This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Installer Hijacked

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I began having problems a few weeks ago when I noticed that Windows Updates I watched installing in the dialog box were not showing up as updates in Add/Remove Programs with the Show Updated box checked. I was running AVG Free 2011 and noticed it was supposedly updating but at one point no longer displayed the version or database numbers. I tried to use the Repair feature by using the Change button in Add/Remove Programs. The Window would open allowing me to select Repair and the program would start copying files then stop with an error message saying The installation failed because the MSI Installer could not be reached. I used the AVG Remover tool to uninstall AVG before trying to reinstall a fresh download of AVG Free 2011. Now I cannot install AVG at all, I keep getting an error message that says," General Internal Error: The MSI Installer could not be reached. This can happen if you are running Windows in safe mode (Which I was not). I looked into the AVG 2011 folder and saw a very unusual sight, a WMP icon showing as a DAT file. When right clicking this file and opening Properties It shows the WMP icon and says it opens with Notepad. I opened this and read through it it mentioned installing fake updates and fake scan logs. This is also a bit shocking because I had uninstalled and deleted Windows Media Player. At the first hint of problems I tried using some of the Microsoft Automated Fixes at MS Support some ran or appeared to but fixed nothing, some hung and some wouldn't run at all. I had Spybot S&D installed and ran it then the next day all the exe files were gone, shortcuts from the desktop, start menu, and the files in the Program Files folder were all changed to Unknown File Type icons and would not work. Also in there was another WMP icon DAT file that when properties was opened said it opened with Notepad. This same thing happened to my Malwarebytes. This tells me something evil is afoot. Also looking at running processes in HJT there were 25 running processes. I opened Task Manager for comparison and there were 32 processes running in Task Manager, struck me as odd that some things were hiding from HJT and not Task Manager.
Prior to this I also noticed there were some programs in Add/Remove Programs I did not want or need, such as MS Office 60 Day Free Trial, Microsoft Visual J# .NET Framework Redistributable Package 1.1. I researched the MS Visual J# and found it was a developer tool that I did not want or need. I tried to uninstall both these programs but could not. The Office program had a Remove Button, but did nothing. The MS Visual J# didn't have a Remove button and I could not locate it using Search, HJT, OTL, or Systemlook. While trying to locate this file I was looking in Control Panel>Admin Tools>Services and was researching any service that had no discription or Company Name. One of these I found was get Plus® Helper 3004. My research took me to Adobe where they said this was a part of the install files for Adobe 6.0 and should have deleted upon completion of install. They also said that if you still had this file in a NOS folder in C:\Program Files you should delete it since this had a vulnerability that can be exploited by a backdoor. I deleted the folder at C:\Program Files\NOS which contained the get Plus® Helper 3004 file, but after reboot get Plus® Helper 3004 is still running as a service. It was found by HJT and supposedly deleted with HJT, yet still remains. I was trying to remove this service with HJT and went to Services and clicked on Properties and to find the location of the file in C:\WINDOWS\System32\ but in C:\WINDOWS there was not a System32 folder only a system32 folder. While looking for the get Plus file I looked in the folder Installer, which was hidden. In there I found a Microsoft .NET folder and in there I found the Microsoft Visual J# folder with several JSharp files. After much frustration and very careful reading I downloaded ComboFix, saved it as Combo-Fix to desktop and ran a scan only. Lo and Behold the elusive jsharp files turned up for the first time. These appear to me to be malicious since the appear to self install and replace and/or block other files. I am posting the ComboFix log for your review. Thank you in advance for your time and your help. I am currently without any AV at all since I cannot install one. I would also like to get a reccomendation for a user friendly firewall since in my research I have discovered that Windows Firewall is pretty much swiss cheese. BTW, I have started getting a dialog box on boot up between the Windows black screen and my Log In box that has a 0 in the blue title bar and only a 0 in the dialog box. The only way to get past this is to click OK since the X to close does not work and there are no other buttons available.

ComboFix Log 3-2-11

ComboFix 11-03-02.01 - Owner 03/02/2011 13:33:21.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.247.140 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF


((((((((((((((((((((((((( Files Created from 2011-02-02 to 2011-03-02 )))))))))))))))))))))))))))))))
.

2011-03-01 19:55 . 2011-03-01 19:55 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData
2011-02-21 21:02 . 2011-02-21 21:02 ——– d—–w- c:\windows\system32\wbem\Repository
2011-02-21 19:35 . 2011-02-21 21:01 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-02-21 19:35 . 2011-02-21 21:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-02-18 13:33 . 2011-02-18 13:33 ——– d—–w- c:\documents and settings\Owner\My Scans
2011-02-17 13:46 . 2011-02-17 13:46 ——– d—–w- c:\documents and settings\Owner\Application Data\Template
2011-02-17 13:36 . 2011-02-21 21:01 ——– d—–w- C:\MSOffice(2)
2011-02-15 18:52 . 2011-02-15 18:52 ——– d—–w- c:\documents and settings\Owner\Application Data\ElevatedDiagnostics
2011-02-10 17:48 . 2011-02-21 21:01 ——– d—–w- c:\program files\RegScrubXP
2011-02-08 17:48 . 2011-03-01 20:20 ——– d—–w- c:\program files\Trend Micro
2011-02-07 13:37 . 2011-02-07 13:37 ——– d—–w- c:\program files\Reference Assemblies
2011-02-04 19:34 . 2011-02-04 19:34 190032 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2011-02-04 19:34 . 2011-02-04 19:34 ——– d—–w- c:\documents and settings\Owner\log

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2004-06-07 22:09 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-10 18:16 . 2011-01-10 18:17 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-01-10 18:16 . 2011-01-10 18:17 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-01-07 14:09 . 2004-06-07 22:32 290048 —-a-w- c:\windows\system32\atmfd.dll
2011-01-06 16:09 . 2011-01-06 16:09 32768 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\pchapi.dll
2011-01-06 16:09 . 2011-01-06 16:09 114688 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\ZipLib.dll
2011-01-06 16:09 . 2011-01-06 16:09 315392 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\pchmsxml.dll
2011-01-06 16:09 . 2011-01-06 16:09 26572 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\INV16.dll
2011-01-06 16:09 . 2011-01-06 16:09 3072 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\pchealthde.exe
2011-01-06 16:09 . 2011-01-06 16:09 5632 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\GUI.dll
2011-01-06 16:09 . 2011-01-06 16:09 139264 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\ContentUpdater.exe
2011-01-06 16:09 . 2011-01-06 16:09 45056 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\util.dll
2011-01-06 16:09 . 2011-01-06 16:09 24576 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\pcdapi.dll
2011-01-06 16:09 . 2011-01-06 16:09 98304 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\PluginCtrl.dll
2011-01-06 16:09 . 2011-01-06 16:09 69632 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\msxmlwrapper.dll
2011-01-06 16:09 . 2011-01-06 16:09 344064 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\api.dll
2011-01-06 16:09 . 2011-01-06 16:09 114688 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\asst_ui.dll
2011-01-06 16:08 . 2011-01-06 16:08 282624 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\clientutil52.dll
2011-01-06 16:08 . 2011-01-06 16:08 356352 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\client_motkt.dll
2011-01-06 16:08 . 2011-01-06 16:08 20480 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\InetCheckWrap.dll
2011-01-06 16:08 . 2011-01-06 16:08 49152 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\PCHI18N.dll
2011-01-06 16:08 . 2011-01-06 16:08 307200 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\pchnotify.exe
2011-01-06 16:08 . 2011-01-06 16:08 77824 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\WinVerifyTrust.dll
2011-01-06 16:08 . 2011-01-06 16:08 4096 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\winverifytrustwrapper.dll
2011-01-06 16:08 . 2011-01-06 16:08 315392 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\pchmsxml.dll
2011-01-06 16:08 . 2011-01-06 16:08 212992 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\jsharpinterp.dll
2011-01-06 16:08 . 2011-01-06 16:08 159744 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\PCHButton.exe
2011-01-06 16:08 . 2011-01-06 16:08 434176 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\motivede.dll
2011-01-06 16:08 . 2011-01-06 16:08 36864 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\gnu.dll
2011-01-06 16:08 . 2011-01-06 16:08 49152 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\hwinv.dll
2011-01-06 16:08 . 2011-01-06 16:08 126976 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\SearchCtrl.dll
2011-01-06 16:08 . 2011-01-06 16:08 77824 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\FDIWrapper.dll
2011-01-06 16:08 . 2011-01-06 16:08 69632 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\msxmlwrapper.dll
2011-01-06 16:08 . 2011-01-06 16:08 307200 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\pchealthplugin.dll
2010-12-31 13:10 . 2004-04-02 06:52 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-06-07 22:32 301568 —-a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59 . 2004-01-22 07:16 916480 —-a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59 . 2004-06-07 22:33 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59 . 2004-06-07 22:32 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26 . 2004-06-07 22:33 730112 —-a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2011-01-06 16:07 385024 —-a-w- c:\windows\system32\html.iec
2010-12-09 15:15 . 2004-04-02 06:52 718336 —-a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2004-06-07 22:32 33280 —-a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:38 . 2004-04-02 06:52 2192768 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2002-08-29 08:04 2069376 —-a-w- c:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2003-12-18 118784]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2010-09-02 1638400]
"Conime"="c:\windows\system32\conime.exe" [2008-04-14 27648]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=

S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\AiO\Center\ekdiscovery.exe [9/13/2010 5:18 PM 308656]
S2 LinksysUpdater;Linksys Updater;"c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe" -s "c:\program files\Linksys\Linksys Updater\conf\wrapper.conf" –> c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [?]
S4 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [6/7/2004 4:09 PM 14336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-02 13:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1847296987-2612838788-886327785-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3304)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\netdde.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
c:\windows\system32\wscntfy.exe
c:\windows\AGRSMMSG.exe
c:\windows\ALCXMNTR.EXE
.
**************************************************************************
.
Completion time: 2011-03-02 13:45:28 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-02 19:45

Pre-Run: 63,519,031,296 bytes free
Post-Run: 63,451,639,808 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 590401070616869110C053022084D660
:welcome:

I'm not seeing any infections.

Try this:

You can use windows sfc (system file checker) You'd need your XP CD to make this work.
Click Start> Run> type sfc /scannow Note the space.
(Note that there is a space between sfc and /scannow)
Hi, Thank you for your reply. I do not nave the XP Home disk. I would like to know how to get rid of the MS Visual J# .NET Redistributable Package 1.1. In Control Panel>Add/Remove Programs it is listed, but when highlited there is no uninstall button. This program does not turn up in search and the only way I was able to find it was in the ComboFix log. It shows up there as jsharpde in files related to the Intel processor. My research at MS indicates this is purely an optional developer program that I do not use, want or need but can't get rid of. I believe it is the cause of some of my exe files being changed such as Spybot S&D and my AVG. When I finally located it in my system32 folder under Installer there were files that opened with Notepad that were pure gibberish with widely spaced broken words and mostly symbols that are unreadable. I also want to eliminate the get Plus® Helper 3004 which is running as a service also with no option to delete because Adobe says it shouln't be there after install and if it is it has vulnerability to allow backdoor trojans which I believe has already happened. Please take another look at the ComboFix log and look for the jsharpde located in the Intel related files. Also in my D:\ drive there should only be one file with a padlock icon, right ? I have many files besides that and I do not save anything to D:. I have Fast Find Index files with the Office 2003 icons and I do not have Office 2003 installed. There was a tril version tha came with this machine but it has never been activated. Same with the WMP icons showing as DAT files. I have uninstalled WMP in Add/Remove Programs but have gotten these WMP files as DAT since uninstalling, those are the ones with the WMP icon that say they are DAT files but when you right click and go to Properties the say they open with Notepad, and do. These also contain strange symbols and some have instructions to load fake AV definitions. Any help getting rid of these two Microsoft J# . NET Redistributable Package 1.1 and get Plus ® Helper 3004 would be appreciated. As it stands right now I cannot reinstall my AVG 2011 even after running the AVG remover and downloading fresh files. I keep getting a General Internal Error message every time I try to install. Says this problem can occur if running Windows in safe mode, which I was not. This one has me stumped. Thanks in advance. TimK
I can't tell you how to remove them if I can't see them.

Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in:
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs




  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and include them in your next post.
Please include the following in your next post:
  • OTL log
Hi,

Thank you for your reply. My fault, I was not clear on what I was asking you to take a second look at. It was in the Find 3M section of the ComboFix log in the mid section. After the XPHNARS4EN\plugin\bin\ is the jsharpde file I was talking about.

2011-01-06 16:09 . 2011-01-06 16:09 32768 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\pchapi.dll
2011-01-06 16:09 . 2011-01-06 16:09 114688 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\ZipLib.dll
2011-01-06 16:09 . 2011-01-06 16:09 315392 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\pchmsxml.dll
2011-01-06 16:09 . 2011-01-06 16:09 26572 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\INV16.dll
2011-01-06 16:09 . 2011-01-06 16:09 3072 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\pchealthde.exe
2011-01-06 16:09 . 2011-01-06 16:09 5632 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\GUI.dll
2011-01-06 16:09 . 2011-01-06 16:09 139264 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\ContentUpdater.exe
2011-01-06 16:09 . 2011-01-06 16:09 45056 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\util.dll
2011-01-06 16:09 . 2011-01-06 16:09 24576 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\pcdapi.dll
2011-01-06 16:09 . 2011-01-06 16:09 98304 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\PluginCtrl.dll
2011-01-06 16:09 . 2011-01-06 16:09 69632 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\msxmlwrapper.dll
2011-01-06 16:09 . 2011-01-06 16:09 344064 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\api.dll
2011-01-06 16:09 . 2011-01-06 16:09 114688 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\asst_ui.dll
2011-01-06 16:08 . 2011-01-06 16:08 282624 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\clientutil52.dll
2011-01-06 16:08 . 2011-01-06 16:08 356352 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\client_motkt.dll
2011-01-06 16:08 . 2011-01-06 16:08 20480 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\InetCheckWrap.dll
2011-01-06 16:08 . 2011-01-06 16:08 49152 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\PCHI18N.dll
2011-01-06 16:08 . 2011-01-06 16:08 307200 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\pchnotify.exe
2011-01-06 16:08 . 2011-01-06 16:08 77824 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\WinVerifyTrust.dll
2011-01-06 16:08 . 2011-01-06 16:08 4096 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\winverifytrustwrapper.dll
2011-01-06 16:08 . 2011-01-06 16:08 315392 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\pchmsxml.dll
2011-01-06 16:08 . 2011-01-06 16:08 212992 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\jsharpinterp.dll
2011-01-06 16:08 . 2011-01-06 16:08 159744 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\PCHButton.exe
2011-01-06 16:08 . 2011-01-06 16:08 434176 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\motivede.dll
2011-01-06 16:08 . 2011-01-06 16:08 36864 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\gnu.dll
2011-01-06 16:08 . 2011-01-06 16:08 49152 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\hwinv.dll
2011-01-06 16:08 . 2011-01-06 16:08 126976 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\SearchCtrl.dll
2011-01-06 16:08 . 2011-01-06 16:08 77824 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\FDIWrapper.dll
2011-01-06 16:08 . 2011-01-06 16:08 69632 —-a-w- c:\windows\pchealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\jsharpde\msxmlwrapper.dll

I ran the OTL as instructed and here are the logs.

OTL.txt Log

OTL logfile created on: 3/7/2011 2:17:49 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

247.00 Mb Total Physical Memory | 158.00 Mb Available Physical Memory | 64.00% Memory free
641.00 Mb Paging File | 442.00 Mb Available in Paging File | 69.00% Paging File free
Paging file location(s): C:\pagefile.sys 372 744 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.44 Gb Total Space | 58.98 Gb Free Space | 83.73% Space Free | Partition Type: NTFS
Drive D: | 4.07 Gb Total Space | 0.67 Gb Free Space | 16.47% Space Free | Partition Type: FAT32

Computer Name: GOODRICH106 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (nosGetPlusHelper) getPlus® – File not found
SRV - (nmservice) – File not found
SRV - (LinksysUpdater) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (Kodak AiO Network Discovery Service) – C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe (Eastman Kodak Company)


========== Driver Services (SafeList) ==========

DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (SiSkp) – C:\WINDOWS\system32\drivers\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (SiS315) – C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura Ltd)
DRV - (fasttx2k) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (SISAGP) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2011/03/02 13:41:15 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe (SoftThinks)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10m_ActiveX.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/02 02:03:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/07 14:13:46 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/03/07 08:42:10 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/03/02 13:32:17 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/03/02 13:30:01 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/03/02 13:30:01 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/03/02 13:30:01 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/03/02 13:30:01 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/03/02 13:27:34 | 000,000,000 | —D | C] – C:\Qoobox
[2011/03/01 13:55:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/02/28 10:20:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\erunt
[2011/02/25 10:35:34 | 154,871,128 | —- | C] (AVG Technologies) – C:\Documents and Settings\Owner\Desktop\avg_free_x86_all_2011_1204a3402.exe
[2011/02/23 13:41:38 | 007,734,240 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mwbam-setup.exe
[2011/02/22 15:09:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Candy
[2011/02/22 14:00:50 | 004,738,880 | —- | C] (AVG Technologies) – C:\Documents and Settings\Owner\My Documents\avg_free_stb_all_2011_1204_cnet.exe
[2011/02/21 13:35:12 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/02/21 13:35:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/02/21 13:15:15 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Owner\My Documents\spybotsd162.exe
[2011/02/21 11:40:19 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/02/21 11:34:24 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Owner\My Documents\erunt-setup.exe
[2011/02/18 07:33:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Scans
[2011/02/17 11:08:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Forklift Checklists
[2011/02/17 07:46:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Template
[2011/02/17 07:36:18 | 000,000,000 | —D | C] – C:\MSOffice(2)
[2011/02/16 12:20:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Shipping Notices
[2011/02/16 12:18:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Repairs Received
[2011/02/16 12:13:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\AEI TAG P.O.s
[2011/02/15 12:52:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2011/02/15 12:40:24 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2011/02/11 14:41:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\RootkitRevealer
[2011/02/11 14:22:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\backups
[2011/02/10 14:06:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\vmmap
[2011/02/10 11:48:47 | 000,000,000 | —D | C] – C:\Program Files\RegScrubXP
[2011/02/10 11:48:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\RegScrubXP
[2011/02/10 10:17:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Browser Guard 2010
[2011/02/08 11:48:05 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/02/07 07:37:46 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2011/02/07 07:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG PC Tuneup 2011

========== Files - Modified Within 30 Days ==========

[2011/03/07 14:13:50 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/03/03 03:17:21 | 259,575,808 | -HS- | M] () – C:\hiberfil.sys
[2011/03/02 13:41:15 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/03/02 13:32:22 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/03/02 13:29:19 | 004,279,013 | R— | M] () – C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe
[2011/03/02 09:41:25 | 000,000,281 | —- | M] () – C:\Boot.bak
[2011/03/01 15:19:50 | 000,305,152 | —- | M] () – C:\Documents and Settings\Owner\My Documents\windiag.iso
[2011/03/01 15:13:46 | 000,027,106 | —- | M] () – C:\Documents and Settings\Owner\My Documents\AVGInstLog.cab
[2011/03/01 14:09:10 | 001,023,540 | —- | M] () – C:\Documents and Settings\Owner\My Documents\msinfo.nfo
[2011/03/01 14:08:06 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/01 11:22:32 | 000,133,632 | —- | M] () – C:\Documents and Settings\Owner\Desktop\RKUnhookerLE.EXE
[2011/03/01 10:00:50 | 000,146,808 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/28 10:19:36 | 000,513,320 | —- | M] () – C:\Documents and Settings\Owner\Desktop\erunt.zip
[2011/02/25 10:36:06 | 154,871,128 | —- | M] (AVG Technologies) – C:\Documents and Settings\Owner\Desktop\avg_free_x86_all_2011_1204a3402.exe
[2011/02/25 08:09:47 | 000,000,047 | —- | M] () – C:\Documents and Settings\Owner\My Documents\fixes.bat
[2011/02/23 13:41:38 | 007,734,240 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mwbam-setup.exe
[2011/02/22 14:00:50 | 004,738,880 | —- | M] (AVG Technologies) – C:\Documents and Settings\Owner\My Documents\avg_free_stb_all_2011_1204_cnet.exe
[2011/02/22 13:45:20 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/21 14:17:58 | 001,171,456 | -H– | M] () – C:\__ofidx0.ffx
[2011/02/21 14:17:58 | 000,180,224 | -H– | M] () – C:\__ofidx.ffl
[2011/02/21 14:17:58 | 000,004,713 | -H– | M] () – C:\__ofidx.ffa
[2011/02/21 13:15:15 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Owner\My Documents\spybotsd162.exe
[2011/02/21 11:34:32 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Owner\My Documents\erunt-setup.exe
[2011/02/18 11:17:08 | 000,009,830 | —- | M] () – C:\Documents and Settings\Owner\My Documents\exefix.reg
[2011/02/11 11:14:18 | 000,000,041 | —- | M] () – C:\Documents and Settings\Owner\WellKnownServers.xml
[2011/02/10 13:00:55 | 000,443,304 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/10 13:00:55 | 000,072,142 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/10 11:48:48 | 000,000,658 | —- | M] () – C:\Documents and Settings\Owner\Desktop\RegScrubXP.lnk
[2011/02/10 11:47:16 | 000,593,556 | —- | M] () – C:\Documents and Settings\Owner\My Documents\regscrubxpsetup_3.2.exe
[2011/02/10 11:22:17 | 000,654,920 | —- | M] () – C:\Documents and Settings\Owner\My Documents\mtinst.exe
[2011/02/10 11:17:37 | 000,032,078 | —- | M] () – C:\Documents and Settings\Owner\My Documents\RogueChecker.zip
[2011/02/10 11:14:21 | 000,231,390 | —- | M] () – C:\Documents and Settings\Owner\My Documents\RootkitRevealer.zip
[2011/02/10 11:13:20 | 000,554,035 | —- | M] () – C:\Documents and Settings\Owner\My Documents\vmmap.zip
[2011/02/10 11:11:02 | 000,430,080 | —- | M] () – C:\Documents and Settings\Owner\My Documents\UPHClean-Setup.msi
[2011/02/09 08:57:00 | 004,337,573 | —- | M] () – C:\Documents and Settings\Owner\My Documents\u10iavi3432sq.bin
[2011/02/09 08:54:23 | 000,140,288 | —- | M] () – C:\Documents and Settings\Owner\My Documents\vcleaner.exe
[2011/02/08 11:48:51 | 000,000,073 | —- | M] () – C:\WINDOWS\System32\-1
[2011/02/07 07:33:40 | 000,000,856 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2011/02/07 07:33:40 | 000,000,838 | —- | M] () – C:\Documents and Settings\Owner\Desktop\AVG PC Tuneup 2011.lnk
[2011/02/07 07:31:50 | 007,592,248 | —- | M] (AVG ) – C:\Documents and Settings\Owner\My Documents\avg_pct_stf_all_2011_24_c5.exe

========== Files Created - No Company Name ==========

[2011/03/02 13:30:01 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/03/02 13:30:01 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/03/02 13:30:01 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/03/02 13:30:01 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/03/02 13:30:01 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/03/02 13:23:18 | 004,279,013 | R— | C] () – C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe
[2011/03/01 15:13:46 | 000,027,106 | —- | C] () – C:\Documents and Settings\Owner\My Documents\AVGInstLog.cab
[2011/03/01 14:08:05 | 001,023,540 | —- | C] () – C:\Documents and Settings\Owner\My Documents\msinfo.nfo
[2011/03/01 11:22:32 | 000,133,632 | —- | C] () – C:\Documents and Settings\Owner\Desktop\RKUnhookerLE.EXE
[2011/02/28 10:19:32 | 000,513,320 | —- | C] () – C:\Documents and Settings\Owner\Desktop\erunt.zip
[2011/02/25 08:09:47 | 000,000,047 | —- | C] () – C:\Documents and Settings\Owner\My Documents\fixes.bat
[2011/02/21 14:17:58 | 000,004,713 | -H– | C] () – C:\__ofidx.ffa
[2011/02/21 14:17:54 | 001,171,456 | -H– | C] () – C:\__ofidx0.ffx
[2011/02/21 14:13:24 | 000,180,224 | -H– | C] () – C:\__ofidx.ffl
[2011/02/18 11:17:07 | 000,009,830 | —- | C] () – C:\Documents and Settings\Owner\My Documents\exefix.reg
[2011/02/11 11:13:22 | 000,000,041 | —- | C] () – C:\Documents and Settings\Owner\WellKnownServers.xml
[2011/02/10 14:13:21 | 000,305,152 | —- | C] () – C:\Documents and Settings\Owner\My Documents\windiag.iso
[2011/02/10 11:48:48 | 000,000,658 | —- | C] () – C:\Documents and Settings\Owner\Desktop\RegScrubXP.lnk
[2011/02/10 11:47:09 | 000,593,556 | —- | C] () – C:\Documents and Settings\Owner\My Documents\regscrubxpsetup_3.2.exe
[2011/02/10 11:22:11 | 000,654,920 | —- | C] () – C:\Documents and Settings\Owner\My Documents\mtinst.exe
[2011/02/10 11:17:37 | 000,032,078 | —- | C] () – C:\Documents and Settings\Owner\My Documents\RogueChecker.zip
[2011/02/10 11:14:18 | 000,231,390 | —- | C] () – C:\Documents and Settings\Owner\My Documents\RootkitRevealer.zip
[2011/02/10 11:13:14 | 000,554,035 | —- | C] () – C:\Documents and Settings\Owner\My Documents\vmmap.zip
[2011/02/10 11:10:58 | 000,430,080 | —- | C] () – C:\Documents and Settings\Owner\My Documents\UPHClean-Setup.msi
[2011/02/09 08:56:59 | 004,337,573 | —- | C] () – C:\Documents and Settings\Owner\My Documents\u10iavi3432sq.bin
[2011/02/09 08:54:18 | 000,140,288 | —- | C] () – C:\Documents and Settings\Owner\My Documents\vcleaner.exe
[2011/02/08 11:48:50 | 000,000,073 | —- | C] () – C:\WINDOWS\System32\-1
[2011/02/07 07:33:40 | 000,000,856 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2011/02/07 07:33:40 | 000,000,838 | —- | C] () – C:\Documents and Settings\Owner\Desktop\AVG PC Tuneup 2011.lnk
[2011/01/13 12:30:26 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/07 12:29:17 | 000,000,036 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\housecall.guid.cache
[2006/12/31 07:57:08 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/06/07 16:33:40 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/06/07 16:33:39 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/06/07 16:32:41 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/06/07 16:32:21 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/06/07 16:08:53 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/06/07 16:08:53 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/06/07 16:08:50 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/06/07 16:08:45 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/06/07 16:08:41 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/04/03 02:18:54 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/04/03 01:36:40 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\VGAunistlog.ini
[2004/04/03 01:36:39 | 000,000,451 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2004/04/02 18:17:14 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2004/04/02 18:15:40 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2004/04/02 18:00:40 | 000,027,752 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/04/02 04:01:01 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/04/02 03:52:33 | 000,000,889 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004/04/02 03:14:52 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/04/02 03:08:00 | 000,001,040 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2004/04/02 03:04:11 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\sis760.bin
[2004/04/02 03:04:11 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\sis741.bin
[2004/04/02 03:04:11 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\sis660.bin
[2004/04/02 02:43:52 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/04/02 02:34:53 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/04/02 02:34:53 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/04/02 02:34:35 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/04/02 02:08:11 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/04/02 02:01:37 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/04/02 00:52:53 | 000,000,553 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/04/02 00:52:18 | 000,443,304 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/04/02 00:52:18 | 000,072,142 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/04/01 17:57:08 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/04/01 17:56:18 | 000,146,808 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2003/01/08 00:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2011/01/14 14:24:45 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/03/01 13:55:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/02/21 15:08:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/02/04 11:51:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG
[2011/02/15 12:52:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2004/04/02 19:28:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2011/03/07 08:24:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Temp
[2011/02/17 07:46:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/04/02 02:03:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/03/02 09:41:25 | 000,000,281 | —- | M] () – C:\Boot.bak
[2011/03/02 13:32:22 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/02/11 22:25:00 | 000,245,920 | RHS- | M] () – C:\cmldr
[2011/03/02 13:45:29 | 000,013,409 | —- | M] () – C:\ComboFix.txt
[2004/04/02 02:03:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/03/03 03:17:21 | 259,575,808 | -HS- | M] () – C:\hiberfil.sys
[2004/04/02 02:03:32 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2004/04/02 02:03:32 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/01/06 10:03:20 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/01/06 10:03:20 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/03/03 13:13:21 | 426,770,432 | -HS- | M] () – C:\pagefile.sys
[2011/02/21 14:17:58 | 000,004,713 | -H– | M] () – C:\__ofidx.ffa
[2011/02/21 14:17:58 | 000,180,224 | -H– | M] () – C:\__ofidx.ffl
[2011/02/21 14:17:58 | 001,171,456 | -H– | M] () – C:\__ofidx0.ffx

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/04/02 02:03:09 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/09/02 08:17:50 | 000,196,608 | —- | M] (Eastman Kodak Company) – C:\WINDOWS\system32\spool\prtprocs\w32x86\EKIJ5000PPR.dll
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/06/19 02:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/04/01 17:55:44 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/04/01 17:55:44 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/04/01 17:55:44 | 000,393,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/01/06 10:08:14 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2004/04/02 02:31:02 | 000,014,727 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\ml1.srt
[2004/04/02 02:31:02 | 000,014,785 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\ml2.srt
[2004/04/02 02:31:02 | 000,003,568 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\tempdiff.txt

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/01/06 10:18:49 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/04/02 02:07:58 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/02/23 13:37:01 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF-Cleaner.exe
[2011/01/28 09:57:15 | 002,132,576 | —- | M] (AVG Technologies) – C:\Documents and Settings\Owner\Desktop\AVGIDPUninstaller.exe
[2011/02/04 13:41:54 | 004,738,880 | —- | M] (AVG Technologies) – C:\Documents and Settings\Owner\Desktop\avg_free_stb_all_2011_1204_cnet.exe
[2011/02/25 10:36:06 | 154,871,128 | —- | M] (AVG Technologies) – C:\Documents and Settings\Owner\Desktop\avg_free_x86_all_2011_1204a3402.exe
[2011/01/28 09:55:56 | 001,090,912 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Documents and Settings\Owner\Desktop\avg_remover_stf_x86_2011_1184.exe
[2011/03/02 13:29:19 | 004,279,013 | R— | M] () – C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe
[2011/02/04 13:43:31 | 000,532,480 | —- | M] (Trend Micro Incorporated) – C:\Documents and Settings\Owner\Desktop\cwshredder.exe
[2011/02/23 13:41:38 | 007,734,240 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mwbam-setup.exe
[2011/03/07 14:13:50 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/03/01 11:22:32 | 000,133,632 | —- | M] () – C:\Documents and Settings\Owner\Desktop\RKUnhookerLE.EXE
[2011/02/04 13:45:05 | 006,018,568 | —- | M] (Trend Micro, Inc. ) – C:\Documents and Settings\Owner\Desktop\RUBottedSetup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >
[2011/01/14 09:46:58 | 014,662,096 | —- | M] (Eastman Kodak Company) – C:\Documents and Settings\Owner\My Documents\aio_install.exe
[2011/01/12 12:40:20 | 004,622,344 | —- | M] (AVG Technologies) – C:\Documents and Settings\Owner\My Documents\avg_free_stb_all_2011_1191_cnet.exe
[2011/02/22 14:00:50 | 004,738,880 | —- | M] (AVG Technologies) – C:\Documents and Settings\Owner\My Documents\avg_free_stb_all_2011_1204_cnet.exe
[2011/02/07 07:31:50 | 007,592,248 | —- | M] (AVG ) – C:\Documents and Settings\Owner\My Documents\avg_pct_stf_all_2011_24_c5.exe
[2011/01/12 12:27:48 | 001,090,912 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Documents and Settings\Owner\My Documents\avg_remover_stf_x86_2011_1184.exe
[2011/02/10 11:20:55 | 000,122,152 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\My Documents\doomcln-kb836528-v4-enu.exe
[2011/02/21 11:34:32 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Owner\My Documents\erunt-setup.exe
[2010/01/20 08:26:54 | 000,401,720 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\My Documents\HijackThis.exe
[2011/01/10 12:13:35 | 000,883,488 | —- | M] (Sun Microsystems, Inc.) – C:\Documents and Settings\Owner\My Documents\JavaSetup6u23.exe
[2010/12/20 00:52:42 | 006,220,168 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\My Documents\mbam-rules.exe
[2009/03/14 20:27:04 | 002,876,728 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\My Documents\mbam-setup.exe
[2011/02/10 11:09:08 | 000,359,656 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\My Documents\msicuu2.exe
[2011/02/10 11:22:17 | 000,654,920 | —- | M] () – C:\Documents and Settings\Owner\My Documents\mtinst.exe
[2011/02/10 11:47:16 | 000,593,556 | —- | M] () – C:\Documents and Settings\Owner\My Documents\regscrubxpsetup_3.2.exe
[2011/02/21 13:15:15 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Owner\My Documents\spybotsd162.exe
[2011/02/09 08:54:23 | 000,140,288 | —- | M] () – C:\Documents and Settings\Owner\My Documents\vcleaner.exe
[2011/02/10 11:23:44 | 000,115,960 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\My Documents\windows-kb841720-enu-v4.exe

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2011/01/06 10:18:49 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Owner\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/03/07 14:07:04 | 000,049,152 | -HS- | M] () – C:\Documents and Settings\Owner\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-03 09:01:10

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >

Extras.txt Log

OTL Extras logfile created on: 3/7/2011 2:17:49 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

247.00 Mb Total Physical Memory | 158.00 Mb Available Physical Memory | 64.00% Memory free
641.00 Mb Paging File | 442.00 Mb Available in Paging File | 69.00% Paging File free
Paging file location(s): C:\pagefile.sys 372 744 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.44 Gb Total Space | 58.98 Gb Free Space | 83.73% Space Free | Partition Type: NTFS
Drive D: | 4.07 Gb Total Space | 0.67 Gb Free Space | 16.47% Space Free | Partition Type: FAT32

Computer Name: GOODRICH106 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 23
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}" = Microsoft Plus! Digital Media Edition
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DE6B7599-D3EF-4436-8836-BAA0B0D7768D}" = aiofw
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Home Center
"{FBDBC490-089D-4476-BF72-1F7A6368200A}" = Pure Networks Platform
"{FE24086F-3B0C-4C47-A874-97A7B8E2FBBE}" = aioscnnr
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"Compaq Instant Support" = Compaq Instant Support
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"RegScrubXP_is1" = RegScrubXP 3.25
"Windows XP Service Pack" = Windows XP Service Pack 3
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/25/2011 12:56:05 PM | Computer Name = GOODRICH106 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/1/2011 9:16:23 AM | Computer Name = GOODRICH106 | Source = MsiInstaller | ID = 11719
Description = SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2011 – Error
1719. SA_Error1719: StandardAction(0xC00706B7): The Windows Installer Service could
not be accessed. This can occur if you are running Windows in safe mode, or if
the Windows Installer is not correctly installed. Contact your support personnel
for assistance.

Error - 3/1/2011 3:56:44 PM | Computer Name = GOODRICH106 | Source = MsiInstaller | ID = 11719
Description = SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2011 – Error
1719. SA_Error1719: StandardAction(0xC00706B7): The Windows Installer Service could
not be accessed. This can occur if you are running Windows in safe mode, or if
the Windows Installer is not correctly installed. Contact your support personnel
for assistance.

Error - 3/1/2011 4:33:51 PM | Computer Name = GOODRICH106 | Source = MsiInstaller | ID = 11719
Description = SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2011 – Error
1719. SA_Error1719: StandardAction(0xC00706B7): The Windows Installer Service could
not be accessed. This can occur if you are running Windows in safe mode, or if
the Windows Installer is not correctly installed. Contact your support personnel
for assistance.

Error - 3/1/2011 5:12:56 PM | Computer Name = GOODRICH106 | Source = MsiInstaller | ID = 11719
Description = SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2011 – Error
1719. SA_Error1719: StandardAction(0xC00706B7): The Windows Installer Service could
not be accessed. This can occur if you are running Windows in safe mode, or if
the Windows Installer is not correctly installed. Contact your support personnel
for assistance.

Error - 3/1/2011 5:16:57 PM | Computer Name = GOODRICH106 | Source = MsiInstaller | ID = 11719
Description = SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2011 – Error
1719. SA_Error1719: StandardAction(0xC00706B7): The Windows Installer Service could
not be accessed. This can occur if you are running Windows in safe mode, or if
the Windows Installer is not correctly installed. Contact your support personnel
for assistance.

Error - 3/2/2011 11:45:34 AM | Computer Name = GOODRICH106 | Source = MsiInstaller | ID = 11719
Description = SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2011 – Error
1719. SA_Error1719: StandardAction(0xC00706B7): The Windows Installer Service could
not be accessed. This can occur if you are running Windows in safe mode, or if
the Windows Installer is not correctly installed. Contact your support personnel
for assistance.

Error - 3/2/2011 1:56:50 PM | Computer Name = GOODRICH106 | Source = Application Hang | ID = 1002
Description = Hanging application notepad.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/3/2011 3:13:01 PM | Computer Name = GOODRICH106 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/3/2011 3:13:32 PM | Computer Name = GOODRICH106 | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

[ System Events ]
Error - 1/12/2011 12:21:52 PM | Computer Name = GOODRICH106 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.MFC. Reference error
message: The referenced assembly is not installed on your system. .

Error - 1/12/2011 12:21:52 PM | Computer Name = GOODRICH106 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\AVG\AVG10\avgse.dll.
Reference
error message: The operation completed successfully. .

Error - 1/12/2011 12:53:31 PM | Computer Name = GOODRICH106 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC90.MFC could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 1/12/2011 12:53:31 PM | Computer Name = GOODRICH106 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.MFC. Reference error
message: The referenced assembly is not installed on your system. .

Error - 1/12/2011 12:53:31 PM | Computer Name = GOODRICH106 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\AVG\AVG10\avgabout.dll.
Reference
error message: The operation completed successfully. .

Error - 1/12/2011 1:10:03 PM | Computer Name = GOODRICH106 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC90.MFC could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 1/12/2011 1:10:04 PM | Computer Name = GOODRICH106 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.MFC. Reference error
message: The referenced assembly is not installed on your system. .

Error - 1/12/2011 1:10:04 PM | Computer Name = GOODRICH106 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\AVG\AVG10\avgtray.exe.
Reference
error message: The operation completed successfully. .

Error - 1/12/2011 1:16:55 PM | Computer Name = GOODRICH106 | Source = Service Control Manager | ID = 7031
Description = The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 0 milliseconds: Restart the service.

Error - 1/12/2011 1:17:02 PM | Computer Name = GOODRICH106 | Source = Service Control Manager | ID = 7034
Description = The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated
unexpectedly. It has done this 2 time(s).


< End of report >

BTW as I am typing this it is only showing one letter about every second and the hourglass cursor is flashing with each letter.

Thank You
XPHNARS4EN\plugin\bin That came installed with your Compaq Presario computer Do you know what this is? C:\Documents and Settings\Owner\My Documents\fixes.bat You need to run Windows updates. You also need Windows NET Framework so get that when you run Windows Updates
Hi Again, I tried to get updates but it didn't work. The first thing that tried to install was Windows Genuine Advantage Validation Tool. This appeared to download and install successfully. Then it searched my computer for updates and all it came up with were three updates for Office 2003. Office 2003 Update KB907417, Office 2003 SP 3 no KB #, and Office 2003 Outlook Junk Mail Filter KB2492441. After the installer box completed and said all updated installed successfully I looked at my Update History. This showed that the three updates failed to install and that WGA was "Remaining" I could not get the installation for WGA to proceed. I also could not view my Hidden Installations. I have had problems with updates showing they installed successfully in the dialog box, but when looking in Control Panel >Add/Remove Programs with Show Updates checked the updates that were supposed to have installed successfully were not there. If it is any help I have had problems trying to run MS Automated Fixes some just will not run that are supposed to support XP. I tried to install NET Framework but could not find it. According to Add/Remove Programs I have numerous versions of NET Framework installed 1.1, 2.0, 3.0 SP2, 3.5 SP1. Do I need to get rid of the older versions first ? To answer your questions, XPHNARS4EN\plugin\bin That came installed with your Compaq Presario computer - I understand that, I am concerned about the ones that have \jsharpde\ after the \bin Do you know what this is? C:\Documents and Settings\Owner\My Documents\fixes.bat - This is a fix that was tried at the Safer Networking Forum. I was pronounced clean by them but still could not install my AVG, so I came here to try and find the problem. It can be deleted if need be. You need to run Windows updates. You also need Windows NET Framework so get that when you run Windows Updates - These issues were adressed above. I am awaiting further instruction. When I tried to search MS for NET Framework I was taken to what looked like a Google results page, though no mention of Google, it was a list of web sites. Thanks Again, Tim K
Contact MS and tell them the issues you're having getting updates.

Issues with getting Windows Updates.

This is a free service and toll-free call.

1-866-PCSAFETY
or
[removed]
It is available 24 hours a day for the U.S. and Canada.

For support outside the United States and Canada, please contact your Microsoft Help and Support worldwide. Go to this page and choose your region from the box in the upper right corner: http://support.microsoft.com/?pr=SecurityHome
Hi LD, I called the number you sent and the recorded message said to run the One Care scan, which I did. It found 2 problems and 1 issue. I then went to MS update and tried updating. The same 3 Office updates failed but 2 other Windows updates appear to have installed. They said the installed successfully in the dialog box and 2 updates with todays date are in Add/Remove Programs. I also found and installed .NET Framework 4 which seems to have successfully installed. Ready for the next step. Things seem to have sped up a bit even before these updates/installs. Thanks, Tim K
I don't have any other answers for those issues. I always skip th eoffice updates myself because they have always failed when I try them as well. You can start a new topic in our Windows Forum and see if the Tech Team has any suggestions.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI