This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ms removal tool

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I picked up this little gem today.

I googled it and found some removal instructions and followed the instructions. http://www.bleepingcomputer.com/virus-remo…ms-removal-tool

This failed to remove the malware.

I probably should have just come here, but was hoping that the process would remove the problem.

The malware keeps trying to get me to purchase their software and keeps telling me that I have all these infections that dont really exist.


Im hopin that you folks could help :blush:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:27:36 PM, on 4/7/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19019)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\RunOnce: [jGk06511aKeNd06511] C:\ProgramData\jGk06511aKeNd06511\jGk06511aKeNd06511.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: SentriLockCardUtility.lnk = ?
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll C:\Windows\System32\avgrsstx.dll C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Unknown owner - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxbl_device - - C:\Windows\system32\lxblcoms.exe
O23 - Service: MyOwnSuperhero Service (MyOwnSuperheroService) - MyOwnSuperhero - C:\PROGRA~1\MYOWNS~2\bar\1.bin\v3barsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 8735 bytes
that is actually a logfile from version 2.0.2 of hijack this. It wont let me run the new version in safe mode and when I go back to regular mode it won't let me update to version 2.04. This thing is starting to pyss me off. lol
Ok was finally able to run malwarebytes in safe mode and it appeared to remove ms tools removal. I also was able to download hijack this version 2.0.4

here is the hijack this log

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:42:35 AM, on 4/8/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19019)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\SpiralFrog\Spiralfrog.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\ehome\ehmsas.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: SentriLockCardUtility.lnk = ?
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll C:\Windows\System32\avgrsstx.dll C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Unknown owner - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxbl_device - - C:\Windows\system32\lxblcoms.exe
O23 - Service: MyOwnSuperhero Service (MyOwnSuperheroService) - MyOwnSuperhero - C:\PROGRA~1\MYOWNS~2\bar\1.bin\v3barsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 9844 bytes
:welcome:

Just so you know , our helpers look for logs with zero replies to work, by replying to your self so many times it made it look like you where already being helped

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.





You already have Malwarebytes installed, check for updates and run the quick scan and post the log

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please






OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Thanks so much for your help. I just figured you guys were busy. here's the mbam log Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6318 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19019 4/9/2011 4:30:25 AM mbam-log-2011-04-09 (04-30-25).txt Scan type: Quick scan Objects scanned: 190498 Time elapsed: 6 minute(s), 53 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: c:\Users\Mike\AppData\Local\PNKBDFE.dll (Trojan.Hiloti) -> Delete on reboot. Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Qyixahe (Trojan.Hiloti) -> Value: Qyixahe -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Users\Mike\AppData\Local\PNKBDFE.dll (Trojan.Hiloti) -> Delete on reboot. c:\Users\Mike\local settings\application data\PNKBDFE.dll (Trojan.Hiloti) -> Delete on reboot.
here's the otl scan

OTL logfile created on: 4/9/2011 4:39:49 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Mike\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.97 Gb Total Space | 99.05 Gb Free Space | 71.27% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.89 Gb Free Space | 58.88% Space Free | Partition Type: NTFS
Drive E: | 1.05 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: DELL | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mike\Desktop\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\MyOwnSuperhero\bar\1.bin\v3barsvc.exe (MyOwnSuperhero)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
PRC - C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe (SentriLock LLC)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\lxblcoms.exe ( )
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\Mike\Desktop\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)


========== Win32 Services (SafeList) ==========

SRV - (GoogleDesktopManager-110309-193829) – File not found
SRV - (MyOwnSuperheroService) – C:\Program Files\MyOwnSuperhero\bar\1.bin\v3barsvc.exe (MyOwnSuperhero)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – C:\Windows\System32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (lxbl_device) – C:\Windows\System32\lxblcoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (SCR3XX2K) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (SCR3xx USB Smart Card Reader) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (BVRPMPR5) – C:\Windows\System32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (datunidr) – C:\Windows\System32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
IE - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
IE - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/21 10:34:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyOwnSuperhero\bar\1.bin [2011/02/27 21:53:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 09:52:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/08 09:13:37 | 000,000,000 | —D | M]

[2008/08/30 07:19:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Extensions
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions
[2009/09/17 19:00:57 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/09/22 07:48:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2009/09/22 07:48:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2008/10/29 13:48:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/08/20 17:00:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008/01/24 21:59:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2009/01/13 21:39:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/02/17 09:58:45 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2009/08/20 17:08:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\staged-xpis
[2010/11/30 11:40:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2008/12/17 22:57:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/01/26 22:31:08 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/20 21:16:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/28 06:42:36 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/26 22:31:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/04/26 19:09:24 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2008/10/29 13:52:34 | 000,057,240 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000..\Run: [Qyixahe] File not found
O4 - Startup: C:\Users\adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O4 - Startup: C:\Users\Jake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\Windows\System32\avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O24 - Desktop WallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{8aba361e-8e76-11df-a874-001d097cf64b}\Shell - "" = AutoRun
O33 - MountPoints2\{8aba361e-8e76-11df-a874-001d097cf64b}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/08 08:36:05 | 000,000,000 | —D | C] – C:\ProgramData\HP Product Assistant
[2011/04/08 08:34:53 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/04/07 07:55:32 | 000,000,000 | —D | C] – C:\ProgramData\jGk06511aKeNd06511
[2011/03/31 18:19:12 | 000,000,000 | —D | C] – C:\Users\Mike\Documents\walmart pics
[2011/03/25 06:17:23 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\HpUpdate
[2011/03/25 06:17:20 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2011/03/22 12:53:11 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/22 12:53:11 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2008/01/30 23:27:17 | 000,995,328 | —- | C] ( ) – C:\Windows\System32\lxblusb1.dll
[2008/01/30 23:27:17 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxblinpa.dll
[2008/01/30 23:27:17 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbliesc.dll
[2008/01/30 23:27:17 | 000,323,584 | —- | C] ( ) – C:\Windows\System32\LXBLhcp.dll
[2008/01/30 23:27:16 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxblserv.dll
[2008/01/30 23:27:16 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxblhbn3.dll
[2008/01/30 23:27:16 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxblpmui.dll
[2008/01/30 23:27:16 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbllmpm.dll
[2008/01/30 23:27:16 | 000,385,968 | —- | C] ( ) – C:\Windows\System32\lxblih.exe
[2008/01/30 23:27:16 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxblprox.dll
[2008/01/30 23:27:16 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxblpplc.dll
[2008/01/30 23:27:15 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxblcomc.dll
[2008/01/30 23:27:15 | 000,537,520 | —- | C] ( ) – C:\Windows\System32\lxblcoms.exe
[2008/01/30 23:27:15 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxblcomm.dll
[2008/01/30 23:27:15 | 000,381,872 | —- | C] ( ) – C:\Windows\System32\lxblcfg.exe
[2004/07/09 04:08:36 | 000,472,576 | —- | C] (Microsoft Corporation) – C:\Program Files\dxsetup.exe
[2004/07/09 04:08:34 | 002,242,560 | —- | C] (Microsoft Corporation) – C:\Program Files\dsetup32.dll
[2004/07/09 03:03:10 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Program Files\DSETUP.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/09 04:37:33 | 000,607,168 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/09 04:37:33 | 000,104,808 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/09 04:32:15 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/09 04:32:14 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/09 04:32:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/09 04:32:04 | 2136,133,632 | -HS- | M] () – C:\hiberfil.sys
[2011/04/09 04:31:04 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/04/08 17:11:43 | 074,219,917 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2011/04/08 09:13:37 | 000,001,889 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/04/08 08:37:58 | 000,002,521 | —- | M] () – C:\Users\Mike\Desktop\HiJackThis.lnk
[2011/04/07 17:26:13 | 000,000,680 | —- | M] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2011/04/07 17:06:01 | 000,000,511 | —- | M] () – C:\Users\Mike\Desktop\08-recruit-questionnaire.pdf - Shortcut.lnk
[2011/04/07 17:00:42 | 001,402,880 | —- | M] () – C:\Users\Mike\Desktop\HiJackThis.msi
[2011/04/07 16:41:15 | 001,006,778 | —- | M] () – C:\Users\Mike\Desktop\rkill.com
[2011/04/07 11:35:59 | 000,000,761 | —- | M] () – C:\Users\Mike\Desktop\hosts
[2011/04/07 11:02:39 | 000,000,134 | —- | M] () – C:\Users\Mike\Desktop\hosts-perm.bat
[2011/04/01 22:16:09 | 000,000,398 | —- | M] () – C:\Windows\tasks\EasyShare Registration Task.job
[2011/03/14 09:01:45 | 000,033,906 | —- | M] () – C:\Users\Mike\Documents\comcastnov509.rtf
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/08 08:34:53 | 000,002,521 | —- | C] () – C:\Users\Mike\Desktop\HiJackThis.lnk
[2011/04/08 08:29:26 | 2136,133,632 | -HS- | C] () – C:\hiberfil.sys
[2011/04/07 17:24:13 | 000,000,680 | —- | C] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2011/04/07 17:06:01 | 000,000,511 | —- | C] () – C:\Users\Mike\Desktop\08-recruit-questionnaire.pdf - Shortcut.lnk
[2011/04/07 17:00:30 | 001,402,880 | —- | C] () – C:\Users\Mike\Desktop\HiJackThis.msi
[2011/04/07 16:41:27 | 001,006,778 | —- | C] () – C:\Users\Mike\Desktop\rkill.com
[2011/04/07 11:35:49 | 000,000,761 | —- | C] () – C:\Users\Mike\Desktop\hosts
[2011/04/07 10:56:39 | 000,000,134 | —- | C] () – C:\Users\Mike\Desktop\hosts-perm.bat
[2011/01/26 22:02:42 | 000,148,891 | —- | C] () – C:\Windows\hpoins19.dat
[2011/01/26 22:02:28 | 000,026,952 | —- | C] () – C:\Windows\hpomdl19.dat
[2010/11/13 13:21:21 | 000,024,206 | —- | C] () – C:\Users\Mike\AppData\Roaming\UserTile.png
[2009/09/19 20:06:21 | 000,229,888 | —- | C] () – C:\Windows\PEV.exe
[2009/09/19 03:00:40 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/09/18 08:42:32 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/18 08:42:31 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/04/28 21:25:04 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/09/24 05:16:13 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/09/01 06:08:47 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2008/09/01 06:08:47 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2008/09/01 06:08:47 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2008/08/03 13:27:19 | 000,022,328 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2008/08/03 13:27:14 | 000,107,832 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2008/08/03 13:26:51 | 000,066,872 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2008/05/16 11:58:04 | 000,012,632 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2008/01/30 23:27:18 | 000,274,432 | —- | C] () – C:\Windows\System32\LXBLinst.dll
[2008/01/19 10:01:50 | 000,000,552 | —- | C] () – C:\Users\Mike\AppData\Local\d3d8caps.dat
[2008/01/15 20:26:09 | 000,023,345 | —- | C] () – C:\Windows\War3Unin.dat
[2008/01/02 17:57:36 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2008/01/02 17:47:22 | 001,953,696 | —- | C] () – C:\Windows\System32\igklg400.dll
[2008/01/02 17:47:22 | 001,533,360 | —- | C] () – C:\Windows\System32\igklg450.dll
[2007/12/25 00:19:30 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2007/12/24 23:35:10 | 000,052,224 | —- | C] () – C:\Users\Mike\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/24 22:44:37 | 000,047,104 | —- | C] () – C:\Windows\System32\KMVIDC32.DLL
[2007/12/13 11:05:55 | 001,238,832 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2007/12/13 11:05:55 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1322.dll
[2007/12/13 11:05:55 | 000,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2007/12/13 03:20:42 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2007/02/22 19:32:00 | 000,344,064 | —- | C] () – C:\Windows\System32\lxblcoin.dll
[2006/11/10 06:26:12 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/07 12:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,316,904 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,607,168 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,104,808 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/09/16 22:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 22:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2005/09/07 14:44:34 | 000,040,960 | —- | C] () – C:\Windows\System32\lxblvs.dll
[2004/07/22 10:51:34 | 003,432,656 | —- | C] () – C:\Program Files\ManagedDX.CAB
[2004/07/19 22:58:36 | 001,156,363 | —- | C] () – C:\Program Files\BDANT.cab
[2004/07/19 22:53:26 | 000,976,020 | —- | C] () – C:\Program Files\BDAXP.cab
[2004/07/09 14:17:16 | 013,265,040 | —- | C] () – C:\Program Files\dxnt.cab
[2004/07/09 09:13:48 | 015,493,481 | —- | C] () – C:\Program Files\DirectX.cab
[2004/07/09 09:13:46 | 000,703,080 | —- | C] () – C:\Program Files\BDA.cab

========== LOP Check ==========

[2011/03/17 04:08:38 | 000,000,000 | —D | M] – C:\Users\adam\AppData\Roaming\LimeWire
[2011/02/09 05:44:00 | 000,000,000 | —D | M] – C:\Users\adam\AppData\Roaming\SentriLock
[2010/04/15 04:05:02 | 000,000,000 | —D | M] – C:\Users\adam\AppData\Roaming\Skinux
[2008/03/12 21:27:53 | 000,000,000 | —D | M] – C:\Users\Jake\AppData\Roaming\BearShare
[2008/11/11 17:57:53 | 000,000,000 | —D | M] – C:\Users\Jake\AppData\Roaming\LimeWire
[2008/03/01 16:34:42 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\BearShare
[2009/04/28 21:24:46 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\GetRightToGo
[2011/02/28 20:56:51 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Image Zone Express
[2009/07/01 17:05:14 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\LimeWire
[2009/06/05 15:35:48 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\OpenOffice.org
[2010/11/13 13:21:21 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\PeerNetworking
[2011/02/28 20:56:50 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Printer Info Cache
[2011/02/03 20:56:30 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\SentriLock
[2009/12/25 23:24:24 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\Skinux
[2008/10/29 14:05:31 | 000,000,000 | —D | M] – C:\Users\Mike\AppData\Roaming\webex
[2011/04/01 22:16:09 | 000,000,398 | —- | M] () – C:\Windows\Tasks\EasyShare Registration Task.job
[2011/04/09 04:31:04 | 000,032,524 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:62E2D794
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:DFC5A2B2

< End of report >
OTL Extras logfile created on: 4/9/2011 4:39:49 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Mike\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.97 Gb Total Space | 99.05 Gb Free Space | 71.27% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.89 Gb Free Space | 58.88% Space Free | Partition Type: NTFS
Drive E: | 1.05 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: DELL | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1968775331-2293771601-3634261238-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] – "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00333BA3-ADCC-45A1-A186-D426E70B6933}" = lport=445 | protocol=6 | dir=in | name=microsoft directory services |
"{0E3358E3-7690-4557-9798-158F43012AA2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=c:\windows\system32\spoolsv.exe |
"{0F3FFFBB-4922-4A20-8800-D25273A41D24}" = lport=10426 | protocol=17 | dir=in | name=singleclick icc |
"{1D77CB7A-B23F-4BFC-A757-89D3255FDF44}" = lport=138 | protocol=17 | dir=in | app=system |
"{2042DD84-AAE0-4FE2-8FB8-5BF2C6F816F5}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{21F49053-89A2-4318-9F40-EEFDC625754F}" = rport=137 | protocol=17 | dir=out | app=system |
"{2A5ECC2F-41B3-4876-8E0D-C58D96489970}" = lport=10426 | protocol=17 | dir=in | name=singleclick icc |
"{4675253F-3D85-440A-B8CD-1F8075197A7A}" = rport=138 | protocol=17 | dir=out | app=system |
"{55B9C69B-1890-47EB-9C89-156379F1755C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{68708122-C1D5-439F-AD00-89B542267AA2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{85DC4F6A-5CA6-4D67-84C1-E3A40D51BC13}" = lport=445 | protocol=6 | dir=in | app=system |
"{881E6975-DA46-4598-8FD0-FF1874A26007}" = lport=138 | protocol=17 | dir=in | name=netbios datagram service |
"{9B54B380-E74D-4177-9A58-D1B2A1298A06}" = lport=138 | protocol=17 | dir=in | name=netbios datagram service |
"{A1B280D2-5AE9-4F61-B04A-9BA0202C1A2D}" = lport=137 | protocol=17 | dir=in | name=netbios name service |
"{A20AD1AE-03BE-4F5E-BF4B-C04A1CE0F8A3}" = rport=139 | protocol=6 | dir=out | app=system |
"{AC1D92FB-1022-4845-AA99-AEDEC8A54393}" = lport=445 | protocol=6 | dir=in | name=microsoft directory services |
"{AE70A262-B3DC-4993-8914-D31F376684C3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=file and printer sharing (spooler service - rpc-epmap) |
"{BC194F91-9CBB-47E7-BCA0-C234479FE462}" = lport=137 | protocol=17 | dir=in | app=system |
"{BD22FBDC-F6D0-416B-99A7-471B523371E6}" = lport=137 | protocol=17 | dir=in | name=netbios name service |
"{BD30E1CE-C8FD-4073-A9F3-AF741A9090DD}" = lport=139 | protocol=6 | dir=in | app=system |
"{C8021FBC-A562-440B-9CFB-8A897077043A}" = lport=139 | protocol=6 | dir=in | name=netbios file/printer sharing |
"{CE1443EE-BCEA-4310-AC3A-B27BFE1AD986}" = rport=445 | protocol=6 | dir=out | app=system |
"{D2E7F649-DA15-4132-8C82-F82DFA250E7C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E01697F1-5DDF-4B25-B699-C171205925ED}" = lport=10421 | protocol=17 | dir=in | name=singleclick discovery protocol |
"{E71D9F81-9168-428F-9A8B-406413F57020}" = lport=139 | protocol=6 | dir=in | name=netbios file/printer sharing |
"{EA079365-C91B-4156-88C9-2FFF22161A59}" = lport=10421 | protocol=17 | dir=in | name=singleclick discovery protocol |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{10FF1620-7F0C-4636-9C68-F540559E7C56}" = protocol=6 | dir=out | app=system |
"{16B74440-676D-4C2A-8A8C-44B6DC55D76A}" = protocol=1 | dir=out | name=file and printer sharing (echo request - icmpv4-out) |
"{1A0D5F05-FF6C-4991-9380-C60612317AAF}" = dir=in | app=c:\program files\avg\avg8\avgnsx.exe |
"{2E87AAC0-05E1-4CE0-A561-279CA8D5A7DC}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxblpswx.exe |
"{2F3BA009-91EC-4A30-84A0-7E92E87009EF}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{2FCA22B5-BE2D-4507-BBCC-1FD93321CB02}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{342A83D0-F6DD-40E1-8689-827BCBDB11D8}" = protocol=58 | dir=out | name=file and printer sharing (echo request - icmpv6-out) |
"{3444CD1F-D0CD-4A56-9F5C-5F8457CAF126}" = protocol=17 | dir=in | app=c:\windows\system32\lxblcoms.exe |
"{40A1995F-1709-4A64-A51B-E76345C6A45E}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
"{48E4371D-E1C4-41A5-80BC-04DC391AE868}" = protocol=17 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"{67895A31-469E-4FE8-B6CA-0BBEA1074CDA}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{692BC4C3-0C5F-4293-911E-5EB05F7391F5}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxblpswx.exe |
"{6EE9B884-B2CF-41FB-9E8D-256E7C873AC2}" = protocol=6 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"{710D3F7E-BB16-4FDE-B4FC-8E358F427778}" = protocol=17 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"{7C5F7706-F601-498C-B316-7DA0828283F6}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{805CD8B5-BC3E-417E-942E-1F9C998C6443}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{8CBB2863-9BBD-4336-970A-3B149D098767}" = protocol=58 | dir=in | name=file and printer sharing (echo request - icmpv6-in) |
"{91E32B45-6F09-4489-ABFB-BF43B46E329D}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{A1A4A569-1080-4814-BA7D-2B094053ABBB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A96E5E3D-8237-447C-B732-34FBA03FF718}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{BB967E03-C0E4-498F-89E6-6FCDF6378011}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{BC912595-D854-4EF1-A113-DA0C7D2ECBFA}" = protocol=6 | dir=in | app=c:\program files\dell network assistant\ezi_hnm2.exe |
"{C741BC6E-A05A-443F-AD8F-49EED1BF6333}" = protocol=1 | dir=in | name=file and printer sharing (echo request - icmpv4-in) |
"{C75F05FE-1558-40BA-BBED-BA74F119082D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C8DD65DE-EBDA-48B4-BDAD-646ABDB1032B}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{C9D333E2-8E68-4B7D-A944-1E60F0C2D702}" = protocol=6 | dir=in | app=c:\windows\system32\lxblcoms.exe |
"{DE0B3887-C4A9-4534-87EB-934FA215F53E}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{EFD04866-0A6D-451D-893E-1BC4037C1431}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"TCP Query User{0C6225CA-3906-4F3F-85AF-85ABFBA57796}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{37FEAF6A-7977-49ED-8E98-5F5480CA7F60}C:\program files\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"TCP Query User{3A452C91-3807-499A-B6AC-2A7C467E73B9}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"TCP Query User{58B489B2-E024-411A-A38A-843E7DFA6EAE}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{61F46B62-68DA-4187-AA22-41488266FB5E}C:\sun\sdk\jdk\bin\java.exe" = protocol=6 | dir=in | app=c:\sun\sdk\jdk\bin\java.exe |
"TCP Query User{767F2FDF-B41B-4C78-9021-C3B48C7665FC}C:\users\mike\appdata\local\temp\java_ee_sdk-5_07-jdk-6u16-windows.exe2\package\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\users\mike\appdata\local\temp\java_ee_sdk-5_07-jdk-6u16-windows.exe2\package\jre\bin\javaw.exe |
"TCP Query User{A1730505-26CE-41BC-A366-91EDFFE9E0E5}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{E20D8FF9-73EE-4DDE-BCB4-1FB72D9AE8A8}C:\program files\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"TCP Query User{EC726469-B347-42CE-9C31-704A6435445E}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{FE12F0AD-14B9-4A0E-BEA6-D0F1CA800835}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=6 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"TCP Query User{FF61744E-FD4A-484C-A778-76362CC009CA}C:\programdata\59f35a4\wp59f3.exe" = protocol=6 | dir=in | app=c:\programdata\59f35a4\wp59f3.exe |
"UDP Query User{1EEA307F-2707-4B54-A170-3CAA9CB968DE}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{435AACB4-7EF8-47F6-AC35-D382BEB122E2}C:\programdata\59f35a4\wp59f3.exe" = protocol=17 | dir=in | app=c:\programdata\59f35a4\wp59f3.exe |
"UDP Query User{45B713D0-446E-47D1-871F-87EF4E1FF8B5}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"UDP Query User{AA906A42-02B5-4229-80B7-CBFD05A6EC9E}C:\program files\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"UDP Query User{AF918665-48E1-4C59-B251-9E56074CB390}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{B0B5730D-058A-4428-BE96-C32B50EAF15C}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{BA128AB0-7E32-45E0-92D6-D38EB190AA98}C:\program files\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"UDP Query User{BBCE1D9D-50DC-4361-AA18-F6A5AD2FA846}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{E056DADF-78C4-4884-9A6C-9EC1C0A153AE}C:\users\mike\appdata\local\temp\java_ee_sdk-5_07-jdk-6u16-windows.exe2\package\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\users\mike\appdata\local\temp\java_ee_sdk-5_07-jdk-6u16-windows.exe2\package\jre\bin\javaw.exe |
"UDP Query User{EDA5D3E5-441F-402C-A834-5019CEDB6590}C:\program files\bearshare applications\bearshare\bearshare.exe" = protocol=17 | dir=in | app=c:\program files\bearshare applications\bearshare\bearshare.exe |
"UDP Query User{EF616312-9226-4CA6-BB8A-F97BC0CD19CD}C:\sun\sdk\jdk\bin\java.exe" = protocol=17 | dir=in | app=c:\sun\sdk\jdk\bin\java.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{00D15456-F679-4AD4-8BD2-56450D4C3F72}" = WarRock
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = QualxServ Service Agreement
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 23
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2E12D2E2-CC61-4C21-9C62-22EAF560AF15}" = Meeting Manager for Mozilla Firefox/Netscape Navigator
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3143EA86-CF89-4E22-91BB-25B28CE23AED}" = 2350_Help
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{612F4E20-3661-4D44-AD79-823F1B613FB3}" = HP Update
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75685CA8-0B74-45BB-9C64-744A0FB79EDC}" = Business Tools Launcher
"{7583239A-D4BE-48CA-A253-396122B3D3E9}" = Zune
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel® PRO Network Connections 12.1.11.0
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_BASICR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_BASICR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_BASICR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_BASICR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_BASICR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_BASICR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_BASICR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_BASICR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{91120000-0013-0000-0000-0000000FF1CE}" = Microsoft Office Basic 2007
"{91120000-0013-0000-0000-0000000FF1CE}_BASICR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0013-0000-0000-0000000FF1CE}_BASICR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{9332DDCF-336C-4C51-88B2-64F869F4D04B}" = Computrainer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95738B44-49CF-4C62-A620-320F1007B14A}" = SpiralFrog Download Manager 0.8.28
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{A6FC405C-6C58-4ACF-AC41-E999261E76E9}" = 2350Trb
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.3
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C5C649A8-1D21-4C83-9B08-7B3752E580F4}" = Safari
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{C9B8D365-A6C3-4C4D-9624-0F0078FEB1B4}" = Sentrilock Card Utility
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile Device Center Driver Update
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2AB2488-A0BF-4A9B-98A9-A88CF20FD2FF}" = Meeting Manager for Internet Explorer
"{F3757C8B-6552-4EA5-9451-B933A55170BC}" = 2350
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FE34691C-4298-4667-9758-D7F534DD0B94}" = Dell Automated PC TuneUp
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AVG8Uninstall" = AVG Free 8.5
"BASICR" = Microsoft Office Basic 2007
"BearShare" = BearShare
"C4B4D7F5499921DF57A4F6B55E59E0F50C2FE298" = Windows Driver Package - SCM Microsystems Inc. (SCR3xx USB Smart Card Reader) SmartCardReader (11/07/2006 4.35.00.01)
"CCleaner" = CCleaner (remove only)
"COH" = City of Villains/City of Heroes (remove only)
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"Google Desktop" = Google Desktop
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"IrfanView" = IrfanView (remove only)
"Lexmark Z700-P700 Series" = Lexmark Z700-P700 Series
"LimeWire" = LimeWire 4.18.3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"MyOwnSuperherobar Uninstall" = MyOwnSuperhero
"PROSetDX" = Intel® PRO Network Connections 12.1.11.0
"SpywareBlaster_is1" = SpywareBlaster 4.2
"SpywareGuard_is1" = SpywareGuard v2.2
"Super Stunt Spectacular_is1" = Super Stunt Spectacular v1.0
"Warcraft III" = Warcraft III
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
"YInstHelper" = Yahoo! Install Manager

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1968775331-2293771601-3634261238-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ActiveTouchMeetingClient" = Meeting Service

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/8/2011 9:29:59 PM | Computer Name = Dell | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5039

Error - 4/8/2011 9:37:21 PM | Computer Name = Dell | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: DELL ExceptionManager.TimeStamp: 4/8/2011 6:37:21
PM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement, Version=1.0.0.0,
Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName: Spiralfrog.exe
ExceptionManager.ThreadIdentity:
ExceptionManager.WindowsIdentity: Dell\Mike 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The BITS service returned an error for the job with
the ID '69242a6b-9e2c-4efa-84ec-889cd2c47147'; the job's name and description are
'Updater job.' and 'Updater: Download the Server XML File.'. The BITS service
error message for this job is 'HTTP status 404: The requested URL does not exist
on the server. '. This job has been canceled, and the DownloaderManager will attempt
it again. If you see this error frequently, you may have a mis-configuration,
or another administrator process/user is canceling BITS jobs. It is also possible
that some mis-configuration of the Manifest file is causing BITS to have trouble
with a source or destination path; be sure that all SOURCE paths are valid URLs,
and that all DESTINATION paths are valid LOCAL UNC paths–__shares are not allowed__.
Data:
System.Collections.ListDictionaryInternal TargetSite: NULL HelpLink: NULL Source:
NULL

Error - 4/8/2011 9:37:23 PM | Computer Name = Dell | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: DELL ExceptionManager.TimeStamp: 4/8/2011 6:37:23
PM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement, Version=1.0.0.0,
Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName: Spiralfrog.exe
ExceptionManager.ThreadIdentity:
ExceptionManager.WindowsIdentity: Dell\Mike 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The metadata file (the Server Manifest) can't be
downloaded for the application 'SpiralfrogClient'. Either the manifest is unavailable
(check download URL in Updater config file), the downloader failed, or the Manifest
failed validation. Data: System.Collections.ListDictionaryInternal TargetSite: NULL
HelpLink:
NULL Source: NULL 2) Exception Information *********************************************
Exception
Type: System.Runtime.InteropServices.COMException ErrorCode: -2145386481 Message:
Exception from HRESULT: 0x8020000F Data: System.Collections.ListDictionaryInternal
TargetSite:
Void GetError(Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundC
opyError
ByRef) HelpLink: NULL Source: Microsoft.ApplicationBlocks.ApplicationUpdater StackTrace
Information ********************************************* at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundCopyJob.Ge
tError(IBackgroundCopyError&
ppError) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Handle
DownloadErrorCancelJob(IBackgroundCopyJob
copyJob, String& errMessage) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Micros
oft.ApplicationBlocks.ApplicationUpdater.Interfaces.IDownloader.Download(String
sourceFile, String destFile, TimeSpan maxTimeWait) at Microsoft.ApplicationBlocks.ApplicationUpdater.DownloaderManager.IsServerManifes
tDownloaded()

Error - 4/9/2011 1:08:56 AM | Computer Name = Dell | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: DELL ExceptionManager.TimeStamp: 4/8/2011 10:08:56
PM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement, Version=1.0.0.0,
Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName: Spiralfrog.exe
ExceptionManager.ThreadIdentity:
ExceptionManager.WindowsIdentity: Dell\Mike 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The BITS service returned an error for the job with
the ID '76ab5dc1-fd77-4737-8d6e-74026f320b90'; the job's name and description are
'Updater job.' and 'Updater: Download the Server XML File.'. The BITS service
error message for this job is 'HTTP status 404: The requested URL does not exist
on the server. '. This job has been canceled, and the DownloaderManager will attempt
it again. If you see this error frequently, you may have a mis-configuration,
or another administrator process/user is canceling BITS jobs. It is also possible
that some mis-configuration of the Manifest file is causing BITS to have trouble
with a source or destination path; be sure that all SOURCE paths are valid URLs,
and that all DESTINATION paths are valid LOCAL UNC paths–__shares are not allowed__.
Data:
System.Collections.ListDictionaryInternal TargetSite: NULL HelpLink: NULL Source:
NULL

Error - 4/9/2011 1:08:58 AM | Computer Name = Dell | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: DELL ExceptionManager.TimeStamp: 4/8/2011 10:08:58
PM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement, Version=1.0.0.0,
Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName: Spiralfrog.exe
ExceptionManager.ThreadIdentity:
ExceptionManager.WindowsIdentity: Dell\Mike 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The metadata file (the Server Manifest) can't be
downloaded for the application 'SpiralfrogClient'. Either the manifest is unavailable
(check download URL in Updater config file), the downloader failed, or the Manifest
failed validation. Data: System.Collections.ListDictionaryInternal TargetSite: NULL
HelpLink:
NULL Source: NULL 2) Exception Information *********************************************
Exception
Type: System.Runtime.InteropServices.COMException ErrorCode: -2145386481 Message:
Exception from HRESULT: 0x8020000F Data: System.Collections.ListDictionaryInternal
TargetSite:
Void GetError(Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundC
opyError
ByRef) HelpLink: NULL Source: Microsoft.ApplicationBlocks.ApplicationUpdater StackTrace
Information ********************************************* at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundCopyJob.Ge
tError(IBackgroundCopyError&
ppError) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Handle
DownloadErrorCancelJob(IBackgroundCopyJob
copyJob, String& errMessage) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Micros
oft.ApplicationBlocks.ApplicationUpdater.Interfaces.IDownloader.Download(String
sourceFile, String destFile, TimeSpan maxTimeWait) at Microsoft.ApplicationBlocks.ApplicationUpdater.DownloaderManager.IsServerManifes
tDownloaded()

Error - 4/9/2011 6:51:52 AM | Computer Name = Dell | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: DELL ExceptionManager.TimeStamp: 4/9/2011 3:51:52
AM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement, Version=1.0.0.0,
Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName: Spiralfrog.exe
ExceptionManager.ThreadIdentity:
ExceptionManager.WindowsIdentity: Dell\Mike 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The metadata file (the Server Manifest) can't be
downloaded for the application 'SpiralfrogClient'. Either the manifest is unavailable
(check download URL in Updater config file), the downloader failed, or the Manifest
failed validation. Data: System.Collections.ListDictionaryInternal TargetSite: NULL
HelpLink:
NULL Source: NULL 2) Exception Information *********************************************
Exception
Type: System.Runtime.InteropServices.COMException ErrorCode: -2145386481 Message:
Exception from HRESULT: 0x8020000F Data: System.Collections.ListDictionaryInternal
TargetSite:
Void GetError(Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundC
opyError
ByRef) HelpLink: NULL Source: Microsoft.ApplicationBlocks.ApplicationUpdater StackTrace
Information ********************************************* at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundCopyJob.Ge
tError(IBackgroundCopyError&
ppError) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Handle
DownloadErrorCancelJob(IBackgroundCopyJob
copyJob, String& errMessage) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Micros
oft.ApplicationBlocks.ApplicationUpdater.Interfaces.IDownloader.Download(String
sourceFile, String destFile, TimeSpan maxTimeWait) at Microsoft.ApplicationBlocks.ApplicationUpdater.DownloaderManager.IsServerManifes
tDownloaded()

Error - 4/9/2011 6:52:11 AM | Computer Name = Dell | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: DELL ExceptionManager.TimeStamp: 4/9/2011 3:52:11
AM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement, Version=1.0.0.0,
Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName: Spiralfrog.exe
ExceptionManager.ThreadIdentity:
ExceptionManager.WindowsIdentity: Dell\Mike 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The BITS service returned an error for the job with
the ID '6c37c355-a1c2-454b-9780-0ad4a366b248'; the job's name and description are
'Updater job.' and 'Updater: Download the Server XML File.'. The BITS service
error message for this job is 'HTTP status 404: The requested URL does not exist
on the server. '. This job has been canceled, and the DownloaderManager will attempt
it again. If you see this error frequently, you may have a mis-configuration,
or another administrator process/user is canceling BITS jobs. It is also possible
that some mis-configuration of the Manifest file is causing BITS to have trouble
with a source or destination path; be sure that all SOURCE paths are valid URLs,
and that all DESTINATION paths are valid LOCAL UNC paths–__shares are not allowed__.
Data:
System.Collections.ListDictionaryInternal TargetSite: NULL HelpLink: NULL Source:
NULL

Error - 4/9/2011 6:52:13 AM | Computer Name = Dell | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: DELL ExceptionManager.TimeStamp: 4/9/2011 3:52:13
AM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement, Version=1.0.0.0,
Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName: Spiralfrog.exe
ExceptionManager.ThreadIdentity:
ExceptionManager.WindowsIdentity: Dell\Mike 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The metadata file (the Server Manifest) can't be
downloaded for the application 'SpiralfrogClient'. Either the manifest is unavailable
(check download URL in Updater config file), the downloader failed, or the Manifest
failed validation. Data: System.Collections.ListDictionaryInternal TargetSite: NULL
HelpLink:
NULL Source: NULL 2) Exception Information *********************************************
Exception
Type: System.Runtime.InteropServices.COMException ErrorCode: -2145386481 Message:
Exception from HRESULT: 0x8020000F Data: System.Collections.ListDictionaryInternal
TargetSite:
Void GetError(Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundC
opyError
ByRef) HelpLink: NULL Source: Microsoft.ApplicationBlocks.ApplicationUpdater StackTrace
Information ********************************************* at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundCopyJob.Ge
tError(IBackgroundCopyError&
ppError) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Handle
DownloadErrorCancelJob(IBackgroundCopyJob
copyJob, String& errMessage) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Micros
oft.ApplicationBlocks.ApplicationUpdater.Interfaces.IDownloader.Download(String
sourceFile, String destFile, TimeSpan maxTimeWait) at Microsoft.ApplicationBlocks.ApplicationUpdater.DownloaderManager.IsServerManifes
tDownloaded()

Error - 4/9/2011 7:34:42 AM | Computer Name = Dell | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: DELL ExceptionManager.TimeStamp: 4/9/2011 4:34:42
AM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement, Version=1.0.0.0,
Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName: Spiralfrog.exe
ExceptionManager.ThreadIdentity:
ExceptionManager.WindowsIdentity: Dell\Mike 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The BITS service returned an error for the job with
the ID 'd4c83ee8-db18-42a4-9b28-2954c9baad6f'; the job's name and description are
'Updater job.' and 'Updater: Download the Server XML File.'. The BITS service
error message for this job is 'HTTP status 404: The requested URL does not exist
on the server. '. This job has been canceled, and the DownloaderManager will attempt
it again. If you see this error frequently, you may have a mis-configuration,
or another administrator process/user is canceling BITS jobs. It is also possible
that some mis-configuration of the Manifest file is causing BITS to have trouble
with a source or destination path; be sure that all SOURCE paths are valid URLs,
and that all DESTINATION paths are valid LOCAL UNC paths–__shares are not allowed__.
Data:
System.Collections.ListDictionaryInternal TargetSite: NULL HelpLink: NULL Source:
NULL

Error - 4/9/2011 7:34:44 AM | Computer Name = Dell | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: DELL ExceptionManager.TimeStamp: 4/9/2011 4:34:44
AM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement, Version=1.0.0.0,
Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName: Spiralfrog.exe
ExceptionManager.ThreadIdentity:
ExceptionManager.WindowsIdentity: Dell\Mike 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The metadata file (the Server Manifest) can't be
downloaded for the application 'SpiralfrogClient'. Either the manifest is unavailable
(check download URL in Updater config file), the downloader failed, or the Manifest
failed validation. Data: System.Collections.ListDictionaryInternal TargetSite: NULL
HelpLink:
NULL Source: NULL 2) Exception Information *********************************************
Exception
Type: System.Runtime.InteropServices.COMException ErrorCode: -2145386481 Message:
Exception from HRESULT: 0x8020000F Data: System.Collections.ListDictionaryInternal
TargetSite:
Void GetError(Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundC
opyError
ByRef) HelpLink: NULL Source: Microsoft.ApplicationBlocks.ApplicationUpdater StackTrace
Information ********************************************* at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundCopyJob.Ge
tError(IBackgroundCopyError&
ppError) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Handle
DownloadErrorCancelJob(IBackgroundCopyJob
copyJob, String& errMessage) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Micros
oft.ApplicationBlocks.ApplicationUpdater.Interfaces.IDownloader.Download(String
sourceFile, String destFile, TimeSpan maxTimeWait) at Microsoft.ApplicationBlocks.ApplicationUpdater.DownloaderManager.IsServerManifes
tDownloaded()

[ Media Center Events ]
Error - 5/26/2008 11:53:01 PM | Computer Name = Dell | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 5/30/2008 11:47:34 PM | Computer Name = Dell | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 5/31/2008 8:04:12 AM | Computer Name = Dell | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 6/2/2008 4:20:38 AM | Computer Name = Dell | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 6/2/2008 11:07:01 AM | Computer Name = Dell | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 6/2/2008 10:22:20 PM | Computer Name = Dell | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 6/8/2008 8:42:14 AM | Computer Name = Dell | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 8/28/2008 8:24:36 AM | Computer Name = Dell | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/11/2009 1:40:26 AM | Computer Name = Dell | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/11/2009 11:27:35 PM | Computer Name = Dell | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ OSession Events ]
Error - 9/3/2008 3:45:20 PM | Computer Name = Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 12
seconds with 0 seconds of active time. This session ended with a crash.

Error - 5/31/2010 6:09:33 PM | Computer Name = Dell | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6571
seconds with 4500 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 4/8/2011 10:47:29 AM | Computer Name = Dell | Source = DCOM | ID = 10005
Description =

Error - 4/8/2011 10:47:32 AM | Computer Name = Dell | Source = DCOM | ID = 10005
Description =

Error - 4/8/2011 10:47:37 AM | Computer Name = Dell | Source = DCOM | ID = 10005
Description =

Error - 4/8/2011 10:48:09 AM | Computer Name = Dell | Source = Service Control Manager | ID = 7001
Description =

Error - 4/8/2011 10:48:09 AM | Computer Name = Dell | Source = Service Control Manager | ID = 7026
Description =

Error - 4/8/2011 10:48:35 AM | Computer Name = Dell | Source = DCOM | ID = 10005
Description =

Error - 4/8/2011 12:13:36 PM | Computer Name = Dell | Source = DCOM | ID = 10005
Description =

Error - 4/8/2011 12:13:36 PM | Computer Name = Dell | Source = Service Control Manager | ID = 7009
Description =

Error - 4/8/2011 12:13:36 PM | Computer Name = Dell | Source = Service Control Manager | ID = 7000
Description =

Error - 4/8/2011 8:29:59 PM | Computer Name = Dell | Source = Service Control Manager | ID = 7011
Description =


< End of report >
Hi,

Backup Your Registry with ERUNT:
  • Download erunt.zip to your Desktop from here:
    http://aumha.org/downloads/erunt.zip
  • Right-click erunt.zip, select Extract All… and follow the prompts to extract ERUNT to a new folder on your Desktop
  • Inside the new folder, double-click ERUNT.exe to start the program
  • OK all the prompts to back up your registry to the default location.
Note: to restore your registry, go to the backup folder and start ERDNT.exe







Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    O4 - HKU\S-1-5-21-1968775331-2293771601-3634261238-1000..\Run: [Qyixahe] File not found
    @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:62E2D794
    @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:DFC5A2B2
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces.
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Ken, thanks again for your help. I ran erunt, but it kept telling me that it could not copy files. It has always done this when I start my computer btw. When I ran otl with the code you supplied, it locked up and was unable to continue. I had to reboot.
Ok, What I would like you to do is run Combofix, the only problem is that it will conflict with AVG so go to Programs and features in the Control Panel and uninstall AVG, dont do any surfing except for accessing this forum and as soon as we're done you can reinstall it.


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 11-04-08.03 - Mike 04/09/2011 8:03.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2036.1069 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\ANTIGEN.tmp
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\cid.dll
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\DBOLE.sys
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\delfile.sys
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\dudl.dll
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\eb.dll
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\eb.drv
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\eb.exe
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\energy.dll
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\energy.exe
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\exec.sys
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\exec.tmp
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\grid.drv
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\grid.sys
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\hymt.dll
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\kernel32.drv
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\kernel32.sys
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\kernel32.tmp
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\pal.dll
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\PE.exe
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\PE.sys
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\PE.tmp
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\runddl.dll
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\runddl.drv
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\runddl.sys
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\runddlkey.tmp
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\SICKBOY.tmp
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\sld.dll
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\tjd.exe
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Recent\tjd.tmp
.
—– BITS: Possible infected sites —–
.
hxxp://www.spiralfrog.com
.
((((((((((((((((((((((((( Files Created from 2011-03-09 to 2011-04-09 )))))))))))))))))))))))))))))))
.
.
2011-04-09 15:09 . 2011-04-09 15:09 ——– d—–w- c:\users\Jake\AppData\Local\temp
2011-04-09 15:09 . 2011-04-09 15:09 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-04-09 15:09 . 2011-04-09 15:09 ——– d—–w- c:\users\adam\AppData\Local\temp
2011-04-09 15:01 . 2011-04-09 15:01 ——– d—–w- c:\users\Mike\AppData\Local\Adobe
2011-04-09 14:58 . 2011-04-09 14:58 ——– d—–w- c:\program files\Common Files\Java
2011-04-09 12:42 . 2011-04-09 12:42 ——– d—–w- C:\_OTL
2011-04-08 15:37 . 2011-03-15 04:05 6792528 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CF54C734-07CC-448D-991E-2E8ABB366100}\mpengine.dll
2011-04-08 15:36 . 2011-04-08 15:36 ——– d—–w- c:\programdata\HP Product Assistant
2011-04-08 15:34 . 2011-04-08 15:34 388096 —-a-r- c:\users\Mike\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-04-07 14:55 . 2011-04-08 15:28 ——– d—–w- c:\programdata\jGk06511aKeNd06511
2011-03-25 13:17 . 2011-04-08 15:36 ——– d—–w- c:\users\Mike\AppData\Roaming\HpUpdate
2011-03-25 13:17 . 2011-03-25 13:17 ——– d—–w- c:\windows\Hewlett-Packard
2011-03-23 04:10 . 2011-03-23 04:10 749832 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-03-22 19:53 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-22 19:53 . 2011-02-22 13:33 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-03-22 19:53 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-03-12 19:28 . 2011-03-12 19:28 103864 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-03-12 19:28 . 2011-03-12 19:28 103864 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 04:40 . 2010-05-21 04:16 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-03 01:11 . 2009-10-03 04:25 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-01-20 16:37 . 2011-02-08 22:36 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-20 16:08 . 2011-02-08 22:36 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08 . 2011-02-08 22:36 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08 . 2011-02-08 22:36 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08 . 2011-02-08 22:36 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08 . 2011-02-08 22:36 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07 . 2011-02-08 22:36 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07 . 2011-02-08 22:36 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07 . 2011-02-08 22:36 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06 . 2011-02-08 22:36 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06 . 2011-02-08 22:36 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04 . 2011-02-08 22:36 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 16:04 . 2011-02-08 22:36 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 14:28 . 2011-02-08 22:36 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27 . 2011-02-08 22:36 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26 . 2011-02-08 22:36 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25 . 2011-02-08 22:36 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24 . 2011-02-08 22:36 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15 . 2011-02-08 22:36 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14 . 2011-02-08 22:36 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14 . 2011-02-08 22:36 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14 . 2011-02-08 22:36 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12 . 2011-02-08 22:36 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11 . 2011-02-08 22:36 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47 . 2011-02-08 22:36 683008 —-a-w- c:\windows\system32\d2d1.dll
2004-07-09 11:08 . 2004-07-09 11:08 472576 —-a-w- c:\program files\dxsetup.exe
2004-07-09 11:08 . 2004-07-09 11:08 2242560 —-a-w- c:\program files\dsetup32.dll
2004-07-09 10:03 . 2004-07-09 10:03 62976 —-a-w- c:\program files\DSETUP.dll
2009-11-29 18:22 . 2008-08-11 04:47 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-14 4452352]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-10 16384]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-01-12 166304]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-03 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-03 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-03 133656]
"SpiralFrog"="c:\program files\SpiralFrog\Spiralfrog.exe" [2008-10-22 204088]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-13 141600]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-21 963976]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-21 963976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\users\adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-6-18 147456]
.
c:\users\Jake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-6-18 147456]
.
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2009-7-10 323584]
SentriLockCardUtility.lnk - c:\windows\Installer\{C9B8D365-A6C3-4C4D-9624-0F0078FEB1B4}\Icon037926361.exe [2011-2-3 84480]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [x]
R3 SCR3xx USB Smart Card Reader;SCR3xx USB Smart Card Reader;c:\windows\system32\DRIVERS\SCR3XX2K.sys [2010-01-07 57856]
R3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\DRIVERS\SCR3XX2K.sys [2010-01-07 57856]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 lxbl_device;lxbl_device;c:\windows\system32\lxblcoms.exe [2007-04-20 537520]
S2 MyOwnSuperheroService;MyOwnSuperhero Service;c:\progra~1\MYOWNS~2\bar\1.bin\v3barsvc.exe [2011-02-28 28766]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2071213
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\
FF - prefs.js: network.proxy.type - 0
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Warcraft III - c:\windows\War3Unin.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-09 08:09
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-04-09 08:10:55
ComboFix-quarantined-files.txt 2011-04-09 15:10
ComboFix2.txt 2009-09-20 03:27
ComboFix3.txt 2009-09-20 03:14
ComboFix4.txt 2008-09-01 13:13
.
Pre-Run: 106,627,039,232 bytes free
Post-Run: 106,598,326,272 bytes free
.
- - End Of File - - 1BA9DB97F2BE0DB607FF738474899D52
Wow, Combofix removed some bad stuff.

Limewire <–Your downloading that file from an unknown source and not all but some contain malware, you should stay away from any type of File Sharing.


MyOwnSuperhero Service <–Is this something that you use ?


Run OTL ( not the fix ) a scan and post a new log
I noticed the myownsuperhero file. I have no idea what the heck that is!

here is my otl scan log

OTL logfile created on: 4/9/2011 12:53:34 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Mike\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.97 Gb Total Space | 99.32 Gb Free Space | 71.47% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.89 Gb Free Space | 58.88% Space Free | Partition Type: NTFS
Drive E: | 1.05 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: DELL | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mike\Desktop\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\MyOwnSuperhero\bar\1.bin\v3barsvc.exe (MyOwnSuperhero)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
PRC - C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe (SentriLock LLC)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\lxblcoms.exe ( )


========== Modules (SafeList) ==========

MOD - C:\Users\Mike\Desktop\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (GoogleDesktopManager-110309-193829) – File not found
SRV - (MyOwnSuperheroService) – C:\Program Files\MyOwnSuperhero\bar\1.bin\v3barsvc.exe (MyOwnSuperhero)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – C:\Windows\System32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (lxbl_device) – C:\Windows\System32\lxblcoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (catchme) – File not found
DRV - (SCR3XX2K) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (SCR3xx USB Smart Card Reader) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (BVRPMPR5) – C:\Windows\System32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (datunidr) – C:\Windows\System32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyOwnSuperhero\bar\1.bin [2011/02/27 21:53:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 09:52:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/08 09:13:37 | 000,000,000 | —D | M]

[2008/08/30 07:19:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Extensions
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions
[2009/09/17 19:00:57 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/09/22 07:48:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2009/09/22 07:48:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2008/10/29 13:48:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/08/20 17:00:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008/01/24 21:59:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2009/01/13 21:39:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/02/17 09:58:45 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2009/08/20 17:08:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\staged-xpis
[2010/11/30 11:40:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2008/12/17 22:57:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/04/09 07:58:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/20 21:16:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/28 06:42:36 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/26 22:31:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/04/09 07:58:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/04/26 19:09:24 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2008/10/29 13:52:34 | 000,057,240 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2011/04/09 08:09:14 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O24 - Desktop WallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = ComFile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/04/09 08:10:59 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/04/09 08:10:57 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/04/09 08:01:47 | 000,000,000 | —D | C] – C:\ComboFix
[2011/04/09 08:01:27 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\swxcacls.exe
[2011/04/09 08:01:01 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Local\Adobe
[2011/04/09 07:58:41 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/04/09 07:58:32 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/04/09 07:58:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/04/09 07:58:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/04/09 05:42:46 | 000,000,000 | —D | C] – C:\_OTL
[2011/04/08 08:36:05 | 000,000,000 | —D | C] – C:\ProgramData\HP Product Assistant
[2011/04/08 08:34:53 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/04/07 07:55:32 | 000,000,000 | —D | C] – C:\ProgramData\jGk06511aKeNd06511
[2011/03/31 18:19:12 | 000,000,000 | —D | C] – C:\Users\Mike\Documents\walmart pics
[2011/03/25 06:17:23 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\HpUpdate
[2011/03/25 06:17:20 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2011/03/22 12:53:11 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/22 12:53:11 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2008/01/30 23:27:17 | 000,995,328 | —- | C] ( ) – C:\Windows\System32\lxblusb1.dll
[2008/01/30 23:27:17 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxblinpa.dll
[2008/01/30 23:27:17 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbliesc.dll
[2008/01/30 23:27:17 | 000,323,584 | —- | C] ( ) – C:\Windows\System32\LXBLhcp.dll
[2008/01/30 23:27:16 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxblserv.dll
[2008/01/30 23:27:16 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxblhbn3.dll
[2008/01/30 23:27:16 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxblpmui.dll
[2008/01/30 23:27:16 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbllmpm.dll
[2008/01/30 23:27:16 | 000,385,968 | —- | C] ( ) – C:\Windows\System32\lxblih.exe
[2008/01/30 23:27:16 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxblprox.dll
[2008/01/30 23:27:16 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxblpplc.dll
[2008/01/30 23:27:15 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxblcomc.dll
[2008/01/30 23:27:15 | 000,537,520 | —- | C] ( ) – C:\Windows\System32\lxblcoms.exe
[2008/01/30 23:27:15 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxblcomm.dll
[2008/01/30 23:27:15 | 000,381,872 | —- | C] ( ) – C:\Windows\System32\lxblcfg.exe
[2004/07/09 04:08:36 | 000,472,576 | —- | C] (Microsoft Corporation) – C:\Program Files\dxsetup.exe
[2004/07/09 04:08:34 | 002,242,560 | —- | C] (Microsoft Corporation) – C:\Program Files\dsetup32.dll
[2004/07/09 03:03:10 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Program Files\DSETUP.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/09 11:52:16 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/09 11:52:16 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/09 10:02:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/09 08:09:14 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/04/09 07:57:29 | 000,607,168 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/09 07:57:29 | 000,104,808 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/09 07:52:10 | 2136,133,632 | -HS- | M] () – C:\hiberfil.sys
[2011/04/09 07:51:17 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/04/08 09:13:37 | 000,001,889 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/04/08 08:37:58 | 000,002,521 | —- | M] () – C:\Users\Mike\Desktop\HiJackThis.lnk
[2011/04/07 17:26:13 | 000,000,680 | —- | M] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2011/04/07 17:06:01 | 000,000,511 | —- | M] () – C:\Users\Mike\Desktop\08-recruit-questionnaire.pdf - Shortcut.lnk
[2011/04/07 17:00:42 | 001,402,880 | —- | M] () – C:\Users\Mike\Desktop\HiJackThis.msi
[2011/04/07 16:41:15 | 001,006,778 | —- | M] () – C:\Users\Mike\Desktop\rkill.com
[2011/04/07 11:35:59 | 000,000,761 | —- | M] () – C:\Users\Mike\Desktop\hosts
[2011/04/07 11:02:39 | 000,000,134 | —- | M] () – C:\Users\Mike\Desktop\hosts-perm.bat
[2011/03/14 09:01:45 | 000,033,906 | —- | M] () – C:\Users\Mike\Documents\comcastnov509.rtf
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/09 08:01:52 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/04/08 08:34:53 | 000,002,521 | —- | C] () – C:\Users\Mike\Desktop\HiJackThis.lnk
[2011/04/08 08:29:26 | 2136,133,632 | -HS- | C] () – C:\hiberfil.sys
[2011/04/07 17:24:13 | 000,000,680 | —- | C] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2011/04/07 17:06:01 | 000,000,511 | —- | C] () – C:\Users\Mike\Desktop\08-recruit-questionnaire.pdf - Shortcut.lnk
[2011/04/07 17:00:30 | 001,402,880 | —- | C] () – C:\Users\Mike\Desktop\HiJackThis.msi
[2011/04/07 16:41:27 | 001,006,778 | —- | C] () – C:\Users\Mike\Desktop\rkill.com
[2011/04/07 11:35:49 | 000,000,761 | —- | C] () – C:\Users\Mike\Desktop\hosts
[2011/04/07 10:56:39 | 000,000,134 | —- | C] () – C:\Users\Mike\Desktop\hosts-perm.bat
[2011/01/26 22:02:42 | 000,148,891 | —- | C] () – C:\Windows\hpoins19.dat
[2011/01/26 22:02:28 | 000,026,952 | —- | C] () – C:\Windows\hpomdl19.dat
[2010/11/13 13:21:21 | 000,024,206 | —- | C] () – C:\Users\Mike\AppData\Roaming\UserTile.png
[2009/09/19 20:06:21 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2009/09/19 03:00:40 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/09/18 08:42:32 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/18 08:42:31 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/04/28 21:25:04 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/09/24 05:16:13 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/09/01 06:08:47 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2008/09/01 06:08:47 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2008/09/01 06:08:47 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2008/08/03 13:27:19 | 000,022,328 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2008/08/03 13:27:14 | 000,107,832 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2008/08/03 13:26:51 | 000,066,872 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2008/05/16 11:58:04 | 000,012,632 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2008/01/30 23:27:18 | 000,274,432 | —- | C] () – C:\Windows\System32\LXBLinst.dll
[2008/01/19 10:01:50 | 000,000,552 | —- | C] () – C:\Users\Mike\AppData\Local\d3d8caps.dat
[2008/01/15 20:26:09 | 000,023,345 | —- | C] () – C:\Windows\War3Unin.dat
[2008/01/02 17:57:36 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2008/01/02 17:47:22 | 001,953,696 | —- | C] () – C:\Windows\System32\igklg400.dll
[2008/01/02 17:47:22 | 001,533,360 | —- | C] () – C:\Windows\System32\igklg450.dll
[2007/12/25 00:19:30 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2007/12/24 23:35:10 | 000,052,224 | —- | C] () – C:\Users\Mike\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/24 22:44:37 | 000,047,104 | —- | C] () – C:\Windows\System32\KMVIDC32.DLL
[2007/12/13 11:05:55 | 001,238,832 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2007/12/13 11:05:55 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1322.dll
[2007/12/13 11:05:55 | 000,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2007/12/13 03:20:42 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2007/02/22 19:32:00 | 000,344,064 | —- | C] () – C:\Windows\System32\lxblcoin.dll
[2006/11/10 06:26:12 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/07 12:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,316,904 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,607,168 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,104,808 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/09/16 22:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 22:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2005/09/07 14:44:34 | 000,040,960 | —- | C] () – C:\Windows\System32\lxblvs.dll
[2004/07/22 10:51:34 | 003,432,656 | —- | C] () – C:\Program Files\ManagedDX.CAB
[2004/07/19 22:58:36 | 001,156,363 | —- | C] () – C:\Program Files\BDANT.cab
[2004/07/19 22:53:26 | 000,976,020 | —- | C] () – C:\Program Files\BDAXP.cab
[2004/07/09 14:17:16 | 013,265,040 | —- | C] () – C:\Program Files\dxnt.cab
[2004/07/09 09:13:48 | 015,493,481 | —- | C] () – C:\Program Files\DirectX.cab
[2004/07/09 09:13:46 | 000,703,080 | —- | C] () – C:\Program Files\BDA.cab

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI