated
with the following error: %%1008

Error - 1/19/2011 9:11:52 AM | Computer Name = BISHOPS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd


< End of report >

Thanks for your help
Hi,

Please do the following:


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thanks for your help Here are my DDS logs: DDS (Ver_10-12-12.02) - NTFSx86 Run by [removed] at 14:05:44.35 on Sat 01/22/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3574.2660 [GMT -5:00] AV: ZoneAlarm Security Suite Antivirus *Enabled/Updated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF} FW: ZoneAlarm Security Suite Firewall *Enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Creative\Shared Files\CTDevSrv.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe C:\WINDOWS\system32\ZuneBusEnum.exe C:\WINDOWS\System32\alg.exe C:\PROGRA~1\Intuit\QUICKB~1.0\QBDBMgrN.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\DYMO\DYMO Label Software\DLSService.exe C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe C:\Program Files\Creative\Software Update 3\SoftAuto.exe C:\WINDOWS\system32\LVComsX.exe C:\Program Files\Siber Systems\GoodSync\GoodSync.exe C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Warecentral\PrintKey-Pro\PKey_Pro.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe C:\WINDOWS\system32\wbem\unsecapp.exe C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBW32.EXE C:\Documents and Settings\Donald Bishop\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe C:\Program Files\Mozilla Sunbird\sunbird.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\YoWindow\yowindow.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\CheckPoint\ZAForceField\ForceField.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Logitech\SetPoint\LU\LULnchr.exe C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.AutoUpdate.exe C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe C:\WINDOWS\system32\SearchIndexer.exe C:\program files\real\realplayer\update\realsched.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\Donald Bishop\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe C:\Documents and Settings\Donald Bishop\My Documents\Downloads\dds.com C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ig uDefault_Page_URL = hxxp://www.msn.com uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyServer = http=proxy-server:8080;https=proxy-server:8080 uInternet Settings,ProxyOverride = ams-server*;*.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: RoboForm BHO: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll BHO: FoxyTunes Toolbar Helper: {784d8fbc-4165-4d88-90fb-62907acdd045} - c:\program files\foxytunes\forinternetexplorer\components\ie\FoxyTunesForIE.dll BHO: ZoneAlarm Toolbar Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: Cooliris Plug-In for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\cooliris.dll TB: &RoboForm;: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll TB: ZoneAlarm Toolbar: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll TB: FoxyTunes Toolbar: {1d1901c3-f72a-46f3-9dbb-0aaa0deef6df} - c:\program files\foxytunes\forinternetexplorer\components\ie\FoxyTunesForIE.dll TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File TB: {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - No File uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup uRun: [MRC] "c:\program files\pc tune-up\PCTuneUp.exe" /MBRSTART uRun: [DeskDriveStartup] c:\program files\blue onion software\desk drive\DeskDrive.exe uRun: [SoftAuto.exe] "c:\program files\creative\software update 3\SoftAuto.exe" uRun: [GoodSync] "c:\program files\siber systems\goodsync\GoodSync.exe" /min uRun: [Google Update] "c:\documents and settings\donald bishop\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe" uRun: [fsm] uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [CTZDetec.exe] c:\program files\creative\creative media lite\CTZDetec.exe uRun: [SystemExplorer] uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe" mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [LogitechVideoRepair] c:\program files\logitech\video\ISStart.exe mRun: [LogitechVideoTray] c:\program files\logitech\video\LogiTray.exe mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup mRun: [DLSService] "c:\program files\dymo\dymo label software\DLSService.exe" mRun: [WinPatrol] c:\program files\billp studios\winpatrol\WinPatrol.exe -expressboot mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [ISW] "c:\program files\checkpoint\zaforcefield\ForceField.exe" /icon="hidden" mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [] mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe" mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRunOnce: [SMRequiresRestart] dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe StartupFolder: c:\docume~1\donald~1\startm~1\programs\startup\cnette~1.lnk - c:\documents and settings\donald bishop\application data\cbs interactive\cnet techtracker\TechTracker.exe StartupFolder: c:\docume~1\donald~1\startm~1\programs\startup\mozill~1.lnk - c:\program files\mozilla sunbird\sunbird.exe StartupFolder: c:\docume~1\donald~1\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe StartupFolder: c:\docume~1\donald~1\startm~1\programs\startup\yowindow.lnk - c:\program files\yowindow\yowindow.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\printk~1.lnk - c:\windows\installer\{5efa4ea3-0604-458c-a06d-485f6b2724c9}\NewShortcut2_6999F52849E742A78F6F4501EF3B5A3A.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbwebconnector\QBWebConnector.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~2.lnk - c:\program files\intuit\quickbooks enterprise solutions 11.0\QBW32.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\system~1\intuit~1.lnk - c:\program files\common files\intuit\dataprotect\IntuitDataProtect.exe uPolicies-explorer: NoResolveTrack = 1 (0x1) mPolicies-explorer: NoResolveTrack = 1 (0x1) IE: &Winamp; Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: LastPass - file://c:\program files\lastpass\context.html?cmd=lastpass IE: LastPass Fill Forms - file://c:\program files\lastpass\context.html?cmd=fillforms IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - {8C85E2EE-9FD6-11D5-B770-504D54C10000} - c:\program files\visualroute lite edition\vrie.dll IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - c:\program files\piclensie\cooliris.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {16F67783-7E72-4C39-99C4-4780A8335484} - hxxp://www.syncmyride.com/Own/Modules/UploadDownload/applets/sync.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1266388971562 DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - hxxp://mediaplayer.walmart.com/installer/install.cab DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} - hxxp://www.shockwave.com/content/bigcityadventuresf/sis/JBGamePlayer.cab DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} - hxxp://www.worldwinner.com/games/v45/royal/royal.cab DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://clubgames.pogo.com/online2/pogop/bejeweled2/popcaploader_v6.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll Handler: intu-help-qb4 - {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - c:\program files\intuit\quickbooks enterprise solutions 11.0\HelpAsyncPluggableProtocol.dll Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll Notify: igfxcui - igfxdev.dll Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File IFEO: wupdmgr.exe - ntsd– Hosts: 127.0.0.1 www.spywareinfo.com ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\donald~1\applic~1\mozilla\firefox\profiles\i9q0zbvp.default\ FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig FF - prefs.js: network.proxy.http - proxy-server FF - prefs.js: network.proxy.http_port - 8080 FF - prefs.js: network.proxy.ssl - proxy-server FF - prefs.js: network.proxy.ssl_port - 8080 FF - prefs.js: network.proxy.type - 0 FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll FF - component: c:\documents and settings\donald bishop\application data\mozilla\firefox\profiles\i9q0zbvp.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll FF - component: c:\documents and settings\donald bishop\application data\mozilla\firefox\profiles\i9q0zbvp.default\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll FF - component: c:\documents and settings\donald bishop\application data\mozilla\firefox\profiles\i9q0zbvp.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll FF - component: c:\documents and settings\donald bishop\application data\mozilla\firefox\profiles\i9q0zbvp.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll FF - component: c:\program files\siber systems\ai roboform\firefox\components\rfproxy_31.dll FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\documents and settings\donald bishop\application data\move networks\plugins\npqmp071505000011.dll FF - plugin: c:\documents and settings\donald bishop\application data\mozilla\firefox\profiles\i9q0zbvp.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\documents and settings\donald bishop\application data\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\donald bishop\application data\mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: c:\documents and settings\donald bishop\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll FF - plugin: c:\program files\research in motion limited\blackberry app world browser plugin\npappworld.dll FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} FF - Ext: LittleFox: {29852C08-1E91-4889-A6BF-C77F91D6A8F3} - %profile%\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3} FF - Ext: FoxyTunes: {463F6CA5-EE3C-4be1-B7E6-7FEE11953374} - %profile%\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374} FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822} FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\Ext FF - Ext: Roboform Toolbar for Firefox: {22119944-ED35-4ab1-910B-E619EA06A115} - c:\program files\siber systems\ai roboform\Firefox ============= SERVICES / DRIVERS =============== R0 kl1;kl1;c:\windows\system32\drivers\kl1.sys [2010-8-12 128016] R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2010-8-12 317072] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2006-12-2 528128] R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2010-10-19 724152] R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2010-10-19 724152] R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2010-3-16 26352] R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2010-3-16 493032] R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-6-30 10384] R2 QBVSS;QBIDPService;c:\program files\common files\intuit\dataprotect\QBIDPService.exe [2010-12-2 1251840] R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2010-8-24 92008] R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] R3 QuickBooksDB21;QuickBooksDB21;c:\progra~1\intuit\quickb~1.0\qbdbmgrn.exe -hvquickbooksdb21 –> c:\progra~1\intuit\quickb~1.0\QBDBMgrN.exe -hvQuickBooksDB21 [?] S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?] S2 gupdate1c9949bd8522a78;Google Update Service (gupdate1c9949bd8522a78);c:\program files\google\update\GoogleUpdate.exe [2009-2-21 133104] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-9-15 10976] S3 Media Center 15 Service;Media Center 15 Service;c:\program files\j river\media center 15\JRService.exe [2010-8-6 376832] S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-4 14336] S3 se3ebus;Sony Ericsson Device 062 (WDM);c:\windows\system32\drivers\se3ebus.sys [2007-4-10 83080] S3 se3emdfl;Sony Ericsson Device 062 USB WMC Modem Filter;c:\windows\system32\drivers\se3emdfl.sys [2007-4-10 15112] S3 se3emdm;Sony Ericsson Device 062 USB WMC Modem Driver;c:\windows\system32\drivers\se3emdm.sys [2007-4-10 108552] S3 se3emgmt;Sony Ericsson Device 062 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\se3emgmt.sys [2008-9-15 100360] S3 se3eobex;Sony Ericsson Device 062 USB WMC OBEX Interface;c:\windows\system32\drivers\se3eobex.sys [2008-9-15 98568] S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\zune\WMZuneComm.exe [2010-9-24 268528] S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2010-3-9 85504] =============== File Associations =============== JSEFile=NOTEPAD.EXE %1 regfile=NOTEPAD.EXE %1 scrfile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 =============== Created Last 30 ================ 2011-01-21 12:11:10 67 —-a-w- C:\NtfB200.tmp 2011-01-21 12:11:10 67 —-a-w- C:\NtfB1FF.tmp 2011-01-15 13:02:11 ——– d—–w- c:\docume~1\donald~1\applic~1\RoboForm 2011-01-14 12:42:08 ——– d-sh–w- C:\Qui9AD.tmp 2011-01-14 12:42:08 ——– d-sh–w- C:\Qui9AC.tmp 2011-01-14 12:42:08 ——– d-sh–w- C:\Qui9AB.tmp 2011-01-04 01:10:25 ——– d—–w- c:\docume~1\donald~1\locals~1\applic~1\Intuit_Inc 2010-12-25 18:11:27 ——– d—–w- c:\program files\Research In Motion Limited 2010-12-23 20:48:39 ——– d—–w- c:\docume~1\donald~1\applic~1\Blackberry Desktop ==================== Find3M ==================== 2010-12-20 20:14:08 364544 ——w- c:\windows\system32\MC15.exe 2010-12-07 13:08:24 684544 —-a-w- c:\windows\system32\yowindow.scr 2010-12-04 00:36:29 106496 —-a-w- c:\windows\system32\ATL71.DLL 2010-12-02 20:21:04 87688 —-a-w- c:\windows\system32\IncContxMenu.dll 2010-12-02 20:20:18 11776 —-a-w- c:\windows\system32\smrgdf.exe 2010-12-02 20:20:10 29696 —-a-w- c:\windows\system32\iolobtdfg.exe 2010-12-02 20:18:28 2234040 —-a-w- c:\windows\system32\Incinerator.dll 2010-11-29 22:38:30 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2010-11-29 22:38:30 69632 —-a-w- c:\windows\system32\QuickTime.qts 2010-11-18 18:12:44 81920 —-a-w- c:\windows\system32\isign32.dll 2010-11-09 14:52:35 249856 —-a-w- c:\windows\system32\odbc32.dll 2010-11-06 00:26:58 916480 —-a-w- c:\windows\system32\wininet.dll 2010-11-06 00:26:58 43520 —-a-w- c:\windows\system32\licmgr10.dll 2010-11-06 00:26:58 1469440 ——w- c:\windows\system32\inetcpl.cpl 2010-11-03 12:25:54 385024 —-a-w- c:\windows\system32\html.iec 2010-10-28 13:13:22 290048 —-a-w- c:\windows\system32\atmfd.dll 2010-10-26 13:25:00 1853312 —-a-w- c:\windows\system32\win32k.sys 2010-08-31 22:04:24 8134344 —-a-w- c:\program files\common files\lpuninstall.exe ============= FINISH: 14:08:51.15 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-12-12.02) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 2/17/2010 12:59:24 AM System Uptime: 1/20/2011 7:58:18 PM (43 hours ago) Motherboard: Dell Inc. | | 0PY423 Processor: Intel® Pentium® D CPU 2.80GHz | Microprocessor | 2793/800mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 149 GiB total, 81.423 GiB free. D: is CDROM () E: is FIXED (FAT32) - 466 GiB total, 430.077 GiB free. F: is Removable G: is Removable H: is Removable I: is Removable J: is Removable K: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP398: 12/27/2010 2:14:06 PM - System Checkpoint RP399: 12/28/2010 6:45:48 PM - System Checkpoint RP400: 12/29/2010 8:33:59 PM - System Checkpoint RP401: 12/30/2010 8:59:36 PM - System Checkpoint RP402: 12/31/2010 10:16:25 PM - System Checkpoint RP403: 1/2/2011 1:19:25 AM - System Checkpoint RP404: 1/3/2011 1:22:29 AM - System Checkpoint RP405: 1/4/2011 1:25:28 AM - System Checkpoint RP406: 1/5/2011 4:56:54 AM - System Checkpoint RP407: 1/5/2011 8:03:51 PM - Software Distribution Service 3.0 RP408: 1/6/2011 8:29:19 PM - System Checkpoint RP409: 1/7/2011 8:58:59 PM - System Checkpoint RP410: 1/8/2011 12:37:37 AM - Revo Uninstaller's restore point - iLike Sidebar RP411: 1/8/2011 12:38:27 AM - Removed iLike Sidebar RP412: 1/8/2011 1:11:29 AM - Revo Uninstaller's restore point - BlackBerry Desktop Software 6.0.1 RP413: 1/8/2011 1:24:39 AM - Installed BlackBerry Desktop Software 6.0.1. RP414: 1/9/2011 3:22:56 AM - System Checkpoint RP415: 1/10/2011 4:49:09 AM - System Checkpoint RP416: 1/11/2011 4:55:06 AM - System Checkpoint RP417: 1/12/2011 5:07:06 AM - System Checkpoint RP418: 1/12/2011 7:35:19 AM - Software Distribution Service 3.0 RP419: 1/12/2011 8:10:04 PM - Software Distribution Service 3.0 RP420: 1/12/2011 10:08:26 PM - Software Distribution Service 3.0 RP421: 1/12/2011 10:53:35 PM - Revo Uninstaller's restore point - McAfee Security Scan Plus RP422: 1/12/2011 10:55:17 PM - Removed Adobe Reader 9.4.1. RP423: 1/12/2011 10:57:53 PM - Installed Adobe Reader X. RP424: 1/14/2011 1:19:04 AM - System Checkpoint RP425: 1/14/2011 5:28:56 PM - Installed TurboTax 2010 wrapper RP426: 1/14/2011 5:49:15 PM - Installed TurboTax 2010 wnyiper RP427: 1/14/2011 5:49:51 PM - Installed TurboTax 2010 wneiper RP428: 1/15/2011 6:09:10 PM - System Checkpoint RP429: 1/17/2011 2:32:33 AM - System Checkpoint RP430: 1/18/2011 4:57:10 AM - System Checkpoint RP431: 1/18/2011 8:19:47 PM - Revo Uninstaller's restore point - Google Chrome RP432: 1/18/2011 11:56:07 PM - Revo Uninstaller's restore point - System Explorer 2.6.3 RP433: 1/19/2011 9:37:53 PM - Revo Uninstaller's restore point - Creative MuVo N200 Media Explorer RP434: 1/19/2011 9:38:48 PM - Configured Your Application Name RP435: 1/19/2011 9:39:34 PM - Configured Your Application Name RP436: 1/19/2011 9:45:39 PM - Revo Uninstaller's restore point - Perfect Optimizer 5.2 RP437: 1/19/2011 9:49:09 PM - Revo Uninstaller's restore point - Software Informer 1.0 BETA RP438: 1/19/2011 9:51:08 PM - Revo Uninstaller's restore point - AnswerWorks 4.0 Runtime - English RP439: 1/19/2011 9:51:39 PM - Removed AnswerWorks 4.0 Runtime - English RP440: 1/19/2011 9:59:30 PM - OTL Restore Point RP441: 1/20/2011 10:27:18 PM - System Checkpoint RP442: 1/21/2011 10:33:14 PM - System Checkpoint ==== Installed Programs ====================== 7-Zip 4.65 Acrobat.com Add-Remove Manager Adobe AIR Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Product/Adobe Studio Update 10/2001 Adobe Reader X Adobe Shockwave Player 11.5 AIM 7 Amazon MP3 Downloader 1.0.10 AnswerWorks 5.0 English Runtime Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft Panorama Maker 5 Audit Support Center 1.0 Bejeweled 2 Deluxe Bejeweled Blitz Bing Maps 3D BlackBerry App World Browser Plugin BlackBerry Desktop Software 6.0.1 Bonjour Broadcom Advanced Control Suite Canon MP Navigator EX 1.0 Canon MX310 series Canon MX310 series User Registration Canon My Printer Canon Utilities Easy-PhotoPrint EX Canon Utilities Solution Menu CCleaner CDBurnerXP CDDRV_Installer Chromium CleanUp! Clickster-Pro CNET TechTracker Compatibility Pack for the 2007 Office system Cooliris for Internet Explorer CP_Package_Variety1 CP_Package_Variety2 CP_Package_Variety3 Creative Media Lite Creative MediaSource Creative MuVo T200 User's Guide Creative Software Update Defraggler Dell Driver Reset Tool Desk Drive Document eSort Components Download Updater (AOL LLC) Drivers Install For Linksys Easylink Advisor DYMO Label Software DYMO Label v.8 DYMO QuickBooks Add-In ESET Online Scanner ESET Online Scanner v3 ffdshow [rev 3154] [2009-12-09] File Uploader FoxyTunes for Firefox FoxyTunes for Internet Explorer Full Tilt Poker getPlus® for Adobe Gmail POP Troubleshooter GoodSync Google Earth Google Talk Plugin Google Toolbar for Internet Explorer Google Update Helper Google Updater Google Video Uploader HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows Media Format 11 SDK (KB973442) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Intel® Graphics Media Accelerator Driver Intuit Entitlement Client iolo technologies' System Mechanic iPhone Configuration Utility iTunes Java Auto Updater Java™ 6 Update 21 Java™ 6 Update 7 KhalInstallWrapper LastPass (uninstall only) Linksys EasyLink Advisor 1.6 (0033) Logitech Print Service Logitech QuickCam Software Logitech Resource Center Logitech SetPoint Logitech® Camera Driver Mahjong Garden Deluxe Malwarebytes' Anti-Malware Mastering Intuit QuickBooks Enterprise Solutions 11.0 MCU Media Center 12 Media Center 15 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Digital Image Pro 9 Microsoft IntelliType Pro 5.3 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft National Language Support Downlevel APIs Microsoft Office 2003 Web Components Microsoft Office 2007 Primary Interop Assemblies Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher 2003 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Small Business Connectivity Components Microsoft Office Standard 2007 Microsoft Office Word MUI (English) 2007 Microsoft Outlook Personal Folders Backup Microsoft Outlook Social Connector 32-bit Microsoft Outlook Social Connector Provider for Facebook 32-bit Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual C Runtime Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual Studio 2005 Tools for Office Runtime Microsoft WinUsb 1.0 Microsoft Works 2003 Setup Launcher Microsoft Works 7.0 Mozilla Firefox (3.6.13) Mozilla Sunbird (0.9) MP3 Player Recovery Tool MP3 WAV Converter 4.13 MSN MSN Music Assistant MSN Toolbar MSXML 4.0 MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK MSXML 6 Service Pack 2 (KB973686) MuVo Driver Network Recording Player Nikon Message Center Nikon Transfer PC Matic 1.0.0.0 PC Pitstop Disk MD 2.0 PC Pitstop Optimize2 2.0 PC Tune-Up Picture Control Utility PL-2303 USB-to-Serial PowerDVD 5.9 PrintKey-Pro v1.05 QuickBooks QuickBooks Enterprise Solutions: Retail Edition 10.0 QuickBooks Enterprise Solutions: Retail Edition 11.0 Quicken 2011 QuickTime RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer RealUpgrade 1.1 Revo Uninstaller 1.91 RoboForm 7-1-6 (All Users) Safari ScanSoft OmniPage SE 4 SearchAssist Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2289158) Security Update for 2007 Microsoft Office System (KB2344875) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft Office Excel 2007 (KB2345035) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB982158) Security Update for Microsoft Office PowerPoint Viewer (KB2413381) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953155) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165-v2) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Shockwave ShortKeys 2 ShortKeys 3 Songbird 1.8.0 (Build 1800) Spelling Dictionaries Support For Adobe Reader 8 SupportSoft Assisted Service TomTom HOME 2.7.6.2056 TomTom HOME Visual Studio Merge Modules TurboTax 2009 TurboTax 2009 WinPerFedFormset TurboTax 2009 WinPerReleaseEngine TurboTax 2009 WinPerTaxSupport TurboTax 2009 wneiper TurboTax 2009 wnyiper TurboTax 2009 wrapper TurboTax 2010 TurboTax 2010 WinPerFedFormset TurboTax 2010 WinPerReleaseEngine TurboTax 2010 WinPerTaxSupport TurboTax 2010 wneiper TurboTax 2010 wnyiper TurboTax 2010 wrapper U3Launcher Unlocker 1.8.9 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office Outlook 2007 (KB2412171) Update for Outlook 2007 Junk Email Filter (KB2483110) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB978506) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update for Windows XP (KB978207) Update Service URGE VC 9.0 Runtime ViewNX Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 Visual C++ 8.0 CRT (x86) WinSXS MSM Visual Studio 2005 Tools for Office Second Edition Runtime VisualRoute Lite Edition WD Diagnostics WebEx Support Manager for Internet Explorer WebFldrs XP Winamp Winamp Detector Plug-in Winamp Remote Winamp Toolbar Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live installer Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player Firefox Plugin Windows Mobile Device Updater Component Windows XP Service Pack 3 WinPatrol Works Suite OS Pack Yahoo! Widgets YoWindow ZoneAlarm Security Suite ZoneAlarm Spy Blocker ZoneAlarm Toolbar Zune Zune Language Pack (DEU) Zune Language Pack (ESP) Zune Language Pack (FRA) Zune Language Pack (ITA) Zune Language Pack (NLD) Zune Language Pack (PTB) Zune Language Pack (PTG) Zynga Toolbar ==== Event Viewer Messages From Past Week ======== 1/20/2011 7:23:48 AM, error: Service Control Manager [7034] - The TrueVector Internet Monitor service terminated unexpectedly. It has done this 1 time(s). 1/18/2011 7:51:35 PM, error: Service Control Manager [7034] - The QBIDPService service terminated unexpectedly. It has done this 1 time(s). 1/18/2011 7:51:31 PM, error: Service Control Manager [7034] - The QuickBooksDB21 service terminated unexpectedly. It has done this 1 time(s). 1/18/2011 7:51:27 PM, error: Service Control Manager [7034] - The QBCFMonitorService service terminated unexpectedly. It has done this 1 time(s). 1/18/2011 7:39:39 PM, error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23). 1/18/2011 11:40:03 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 1/18/2011 11:31:50 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec kl1 KLIF Lbd MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip vsdatant 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The TrueVector Internet Monitor service depends on the vsdatant service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:14 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 1/18/2011 11:31:13 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 1/18/2011 11:21:15 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Lbd 1/18/2011 11:20:56 PM, error: Service Control Manager [7023] - The Windows Media Player Network Sharing Service service terminated with the following error: An attempt was made to reference a token that does not exist. 1/18/2011 11:20:40 PM, error: WMPNetworkSvc [14329] - Service 'WMPNetworkSvc' did not start correctly because the registry could not be updated due to error '0x80070006'. If possible, reinstall Windows Media Player. 1/18/2011 11:20:22 PM, error: Print [23] - Printer WebEx Document Loader failed to initialize because a suitable PageManager PDF Writer driver could not be found. ==== End Of File =========================== and my gmer file is attached

Attachments:

Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ruh oh, While running CombFix (I think it started deleting some program files), I got a Blue Screen: Plug & Play has detected an error most likely caused by a faulty driver STOP: 0x000000CA, (0x0000004,0x8976c310,0x0000000, 0x00000000) I noticed while I was running ComboFix, my phone was charging on USB? Oops? Will await further instruction Thanks
ok

unplug your phone

make sure all other programs are closed

make sure all your security programs are disabled

delete the copy of combofix that you have on your desktop

download a fresh copy, but rename it to iexplore before saving it to your desktop

now try and run it again

if it still wont run

try running it in safe mode

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY repeatedly,
  • this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
  • go into your usual account
Hi


Did you set a Proxy Server 8080 for a reason?


Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
C:\Ntf8.tmp
C:\Ntf7.tmp
C:\Ntf16.tmp
C:\Ntf15.tmp
C:\Ntf6.tmp
C:\Ntf5.tmp
C:\Ntf4.tmp
C:\Ntf3.tmp
C:\NtfB200.tmp
C:\NtfB1FF.tmp

Folder::
C:\Qui9AB.tmp
C:\Qui9AD.tmp
C:\Qui9AC.tmp

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
I have no knowledge of Proxy Server 8080

My Combo Fix, Malwarebytes and Eset Scan Reports:

ComboFix 11-01-22.03 - Donald Bishop 01/23/2011 11:43:17.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3574.3018 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Donald Bishop\Desktop\CFScript.txt
AV: ZoneAlarm Security Suite Antivirus *Disabled/Updated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

FILE ::
"C:\Ntf15.tmp"
"C:\Ntf16.tmp"
"C:\Ntf3.tmp"
"C:\Ntf4.tmp"
"C:\Ntf5.tmp"
"C:\Ntf6.tmp"
"C:\Ntf7.tmp"
"C:\Ntf8.tmp"
"C:\NtfB1FF.tmp"
"C:\NtfB200.tmp"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Ntf7.tmp
C:\Ntf8.tmp
C:\Qui9AB.tmp
C:\Qui9AC.tmp
C:\Qui9AD.tmp

.
((((((((((((((((((((((((( Files Created from 2010-12-23 to 2011-01-23 )))))))))))))))))))))))))))))))
.

2011-01-15 13:02 . 2011-01-15 13:02 ——– d—–w- c:\documents and settings\Donald Bishop\Application Data\RoboForm
2011-01-13 03:52 . 2011-01-13 03:52 ——– d—–w- c:\program files\Common Files\Adobe AIR
2011-01-04 01:10 . 2011-01-04 01:10 ——– d—–w- c:\documents and settings\Donald Bishop\Local Settings\Application Data\Intuit_Inc
2010-12-25 18:11 . 2010-12-25 18:11 ——– d—–w- c:\program files\Research In Motion Limited

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 23:09 . 2010-12-03 21:22 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 23:08 . 2010-12-03 21:22 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 20:14 . 2010-08-07 02:41 364544 ——w- c:\windows\system32\MC15.exe
2010-12-07 13:08 . 2010-12-07 13:08 684544 —-a-w- c:\windows\system32\yowindow.scr
2010-12-04 00:42 . 2010-12-04 00:42 49152 —-a-r- c:\documents and settings\Donald Bishop\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
2010-12-04 00:41 . 2010-12-04 00:41 335872 —-a-r- c:\documents and settings\Donald Bishop\Application Data\Microsoft\Installer\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}\ARPPRODUCTICON.exe
2010-12-04 00:40 . 2010-12-04 00:40 57344 —-a-r- c:\documents and settings\Donald Bishop\Application Data\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2010-12-04 00:36 . 2006-12-02 19:02 106496 —-a-w- c:\windows\system32\ATL71.DLL
2010-12-02 20:21 . 2010-10-19 21:54 87688 —-a-w- c:\windows\system32\IncContxMenu.dll
2010-12-02 20:20 . 2008-04-04 03:38 11776 —-a-w- c:\windows\system32\smrgdf.exe
2010-12-02 20:20 . 2008-04-04 03:38 29696 —-a-w- c:\windows\system32\iolobtdfg.exe
2010-12-02 20:18 . 2008-04-04 03:38 2234040 —-a-w- c:\windows\system32\Incinerator.dll
2010-11-29 22:38 . 2010-11-29 22:38 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 22:38 . 2010-11-29 22:38 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-11-18 18:12 . 2004-08-10 18:02 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 2004-08-04 10:00 249856 —-a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2004-08-04 10:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2004-08-04 10:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2004-08-04 10:00 385024 —-a-w- c:\windows\system32\html.iec
2010-11-02 19:52 . 2010-11-02 19:52 12 —-a-w- c:\windows\Fonts\wfonts.key
2010-11-02 15:17 . 2004-08-04 10:00 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2004-08-04 10:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2004-08-04 10:00 1853312 —-a-w- c:\windows\system32\win32k.sys
2010-08-31 22:04 . 2010-08-31 22:04 8134344 —-a-w- c:\program files\Common Files\lpuninstall.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"MRC"="c:\program files\PC Tune-Up\PCTuneUp.exe" [2007-10-12 2435072]
"DeskDriveStartup"="c:\program files\Blue Onion Software\Desk Drive\DeskDrive.exe" [2008-07-27 41984]
"SoftAuto.exe"="c:\program files\Creative\Software Update 3\SoftAuto.exe" [2008-08-13 405504]
"GoodSync"="c:\program files\Siber Systems\GoodSync\GoodSync.exe" [2011-01-07 4990392]
"Google Update"="c:\documents and settings\Donald Bishop\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-05 133104]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2010-08-24 247144]
"CTZDetec.exe"="c:\program files\Creative\Creative Media Lite\CTZDetec.exe" [2008-04-24 368640]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2011-01-15 107000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2010-11-10 1457928]
"DLSService"="c:\program files\DYMO\DYMO Label Software\DLSService.exe" [2009-06-24 55808]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\WinPatrol.exe" [2010-10-24 329096]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-07-21 1038848]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-09-24 159472]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2010-11-20 274608]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 69632]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Install LastPass FF RunOnce.lnk - c:\program files\Common Files\lpuninstall.exe [2010-8-31 8134344]
Install LastPass IE RunOnce.lnk - c:\program files\Common Files\lpuninstall.exe [2010-8-31 8134344]

c:\documents and settings\QBDataServiceUser18\Start Menu\Programs\Startup\
Install LastPass FF RunOnce.lnk - c:\program files\Common Files\lpuninstall.exe [2010-8-31 8134344]
Install LastPass IE RunOnce.lnk - c:\program files\Common Files\lpuninstall.exe [2010-8-31 8134344]

c:\documents and settings\Donald Bishop\Start Menu\Programs\Startup\
CNET TechTracker.lnk - c:\documents and settings\Donald Bishop\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe [2010-12-2 2621952]
Mozilla Sunbird.lnk - c:\program files\Mozilla Sunbird\sunbird.exe [2009-5-31 6354540]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-18 4742184]
YoWindow.lnk - c:\program files\YoWindow\yowindow.exe [2010-12-4 739328]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-6-30 809488]
PrintKey-Pro.lnk - c:\windows\Installer\{5EFA4EA3-0604-458C-A06D-485F6B2724C9}\NewShortcut2_6999F52849E742A78F6F4501EF3B5A3A.exe [2009-4-13 1078]
QuickBooks Web Connector.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe [2009-2-9 300328]
QuickBooks_Standard_21.lnk - c:\program files\Intuit\QuickBooks Enterprise Solutions 11.0\QBW32.EXE [2010-12-3 1178400]

c:\documents and settings\All Users\Start Menu\Programs\Startup\SystemExplorerDisabled
Intuit Data Protect.lnk - c:\program files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe [2010-12-2 5756680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-11-07 20:41 72208 —-a-w- c:\program files\Common Files\logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
Domestic Security Version 4.87

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Printkey2000.lnk]
backup=c:\windows\pss\Printkey2000.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Web Connector.lnk]
backup=c:\windows\pss\QuickBooks Web Connector.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ShortKeys 2.lnk]
backup=c:\windows\pss\ShortKeys 2.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-04-04 01:50 1603152 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-05-15 01:01 644696 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2006-04-06 15:51 49152 -c–a-w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-10-14 18:46 77824 -c–a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISW]
2010-06-15 11:09 730600 —-a-w- c:\program files\CheckPoint\ZAForceField\ForceField.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 22:16 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
2008-04-01 01:54 507904 —-a-w- c:\program files\Winamp Remote\bin\OrbTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 14:03 210472 —-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-04-05 18:02 68856 -c–a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\type32]
2005-03-15 09:46 196608 —-a-w- c:\program files\Microsoft IntelliType Pro\type32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2010-11-30 14:10 74752 —-a-w- c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-10-19 01:05 204288 -c–a-w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Documents and Settings\\Donald Bishop\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Donald Bishop\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Intuit\\QuickBooks Enterprise Solutions 11.0\\QBDBMgrN.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=

R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [10/19/2010 4:54 PM 724152]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [10/19/2010 4:54 PM 724152]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [3/16/2010 3:55 AM 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [3/16/2010 3:55 AM 493032]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [6/30/2009 4:06 PM 10384]
R2 QBVSS;QBIDPService;c:\program files\Common Files\Intuit\DataProtect\QBIDPService.exe [12/2/2010 1:02 PM 1251840]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [8/24/2010 4:38 AM 92008]
R3 QuickBooksDB21;QuickBooksDB21;c:\progra~1\Intuit\QUICKB~1.0\QBDBMgrN.exe -hvQuickBooksDB21 –> c:\progra~1\Intuit\QUICKB~1.0\QBDBMgrN.exe -hvQuickBooksDB21 [?]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate1c9949bd8522a78;Google Update Service (gupdate1c9949bd8522a78);c:\program files\Google\Update\GoogleUpdate.exe [2/21/2009 10:15 PM 133104]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [9/15/2008 10:31 AM 10976]
S3 Media Center 15 Service;Media Center 15 Service;c:\program files\J River\Media Center 15\JRService.exe [8/6/2010 9:42 PM 376832]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [8/4/2004 5:00 AM 14336]
S3 se3ebus;Sony Ericsson Device 062 (WDM);c:\windows\system32\drivers\se3ebus.sys [4/10/2007 12:14 PM 83080]
S3 se3emdfl;Sony Ericsson Device 062 USB WMC Modem Filter;c:\windows\system32\drivers\se3emdfl.sys [4/10/2007 12:14 PM 15112]
S3 se3emdm;Sony Ericsson Device 062 USB WMC Modem Driver;c:\windows\system32\drivers\se3emdm.sys [4/10/2007 12:14 PM 108552]
S3 se3emgmt;Sony Ericsson Device 062 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\se3emgmt.sys [9/15/2008 10:22 AM 100360]
S3 se3eobex;Sony Ericsson Device 062 USB WMC OBEX Interface;c:\windows\system32\drivers\se3eobex.sys [9/15/2008 10:22 AM 98568]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [9/24/2010 12:19 PM 268528]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [3/9/2010 5:12 PM 85504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2011-01-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]

2011-01-20 c:\windows\Tasks\Defraggler Volume C Task.job
- c:\program files\Defraggler\df.exe [2010-07-30 19:18]

2011-01-21 c:\windows\Tasks\Defraggler Volume E Task.job
- c:\program files\Defraggler\df.exe [2010-07-30 19:18]

2011-01-23 c:\windows\Tasks\GoodSync - Quicken.job
- c:\program files\Siber Systems\GoodSync\GoodSync.exe [2011-01-07 07:08]

2011-01-23 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-27 02:58]

2011-01-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-22 03:15]

2011-01-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-22 03:15]

2011-01-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-515941520-1664358963-1588231850-1006Core.job
- c:\documents and settings\Donald Bishop\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-30 22:12]

2011-01-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-515941520-1664358963-1588231850-1006UA.job
- c:\documents and settings\Donald Bishop\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-30 22:12]

2011-01-23 c:\windows\Tasks\PC Pitstop Disk MD - Daily E.job
- c:\program files\PCPitstop\Disk MD\DiskMD.exe [2007-08-18 18:07]

2011-01-23 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-515941520-1664358963-1588231850-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]

2011-01-23 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-515941520-1664358963-1588231850-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]

2011-01-23 c:\windows\Tasks\User_Feed_Synchronization-{4E88510E-6616-4593-BDF4-A4DC733FBF4C}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]

2011-01-23 c:\windows\Tasks\User_Feed_Synchronization-{6FE87274-923A-474F-880B-FB60BED54A8F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=proxy-server:8080;https=proxy-server:8080
uInternet Settings,ProxyOverride = ams-server*;*.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: LastPass - file://c:\program files\LastPass\context.html?cmd=lastpass
IE: LastPass Fill Forms - file://c:\program files\LastPass\context.html?cmd=fillforms
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Handler: intu-help-qb4 - {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - c:\program files\Intuit\QuickBooks Enterprise Solutions 11.0\HelpAsyncPluggableProtocol.dll
DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab
DPF: {16F67783-7E72-4C39-99C4-4780A8335484} - hxxp://www.syncmyride.com/Own/Modules/UploadDownload/applets/sync.cab
DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} - hxxp://www.shockwave.com/content/bigcityadventuresf/sis/JBGamePlayer.cab
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath - c:\documents and settings\Donald Bishop\Application Data\Mozilla\Firefox\Profiles\i9q0zbvp.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - prefs.js: network.proxy.http - proxy-server
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.ssl - proxy-server
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
FF - Ext: LittleFox: {29852C08-1E91-4889-A6BF-C77F91D6A8F3} - %profile%\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}
FF - Ext: FoxyTunes: {463F6CA5-EE3C-4be1-B7E6-7FEE11953374} - %profile%\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: Roboform Toolbar for Firefox: {22119944-ED35-4ab1-910B-E619EA06A115} - c:\program files\Siber Systems\AI RoboForm\Firefox
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-23 11:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
CTZDetec.exe = c:\program files\Creative\Creative Media Lite\CTZDetec.exe?"???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(648)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

- - - - - - - > 'lsass.exe'(704)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

- - - - - - - > 'explorer.exe'(4276)
c:\windows\system32\WININET.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Creative\Shared Files\CTDevSrv.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\windows\system32\ZuneBusEnum.exe
c:\progra~1\Intuit\QUICKB~1.0\QBDBMgrN.exe
c:\windows\system32\LVComsX.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-01-23 12:14:40 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-23 17:14
ComboFix2.txt 2011-01-23 06:34
ComboFix3.txt 2009-04-28 20:55

Pre-Run: 87,317,061,632 bytes free
Post-Run: 87,263,125,504 bytes free

- - End Of File - - 0B3826423345D4E51A551FF1A1DB6313



Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5577

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/23/2011 12:20:56 PM
mbam-log-2011-01-23 (12-20-56).txt

Scan type: Quick scan
Objects scanned: 188367
Time elapsed: 4 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Eset scan found nothing…..no report generated
Hi,

Please do the following:

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 23 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 23 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u23 with JavaFX 1 License Agreement". Click on Continue. The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u23-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT

Please post a fresh DDS Log and advise how your computer is running now and if there are any outstanding issues
Seems to be running fine….I have a problem with an AdAware error that I've had for sometime…I have referred this to the Windows site I originally came from (jpeg attached) DDS Logs: DDS (Ver_10-12-12.02) - NTFSx86 Run by [removed] at 19:11:05.17 on Sun 01/23/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3574.2615 [GMT -5:00] AV: ZoneAlarm Security Suite Antivirus *Enabled/Updated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF} FW: ZoneAlarm Security Suite Firewall *Enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Creative\Shared Files\CTDevSrv.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\system32\ZuneBusEnum.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\alg.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\DYMO\DYMO Label Software\DLSService.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe C:\program files\real\realplayer\update\realsched.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\Program Files\Blue Onion Software\Desk Drive\DeskDrive.exe C:\WINDOWS\system32\LVComsX.exe C:\PROGRA~1\Intuit\QUICKB~1.0\QBDBMgrN.exe C:\Program Files\Creative\Software Update 3\SoftAuto.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\Siber Systems\GoodSync\GoodSync.exe C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Warecentral\PrintKey-Pro\PKey_Pro.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe C:\Program Files\Intuit\QuickBooks Enterprise Solutions 11.0\QBW32.EXE C:\WINDOWS\system32\wbem\unsecapp.exe C:\Documents and Settings\Donald Bishop\Application Data\CBS Interactive\CNET TechTracker\TechTracker.exe C:\Program Files\Mozilla Sunbird\sunbird.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe C:\Program Files\CheckPoint\ZAForceField\ForceField.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\YoWindow\yowindow.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Donald Bishop\Desktop\dds.com C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ig uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyServer = http=proxy-server:8080;https=proxy-server:8080 uInternet Settings,ProxyOverride = ams-server*;*.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: RoboForm BHO: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll BHO: FoxyTunes Toolbar Helper: {784d8fbc-4165-4d88-90fb-62907acdd045} - c:\program files\foxytunes\forinternetexplorer\components\ie\FoxyTunesForIE.dll BHO: ZoneAlarm Toolbar Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: Cooliris Plug-In for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\cooliris.dll TB: &RoboForm;: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll TB: ZoneAlarm Toolbar: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll TB: FoxyTunes Toolbar: {1d1901c3-f72a-46f3-9dbb-0aaa0deef6df} - c:\program files\foxytunes\forinternetexplorer\components\ie\FoxyTunesForIE.dll TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File TB: {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - No File uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup uRun: [MRC] "c:\program files\pc tune-up\PCTuneUp.exe" /MBRSTART uRun: [DeskDriveStartup] c:\program files\blue onion software\desk drive\DeskDrive.exe uRun: [SoftAuto.exe] "c:\program files\creative\software update 3\SoftAuto.exe" uRun: [GoodSync] "c:\program files\siber systems\goodsync\GoodSync.exe" /min uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe" uRun: [CTZDetec.exe] c:\program files\creative\creative media lite\CTZDetec.exe uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [LogitechVideoRepair] c:\program files\logitech\video\ISStart.exe mRun: [LogitechVideoTray] c:\program files\logitech\video\LogiTray.exe mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup mRun: [DLSService] "c:\program files\dymo\dymo label software\DLSService.exe" mRun: [WinPatrol] c:\program files\billp studios\winpatrol\WinPatrol.exe -expressboot mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe" mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe StartupFolder: c:\docume~1\donald~1\startm~1\programs\startup\cnette~1.lnk - c:\documents and settings\donald bishop\application data\cbs interactive\cnet techtracker\TechTracker.exe StartupFolder: c:\docume~1\donald~1\startm~1\programs\startup\mozill~1.lnk - c:\program files\mozilla sunbird\sunbird.exe StartupFolder: c:\docume~1\donald~1\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe StartupFolder: c:\docume~1\donald~1\startm~1\programs\startup\yowindow.lnk - c:\program files\yowindow\yowindow.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\printk~1.lnk - c:\windows\installer\{5efa4ea3-0604-458c-a06d-485f6b2724c9}\NewShortcut2_6999F52849E742A78F6F4501EF3B5A3A.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbwebconnector\QBWebConnector.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~2.lnk - c:\program files\intuit\quickbooks enterprise solutions 11.0\QBW32.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\system~1\intuit~1.lnk - c:\program files\common files\intuit\dataprotect\IntuitDataProtect.exe uPolicies-explorer: NoResolveTrack = 1 (0x1) mPolicies-explorer: NoResolveTrack = 1 (0x1) IE: &Winamp; Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: LastPass - file://c:\program files\lastpass\context.html?cmd=lastpass IE: LastPass Fill Forms - file://c:\program files\lastpass\context.html?cmd=fillforms IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - {8C85E2EE-9FD6-11D5-B770-504D54C10000} - c:\program files\visualroute lite edition\vrie.dll IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - c:\program files\piclensie\cooliris.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {16F67783-7E72-4C39-99C4-4780A8335484} - hxxp://www.syncmyride.com/Own/Modules/UploadDownload/applets/sync.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1266388971562 DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - hxxp://mediaplayer.walmart.com/installer/install.cab DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {935F9B04-0C7B-4454-A391-348C54AD7ADD} - hxxp://www.shockwave.com/content/bigcityadventuresf/sis/JBGamePlayer.cab DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} - hxxp://www.worldwinner.com/games/v45/royal/royal.cab DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://clubgames.pogo.com/online2/pogop/bejeweled2/popcaploader_v6.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll Handler: intu-help-qb4 - {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - c:\program files\intuit\quickbooks enterprise solutions 11.0\HelpAsyncPluggableProtocol.dll Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll Notify: igfxcui - igfxdev.dll Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll Hosts: 127.0.0.1 www.spywareinfo.com ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\donald~1\applic~1\mozilla\firefox\profiles\i9q0zbvp.default\ FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig FF - prefs.js: network.proxy.http - proxy-server FF - prefs.js: network.proxy.http_port - 8080 FF - prefs.js: network.proxy.ssl - proxy-server FF - prefs.js: network.proxy.ssl_port - 8080 FF - prefs.js: network.proxy.type - 0 FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll FF - component: c:\documents and settings\donald bishop\application data\mozilla\firefox\profiles\i9q0zbvp.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll FF - component: c:\documents and settings\donald bishop\application data\mozilla\firefox\profiles\i9q0zbvp.default\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll FF - component: c:\documents and settings\donald bishop\application data\mozilla\firefox\profiles\i9q0zbvp.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll FF - component: c:\documents and settings\donald bishop\application data\mozilla\firefox\profiles\i9q0zbvp.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll FF - component: c:\program files\siber systems\ai roboform\firefox\components\rfproxy_31.dll FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\documents and settings\donald bishop\application data\mozilla\firefox\profiles\i9q0zbvp.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\documents and settings\donald bishop\application data\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\donald bishop\application data\mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll FF - plugin: c:\program files\research in motion limited\blackberry app world browser plugin\npappworld.dll FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} FF - Ext: LittleFox: {29852C08-1E91-4889-A6BF-C77F91D6A8F3} - %profile%\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3} FF - Ext: FoxyTunes: {463F6CA5-EE3C-4be1-B7E6-7FEE11953374} - %profile%\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374} FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822} FF - Ext: Adobe DLM (powered by getPlus®): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\Ext FF - Ext: Roboform Toolbar for Firefox: {22119944-ED35-4ab1-910B-E619EA06A115} - c:\program files\siber systems\ai roboform\Firefox FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff ============= SERVICES / DRIVERS =============== R0 kl1;kl1;c:\windows\system32\drivers\kl1.sys [2010-8-12 128016] R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2010-8-12 317072] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2006-12-2 528128] R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2010-10-19 724152] R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2010-10-19 724152] R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2010-3-16 26352] R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2010-3-16 493032] R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-6-30 10384] R2 QBVSS;QBIDPService;c:\program files\common files\intuit\dataprotect\QBIDPService.exe [2010-12-2 1251840] R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2010-8-24 92008] R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] R3 QuickBooksDB21;QuickBooksDB21;c:\progra~1\intuit\quickb~1.0\qbdbmgrn.exe -hvquickbooksdb21 –> c:\progra~1\intuit\quickb~1.0\QBDBMgrN.exe -hvQuickBooksDB21 [?] S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?] S2 gupdate1c9949bd8522a78;Google Update Service (gupdate1c9949bd8522a78);c:\program files\google\update\GoogleUpdate.exe [2009-2-21 133104] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-9-15 10976] S3 Media Center 15 Service;Media Center 15 Service;c:\program files\j river\media center 15\JRService.exe [2010-8-6 376832] S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2004-8-4 14336] S3 se3ebus;Sony Ericsson Device 062 (WDM);c:\windows\system32\drivers\se3ebus.sys [2007-4-10 83080] S3 se3emdfl;Sony Ericsson Device 062 USB WMC Modem Filter;c:\windows\system32\drivers\se3emdfl.sys [2007-4-10 15112] S3 se3emdm;Sony Ericsson Device 062 USB WMC Modem Driver;c:\windows\system32\drivers\se3emdm.sys [2007-4-10 108552] S3 se3emgmt;Sony Ericsson Device 062 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\se3emgmt.sys [2008-9-15 100360] S3 se3eobex;Sony Ericsson Device 062 USB WMC OBEX Interface;c:\windows\system32\drivers\se3eobex.sys [2008-9-15 98568] S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\zune\WMZuneComm.exe [2010-9-24 268528] S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2010-3-9 85504] =============== File Associations =============== JSEFile=NOTEPAD.EXE %1 regfile=NOTEPAD.EXE %1 scrfile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 =============== Created Last 30 ================ 2011-01-24 00:05:20 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-01-24 00:05:20 472808 —-a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll 2011-01-23 23:54:58 67 —-a-w- C:\Ntf4.tmp 2011-01-23 23:54:58 446 —-a-w- C:\Ntf3.tmp 2011-01-23 06:01:25 98816 —-a-w- c:\windows\sed.exe 2011-01-23 06:01:25 89088 —-a-w- c:\windows\MBR.exe 2011-01-23 06:01:25 256512 —-a-w- c:\windows\PEV.exe 2011-01-23 06:01:25 161792 —-a-w- c:\windows\SWREG.exe 2011-01-15 13:02:11 ——– d—–w- c:\docume~1\donald~1\applic~1\RoboForm 2011-01-04 01:10:25 ——– d—–w- c:\docume~1\donald~1\locals~1\applic~1\Intuit_Inc 2010-12-25 18:11:27 ——– d—–w- c:\program files\Research In Motion Limited ==================== Find3M ==================== 2011-01-24 00:04:50 472808 —-a-w- c:\windows\system32\deployJava1.dll 2010-12-20 20:14:08 364544 ——w- c:\windows\system32\MC15.exe 2010-12-07 13:08:24 684544 —-a-w- c:\windows\system32\yowindow.scr 2010-12-04 00:36:29 106496 —-a-w- c:\windows\system32\ATL71.DLL 2010-12-02 20:21:04 87688 —-a-w- c:\windows\system32\IncContxMenu.dll 2010-12-02 20:20:18 11776 —-a-w- c:\windows\system32\smrgdf.exe 2010-12-02 20:20:10 29696 —-a-w- c:\windows\system32\iolobtdfg.exe 2010-12-02 20:18:28 2234040 —-a-w- c:\windows\system32\Incinerator.dll 2010-11-29 22:38:30 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2010-11-29 22:38:30 69632 —-a-w- c:\windows\system32\QuickTime.qts 2010-11-18 18:12:44 81920 —-a-w- c:\windows\system32\isign32.dll 2010-11-09 14:52:35 249856 —-a-w- c:\windows\system32\odbc32.dll 2010-11-06 00:26:58 916480 —-a-w- c:\windows\system32\wininet.dll 2010-11-06 00:26:58 43520 —-a-w- c:\windows\system32\licmgr10.dll 2010-11-06 00:26:58 1469440 ——w- c:\windows\system32\inetcpl.cpl 2010-11-03 12:25:54 385024 —-a-w- c:\windows\system32\html.iec 2010-10-28 13:13:22 290048 —-a-w- c:\windows\system32\atmfd.dll 2010-10-26 13:25:00 1853312 —-a-w- c:\windows\system32\win32k.sys 2010-08-31 22:04:24 8134344 —-a-w- c:\program files\common files\lpuninstall.exe ============= FINISH: 19:15:27.65 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-12-12.02) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 2/17/2010 12:59:24 AM System Uptime: 1/23/2011 6:53:25 PM (1 hours ago) Motherboard: Dell Inc. | | 0PY423 Processor: Intel® Pentium® D CPU 2.80GHz | Microprocessor | 2793/800mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 149 GiB total, 80.825 GiB free. D: is CDROM () E: is FIXED (FAT32) - 466 GiB total, 430.078 GiB free. F: is Removable G: is Removable H: is Removable I: is Removable J: is Removable K: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP398: 12/27/2010 2:14:06 PM - System Checkpoint RP399: 12/28/2010 6:45:48 PM - System Checkpoint RP400: 12/29/2010 8:33:59 PM - System Checkpoint RP401: 12/30/2010 8:59:36 PM - System Checkpoint RP402: 12/31/2010 10:16:25 PM - System Checkpoint RP403: 1/2/2011 1:19:25 AM - System Checkpoint RP404: 1/3/2011 1:22:29 AM - System Checkpoint RP405: 1/4/2011 1:25:28 AM - System Checkpoint RP406: 1/5/2011 4:56:54 AM - System Checkpoint RP407: 1/5/2011 8:03:51 PM - Software Distribution Service 3.0 RP408: 1/6/2011 8:29:19 PM - System Checkpoint RP409: 1/7/2011 8:58:59 PM - System Checkpoint RP410: 1/8/2011 12:37:37 AM - Revo Uninstaller's restore point - iLike Sidebar RP411: 1/8/2011 12:38:27 AM - Removed iLike Sidebar RP412: 1/8/2011 1:11:29 AM - Revo Uninstaller's restore point - BlackBerry Desktop Software 6.0.1 RP413: 1/8/2011 1:24:39 AM - Installed BlackBerry Desktop Software 6.0.1. RP414: 1/9/2011 3:22:56 AM - System Checkpoint RP415: 1/10/2011 4:49:09 AM - System Checkpoint RP416: 1/11/2011 4:55:06 AM - System Checkpoint RP417: 1/12/2011 5:07:06 AM - System Checkpoint RP418: 1/12/2011 7:35:19 AM - Software Distribution Service 3.0 RP419: 1/12/2011 8:10:04 PM - Software Distribution Service 3.0 RP420: 1/12/2011 10:08:26 PM - Software Distribution Service 3.0 RP421: 1/12/2011 10:53:35 PM - Revo Uninstaller's restore point - McAfee Security Scan Plus RP422: 1/12/2011 10:55:17 PM - Removed Adobe Reader 9.4.1. RP423: 1/12/2011 10:57:53 PM - Installed Adobe Reader X. RP424: 1/14/2011 1:19:04 AM - System Checkpoint RP425: 1/14/2011 5:28:56 PM - Installed TurboTax 2010 wrapper RP426: 1/14/2011 5:49:15 PM - Installed TurboTax 2010 wnyiper RP427: 1/14/2011 5:49:51 PM - Installed TurboTax 2010 wneiper RP428: 1/15/2011 6:09:10 PM - System Checkpoint RP429: 1/17/2011 2:32:33 AM - System Checkpoint RP430: 1/18/2011 4:57:10 AM - System Checkpoint RP431: 1/18/2011 8:19:47 PM - Revo Uninstaller's restore point - Google Chrome RP432: 1/18/2011 11:56:07 PM - Revo Uninstaller's restore point - System Explorer 2.6.3 RP433: 1/19/2011 9:37:53 PM - Revo Uninstaller's restore point - Creative MuVo N200 Media Explorer RP434: 1/19/2011 9:38:48 PM - Configured Your Application Name RP435: 1/19/2011 9:39:34 PM - Configured Your Application Name RP436: 1/19/2011 9:45:39 PM - Revo Uninstaller's restore point - Perfect Optimizer 5.2 RP437: 1/19/2011 9:49:09 PM - Revo Uninstaller's restore point - Software Informer 1.0 BETA RP438: 1/19/2011 9:51:08 PM - Revo Uninstaller's restore point - AnswerWorks 4.0 Runtime - English RP439: 1/19/2011 9:51:39 PM - Removed AnswerWorks 4.0 Runtime - English RP440: 1/19/2011 9:59:30 PM - OTL Restore Point RP441: 1/20/2011 10:27:18 PM - System Checkpoint RP442: 1/21/2011 10:33:14 PM - System Checkpoint RP443: 1/23/2011 1:52:56 AM - System Checkpoint RP444: 1/23/2011 6:47:10 PM - Revo Uninstaller's restore point - Java™ 6 Update 21 RP445: 1/23/2011 6:47:51 PM - Removed Java™ 6 Update 11 RP446: 1/23/2011 6:49:21 PM - Revo Uninstaller's restore point - Java™ 6 Update 7 RP447: 1/23/2011 7:04:34 PM - Installed Java™ 6 Update 23 ==== Installed Programs ====================== 7-Zip 4.65 Acrobat.com Add-Remove Manager Adobe AIR Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Product/Adobe Studio Update 10/2001 Adobe Reader X Adobe Shockwave Player 11.5 AIM 7 Amazon MP3 Downloader 1.0.10 AnswerWorks 5.0 English Runtime Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft Panorama Maker 5 Audit Support Center 1.0 Bejeweled 2 Deluxe Bejeweled Blitz Bing Maps 3D BlackBerry App World Browser Plugin BlackBerry Desktop Software 6.0.1 Bonjour Broadcom Advanced Control Suite Canon MP Navigator EX 1.0 Canon MX310 series Canon MX310 series User Registration Canon My Printer Canon Utilities Easy-PhotoPrint EX Canon Utilities Solution Menu CCleaner CDBurnerXP CDDRV_Installer Chromium CleanUp! Clickster-Pro CNET TechTracker Compatibility Pack for the 2007 Office system Cooliris for Internet Explorer CP_Package_Variety1 CP_Package_Variety2 CP_Package_Variety3 Creative Media Lite Creative MediaSource Creative MuVo T200 User's Guide Creative Software Update Defraggler Dell Driver Reset Tool Desk Drive Document eSort Components Download Updater (AOL LLC) Drivers Install For Linksys Easylink Advisor DYMO Label Software DYMO Label v.8 DYMO QuickBooks Add-In ESET Online Scanner ESET Online Scanner v3 ffdshow [rev 3154] [2009-12-09] File Uploader FoxyTunes for Firefox FoxyTunes for Internet Explorer Full Tilt Poker getPlus® for Adobe Gmail POP Troubleshooter GoodSync Google Earth Google Talk Plugin Google Toolbar for Internet Explorer Google Update Helper Google Updater Google Video Uploader HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows Media Format 11 SDK (KB973442) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Intel® Graphics Media Accelerator Driver Intuit Entitlement Client iolo technologies' System Mechanic iPhone Configuration Utility iTunes Java Auto Updater Java™ 6 Update 23 KhalInstallWrapper LastPass (uninstall only) Linksys EasyLink Advisor 1.6 (0033) Logitech Print Service Logitech QuickCam Software Logitech Resource Center Logitech SetPoint Logitech® Camera Driver Mahjong Garden Deluxe Malwarebytes' Anti-Malware Mastering Intuit QuickBooks Enterprise Solutions 11.0 MCU Media Center 12 Media Center 15 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Digital Image Pro 9 Microsoft IntelliType Pro 5.3 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft National Language Support Downlevel APIs Microsoft Office 2003 Web Components Microsoft Office 2007 Primary Interop Assemblies Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher 2003 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Small Business Connectivity Components Microsoft Office Standard 2007 Microsoft Office Word MUI (English) 2007 Microsoft Outlook Personal Folders Backup Microsoft Outlook Social Connector 32-bit Microsoft Outlook Social Connector Provider for Facebook 32-bit Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual C Runtime Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual Studio 2005 Tools for Office Runtime Microsoft WinUsb 1.0 Microsoft Works 2003 Setup Launcher Microsoft Works 7.0 Mozilla Firefox (3.6.13) Mozilla Sunbird (0.9) MP3 Player Recovery Tool MP3 WAV Converter 4.13 MSN MSN Music Assistant MSN Toolbar MSXML 4.0 MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK MSXML 6 Service Pack 2 (KB973686) MuVo Driver Network Recording Player Nikon Message Center Nikon Transfer PC Matic 1.0.0.0 PC Pitstop Disk MD 2.0 PC Pitstop Optimize2 2.0 PC Tune-Up Picture Control Utility PL-2303 USB-to-Serial PowerDVD 5.9 PrintKey-Pro v1.05 QuickBooks QuickBooks Enterprise Solutions: Retail Edition 10.0 QuickBooks Enterprise Solutions: Retail Edition 11.0 Quicken 2011 QuickTime RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer RealUpgrade 1.1 Revo Uninstaller 1.91 RoboForm 7-1-6 (All Users) Safari ScanSoft OmniPage SE 4 SearchAssist Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2289158) Security Update for 2007 Microsoft Office System (KB2344875) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft Office Excel 2007 (KB2345035) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB982158) Security Update for Microsoft Office PowerPoint Viewer (KB2413381) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953155) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165-v2) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Shockwave ShortKeys 2 ShortKeys 3 Songbird 1.8.0 (Build 1800) Spelling Dictionaries Support For Adobe Reader 8 SupportSoft Assisted Service TomTom HOME 2.7.6.2056 TomTom HOME Visual Studio Merge Modules TurboTax 2009 TurboTax 2009 WinPerFedFormset TurboTax 2009 WinPerReleaseEngine TurboTax 2009 WinPerTaxSupport TurboTax 2009 wneiper TurboTax 2009 wnyiper TurboTax 2009 wrapper TurboTax 2010 TurboTax 2010 WinPerFedFormset TurboTax 2010 WinPerReleaseEngine TurboTax 2010 WinPerTaxSupport TurboTax 2010 wneiper TurboTax 2010 wnyiper TurboTax 2010 wrapper U3Launcher Unlocker 1.8.9 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office Outlook 2007 (KB2412171) Update for Outlook 2007 Junk Email Filter (KB2483110) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB978506) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update for Windows XP (KB978207) URGE VC 9.0 Runtime ViewNX Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 Visual C++ 8.0 CRT (x86) WinSXS MSM Visual Studio 2005 Tools for Office Second Edition Runtime VisualRoute Lite Edition WD Diagnostics WebEx Support Manager for Internet Explorer WebFldrs XP Winamp Winamp Detector Plug-in Winamp Remote Winamp Toolbar Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live installer Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player Firefox Plugin Windows Mobile Device Updater Component Windows XP Service Pack 3 WinPatrol Works Suite OS Pack Yahoo! Widgets YoWindow ZoneAlarm Security Suite ZoneAlarm Spy Blocker ZoneAlarm Toolbar Zune Zune Language Pack (DEU) Zune Language Pack (ESP) Zune Language Pack (FRA) Zune Language Pack (ITA) Zune Language Pack (NLD) Zune Language Pack (PTB) Zune Language Pack (PTG) Zynga Toolbar ==== Event Viewer Messages From Past Week ======== 1/23/2011 12:45:39 AM, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). 1/23/2011 12:45:39 AM, error: Service Control Manager [7034] - The Pml Driver HPZ12 service terminated unexpectedly. It has done this 1 time(s). 1/23/2011 12:45:39 AM, error: Service Control Manager [7034] - The NMSAccessU service terminated unexpectedly. It has done this 1 time(s). 1/23/2011 12:45:39 AM, error: Service Control Manager [7034] - The CT Device Query service service terminated unexpectedly. It has done this 1 time(s). 1/23/2011 12:45:39 AM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s). 1/23/2011 12:45:39 AM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s). 1/23/2011 12:45:39 AM, error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. 1/23/2011 12:45:39 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 1/23/2011 12:43:00 AM, error: Service Control Manager [7034] - The Zune Bus Enumerator service terminated unexpectedly. It has done this 3 time(s). 1/23/2011 12:42:39 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 1/23/2011 12:42:19 AM, error: Service Control Manager [7031] - The Zune Bus Enumerator service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 1/23/2011 12:42:11 AM, error: Service Control Manager [7031] - The Zune Bus Enumerator service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 1/23/2011 12:42:06 AM, error: Service Control Manager [7034] - The TomTomHOMEService service terminated unexpectedly. It has done this 1 time(s). 1/23/2011 12:41:49 AM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s). 1/23/2011 12:41:46 AM, error: Service Control Manager [7034] - The iolo System Service service terminated unexpectedly. It has done this 1 time(s). 1/23/2011 12:41:46 AM, error: Service Control Manager [7034] - The iolo FileInfoList Service service terminated unexpectedly. It has done this 1 time(s). 1/23/2011 12:41:35 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 1/23/2011 12:01:42 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Fips intelppm kl1 KLIF Lbd 1/23/2011 1:01:10 AM, error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. 1/23/2011 1:01:10 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 4 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 1/22/2011 8:30:02 PM, error: System Error [1003] - Error code 000000ca, parameter1 00000004, parameter2 8976c310, parameter3 00000000, parameter4 00000000. 1/20/2011 7:23:48 AM, error: Service Control Manager [7034] - The TrueVector Internet Monitor service terminated unexpectedly. It has done this 1 time(s). 1/19/2011 8:11:52 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Lbd 1/19/2011 8:11:40 AM, error: Service Control Manager [7023] - The Windows Media Player Network Sharing Service service terminated with the following error: An attempt was made to reference a token that does not exist. 1/19/2011 8:11:25 AM, error: WMPNetworkSvc [14329] - Service 'WMPNetworkSvc' did not start correctly because the registry could not be updated due to error '0x80070006'. If possible, reinstall Windows Media Player. 1/19/2011 8:10:16 AM, error: Print [23] - Printer WebEx Document Loader failed to initialize because a suitable PageManager PDF Writer driver could not be found. 1/18/2011 7:51:35 PM, error: Service Control Manager [7034] - The QBIDPService service terminated unexpectedly. It has done this 1 time(s). 1/18/2011 7:51:31 PM, error: Service Control Manager [7034] - The QuickBooksDB21 service terminated unexpectedly. It has done this 1 time(s). 1/18/2011 7:51:27 PM, error: Service Control Manager [7034] - The QBCFMonitorService service terminated unexpectedly. It has done this 1 time(s). 1/18/2011 7:39:39 PM, error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23). 1/18/2011 11:41:03 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 1/18/2011 11:40:03 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 1/18/2011 11:32:43 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 1/18/2011 11:31:50 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec kl1 KLIF Lbd MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip vsdatant 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The TrueVector Internet Monitor service depends on the vsdatant service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/18/2011 11:31:50 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. ==== End Of File ===========================
Hi

Please do the following:

You may need to uninstall Adaware and re-install it

just some housekeeping to do now:

You can delete the DDS and GMER logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.



Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI