This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ms removal tool

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Why don't you go to Programs and Features in the Control Panel and uninstall it , then run a new scan with OTL and post the new log. Take your time as I will be offline until later on this evening
uninstalled mysuperhero.

Here's the new otl scan

OTL logfile created on: 4/9/2011 2:06:29 PM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Mike\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 59.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.97 Gb Total Space | 99.32 Gb Free Space | 71.47% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.89 Gb Free Space | 58.88% Space Free | Partition Type: NTFS
Drive E: | 1.05 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: DELL | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mike\Desktop\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
PRC - C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe (SentriLock LLC)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\lxblcoms.exe ( )


========== Modules (SafeList) ==========

MOD - C:\Users\Mike\Desktop\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (GoogleDesktopManager-110309-193829) – File not found
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – C:\Windows\System32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (lxbl_device) – C:\Windows\System32\lxblcoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (catchme) – File not found
DRV - (SCR3XX2K) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (SCR3xx USB Smart Card Reader) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (BVRPMPR5) – C:\Windows\System32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (datunidr) – C:\Windows\System32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 09:52:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/08 09:13:37 | 000,000,000 | —D | M]

[2008/08/30 07:19:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Extensions
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions
[2009/09/17 19:00:57 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/09/22 07:48:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2009/09/22 07:48:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2008/10/29 13:48:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/08/20 17:00:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008/01/24 21:59:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2009/01/13 21:39:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/02/17 09:58:45 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2009/08/20 17:08:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\staged-xpis
[2010/11/30 11:40:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2008/12/17 22:57:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/04/09 07:58:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/20 21:16:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/28 06:42:36 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/26 22:31:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/04/09 07:58:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/04/26 19:09:24 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2008/10/29 13:52:34 | 000,057,240 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2011/04/09 08:09:14 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [MyOwnSuperherobar Uninstall] C:\Program Files\Uninstall MyOwnSuperhero.dll (MyOwnSuperhero)
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O24 - Desktop WallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = ComFile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/04/09 13:41:40 | 000,675,840 | —- | C] (MyOwnSuperhero) – C:\Program Files\Uninstall MyOwnSuperhero.dll
[2011/04/09 08:10:59 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/04/09 08:10:57 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/04/09 08:01:47 | 000,000,000 | —D | C] – C:\ComboFix
[2011/04/09 08:01:27 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\swxcacls.exe
[2011/04/09 08:01:01 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Local\Adobe
[2011/04/09 07:58:41 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/04/09 07:58:32 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/04/09 07:58:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/04/09 07:58:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/04/09 05:42:46 | 000,000,000 | —D | C] – C:\_OTL
[2011/04/08 08:36:05 | 000,000,000 | —D | C] – C:\ProgramData\HP Product Assistant
[2011/04/08 08:34:53 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/04/07 07:55:32 | 000,000,000 | —D | C] – C:\ProgramData\jGk06511aKeNd06511
[2011/03/31 18:19:12 | 000,000,000 | —D | C] – C:\Users\Mike\Documents\walmart pics
[2011/03/25 06:17:23 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\HpUpdate
[2011/03/25 06:17:20 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2011/03/22 12:53:11 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/22 12:53:11 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2008/01/30 23:27:17 | 000,995,328 | —- | C] ( ) – C:\Windows\System32\lxblusb1.dll
[2008/01/30 23:27:17 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxblinpa.dll
[2008/01/30 23:27:17 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbliesc.dll
[2008/01/30 23:27:17 | 000,323,584 | —- | C] ( ) – C:\Windows\System32\LXBLhcp.dll
[2008/01/30 23:27:16 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxblserv.dll
[2008/01/30 23:27:16 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxblhbn3.dll
[2008/01/30 23:27:16 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxblpmui.dll
[2008/01/30 23:27:16 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbllmpm.dll
[2008/01/30 23:27:16 | 000,385,968 | —- | C] ( ) – C:\Windows\System32\lxblih.exe
[2008/01/30 23:27:16 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxblprox.dll
[2008/01/30 23:27:16 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxblpplc.dll
[2008/01/30 23:27:15 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxblcomc.dll
[2008/01/30 23:27:15 | 000,537,520 | —- | C] ( ) – C:\Windows\System32\lxblcoms.exe
[2008/01/30 23:27:15 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxblcomm.dll
[2008/01/30 23:27:15 | 000,381,872 | —- | C] ( ) – C:\Windows\System32\lxblcfg.exe
[2004/07/09 04:08:36 | 000,472,576 | —- | C] (Microsoft Corporation) – C:\Program Files\dxsetup.exe
[2004/07/09 04:08:34 | 002,242,560 | —- | C] (Microsoft Corporation) – C:\Program Files\dsetup32.dll
[2004/07/09 03:03:10 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Program Files\DSETUP.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/09 13:52:16 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/09 13:52:16 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/09 10:02:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/09 08:09:14 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/04/09 07:57:29 | 000,607,168 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/09 07:57:29 | 000,104,808 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/09 07:52:10 | 2136,133,632 | -HS- | M] () – C:\hiberfil.sys
[2011/04/09 07:51:17 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/04/08 09:13:37 | 000,001,889 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/04/08 08:37:58 | 000,002,521 | —- | M] () – C:\Users\Mike\Desktop\HiJackThis.lnk
[2011/04/07 17:26:13 | 000,000,680 | —- | M] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2011/04/07 17:06:01 | 000,000,511 | —- | M] () – C:\Users\Mike\Desktop\08-recruit-questionnaire.pdf - Shortcut.lnk
[2011/04/07 17:00:42 | 001,402,880 | —- | M] () – C:\Users\Mike\Desktop\HiJackThis.msi
[2011/04/07 16:41:15 | 001,006,778 | —- | M] () – C:\Users\Mike\Desktop\rkill.com
[2011/04/07 11:35:59 | 000,000,761 | —- | M] () – C:\Users\Mike\Desktop\hosts
[2011/04/07 11:02:39 | 000,000,134 | —- | M] () – C:\Users\Mike\Desktop\hosts-perm.bat
[2011/03/14 09:01:45 | 000,033,906 | —- | M] () – C:\Users\Mike\Documents\comcastnov509.rtf
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/09 08:01:52 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/04/08 08:34:53 | 000,002,521 | —- | C] () – C:\Users\Mike\Desktop\HiJackThis.lnk
[2011/04/08 08:29:26 | 2136,133,632 | -HS- | C] () – C:\hiberfil.sys
[2011/04/07 17:24:13 | 000,000,680 | —- | C] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2011/04/07 17:06:01 | 000,000,511 | —- | C] () – C:\Users\Mike\Desktop\08-recruit-questionnaire.pdf - Shortcut.lnk
[2011/04/07 17:00:30 | 001,402,880 | —- | C] () – C:\Users\Mike\Desktop\HiJackThis.msi
[2011/04/07 16:41:27 | 001,006,778 | —- | C] () – C:\Users\Mike\Desktop\rkill.com
[2011/04/07 11:35:49 | 000,000,761 | —- | C] () – C:\Users\Mike\Desktop\hosts
[2011/04/07 10:56:39 | 000,000,134 | —- | C] () – C:\Users\Mike\Desktop\hosts-perm.bat
[2011/01/26 22:02:42 | 000,148,891 | —- | C] () – C:\Windows\hpoins19.dat
[2011/01/26 22:02:28 | 000,026,952 | —- | C] () – C:\Windows\hpomdl19.dat
[2010/11/13 13:21:21 | 000,024,206 | —- | C] () – C:\Users\Mike\AppData\Roaming\UserTile.png
[2009/09/19 20:06:21 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2009/09/19 03:00:40 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/09/18 08:42:32 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/18 08:42:31 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/04/28 21:25:04 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/09/24 05:16:13 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/09/01 06:08:47 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2008/09/01 06:08:47 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2008/09/01 06:08:47 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2008/08/03 13:27:19 | 000,022,328 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2008/08/03 13:27:14 | 000,107,832 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2008/08/03 13:26:51 | 000,066,872 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2008/05/16 11:58:04 | 000,012,632 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2008/01/30 23:27:18 | 000,274,432 | —- | C] () – C:\Windows\System32\LXBLinst.dll
[2008/01/19 10:01:50 | 000,000,552 | —- | C] () – C:\Users\Mike\AppData\Local\d3d8caps.dat
[2008/01/15 20:26:09 | 000,023,345 | —- | C] () – C:\Windows\War3Unin.dat
[2008/01/02 17:57:36 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2008/01/02 17:47:22 | 001,953,696 | —- | C] () – C:\Windows\System32\igklg400.dll
[2008/01/02 17:47:22 | 001,533,360 | —- | C] () – C:\Windows\System32\igklg450.dll
[2007/12/25 00:19:30 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2007/12/24 23:35:10 | 000,052,224 | —- | C] () – C:\Users\Mike\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/24 22:44:37 | 000,047,104 | —- | C] () – C:\Windows\System32\KMVIDC32.DLL
[2007/12/13 11:05:55 | 001,238,832 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2007/12/13 11:05:55 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1322.dll
[2007/12/13 11:05:55 | 000,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2007/12/13 03:20:42 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2007/02/22 19:32:00 | 000,344,064 | —- | C] () – C:\Windows\System32\lxblcoin.dll
[2006/11/10 06:26:12 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/07 12:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,316,904 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,607,168 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,104,808 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/09/16 22:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 22:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2005/09/07 14:44:34 | 000,040,960 | —- | C] () – C:\Windows\System32\lxblvs.dll
[2004/07/22 10:51:34 | 003,432,656 | —- | C] () – C:\Program Files\ManagedDX.CAB
[2004/07/19 22:58:36 | 001,156,363 | —- | C] () – C:\Program Files\BDANT.cab
[2004/07/19 22:53:26 | 000,976,020 | —- | C] () – C:\Program Files\BDAXP.cab
[2004/07/09 14:17:16 | 013,265,040 | —- | C] () – C:\Program Files\dxnt.cab
[2004/07/09 09:13:48 | 015,493,481 | —- | C] () – C:\Program Files\DirectX.cab
[2004/07/09 09:13:46 | 000,703,080 | —- | C] () – C:\Program Files\BDA.cab

< End of report >
Lets see if the fix will work now

Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    O4 - HKLM..\RunOnce: [MyOwnSuperherobar Uninstall] C:\Program Files\Uninstall MyOwnSuperhero.dll (MyOwnSuperhero)
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces.
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
All processes killed
========== PROCESSES ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\MyOwnSuperherobar Uninstall not found.
C:\Program Files\Uninstall MyOwnSuperhero.dll moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Mike\Desktop\Downloads\cmd.bat deleted successfully.
C:\Users\Mike\Desktop\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: adam
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Jake
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Mike
->Temp folder emptied: 196100 bytes
->Temporary Internet Files folder emptied: 1156441 bytes
->Java cache emptied: 15925094 bytes
->FireFox cache emptied: 55815757 bytes
->Flash cache emptied: 1961015 bytes

User: Public
->Temp folder emptied: 0 bytes

User: TEMP
->Temp folder emptied: 0 bytes

User: TEMP.Dell
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 675840 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5613 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 72.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 04092011_181545

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
OTL logfile created on: 4/9/2011 6:19:40 PM - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Mike\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 52.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.97 Gb Total Space | 99.42 Gb Free Space | 71.54% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.89 Gb Free Space | 58.88% Space Free | Partition Type: NTFS
Drive E: | 1.05 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: DELL | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mike\Desktop\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
PRC - C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe (SentriLock LLC)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\lxblcoms.exe ( )
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\Mike\Desktop\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (GoogleDesktopManager-110309-193829) – File not found
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – C:\Windows\System32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (lxbl_device) – C:\Windows\System32\lxblcoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (SCR3XX2K) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (SCR3xx USB Smart Card Reader) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (BVRPMPR5) – C:\Windows\System32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (datunidr) – C:\Windows\System32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 09:52:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/08 09:13:37 | 000,000,000 | —D | M]

[2008/08/30 07:19:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Extensions
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions
[2009/09/17 19:00:57 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/09/22 07:48:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2009/09/22 07:48:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2008/10/29 13:48:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/08/20 17:00:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008/01/24 21:59:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2009/01/13 21:39:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/02/17 09:58:45 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2009/08/20 17:08:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\staged-xpis
[2010/11/30 11:40:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2008/12/17 22:57:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/04/09 07:58:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/20 21:16:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/28 06:42:36 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/26 22:31:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/04/09 07:58:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/04/26 19:09:24 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2008/10/29 13:52:34 | 000,057,240 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2011/04/09 18:15:47 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O24 - Desktop WallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = ComFile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/04/09 08:10:59 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/04/09 08:10:57 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/04/09 08:01:47 | 000,000,000 | —D | C] – C:\ComboFix
[2011/04/09 08:01:27 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\swxcacls.exe
[2011/04/09 08:01:01 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Local\Adobe
[2011/04/09 07:58:41 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/04/09 07:58:32 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/04/09 07:58:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/04/09 07:58:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/04/09 05:42:46 | 000,000,000 | —D | C] – C:\_OTL
[2011/04/08 08:36:05 | 000,000,000 | —D | C] – C:\ProgramData\HP Product Assistant
[2011/04/08 08:34:53 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/04/07 07:55:32 | 000,000,000 | —D | C] – C:\ProgramData\jGk06511aKeNd06511
[2011/03/31 18:19:12 | 000,000,000 | —D | C] – C:\Users\Mike\Documents\walmart pics
[2011/03/25 06:17:23 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\HpUpdate
[2011/03/25 06:17:20 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2011/03/22 12:53:11 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/22 12:53:11 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2008/01/30 23:27:17 | 000,995,328 | —- | C] ( ) – C:\Windows\System32\lxblusb1.dll
[2008/01/30 23:27:17 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxblinpa.dll
[2008/01/30 23:27:17 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbliesc.dll
[2008/01/30 23:27:17 | 000,323,584 | —- | C] ( ) – C:\Windows\System32\LXBLhcp.dll
[2008/01/30 23:27:16 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxblserv.dll
[2008/01/30 23:27:16 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxblhbn3.dll
[2008/01/30 23:27:16 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxblpmui.dll
[2008/01/30 23:27:16 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbllmpm.dll
[2008/01/30 23:27:16 | 000,385,968 | —- | C] ( ) – C:\Windows\System32\lxblih.exe
[2008/01/30 23:27:16 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxblprox.dll
[2008/01/30 23:27:16 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxblpplc.dll
[2008/01/30 23:27:15 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxblcomc.dll
[2008/01/30 23:27:15 | 000,537,520 | —- | C] ( ) – C:\Windows\System32\lxblcoms.exe
[2008/01/30 23:27:15 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxblcomm.dll
[2008/01/30 23:27:15 | 000,381,872 | —- | C] ( ) – C:\Windows\System32\lxblcfg.exe
[2004/07/09 04:08:36 | 000,472,576 | —- | C] (Microsoft Corporation) – C:\Program Files\dxsetup.exe
[2004/07/09 04:08:34 | 002,242,560 | —- | C] (Microsoft Corporation) – C:\Program Files\dsetup32.dll
[2004/07/09 03:03:10 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Program Files\DSETUP.dll

========== Files - Modified Within 30 Days ==========

[2011/04/09 18:17:05 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/09 18:17:05 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/09 18:16:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/09 18:16:55 | 2136,133,632 | -HS- | M] () – C:\hiberfil.sys
[2011/04/09 18:16:02 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/04/09 18:15:47 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2011/04/09 14:49:34 | 000,607,168 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/09 14:49:34 | 000,104,808 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/08 09:13:37 | 000,001,889 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/04/08 08:37:58 | 000,002,521 | —- | M] () – C:\Users\Mike\Desktop\HiJackThis.lnk
[2011/04/07 17:26:13 | 000,000,680 | —- | M] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2011/04/07 17:06:01 | 000,000,511 | —- | M] () – C:\Users\Mike\Desktop\08-recruit-questionnaire.pdf - Shortcut.lnk
[2011/04/07 17:00:42 | 001,402,880 | —- | M] () – C:\Users\Mike\Desktop\HiJackThis.msi
[2011/04/07 16:41:15 | 001,006,778 | —- | M] () – C:\Users\Mike\Desktop\rkill.com
[2011/04/07 11:35:59 | 000,000,761 | —- | M] () – C:\Users\Mike\Desktop\hosts
[2011/04/07 11:02:39 | 000,000,134 | —- | M] () – C:\Users\Mike\Desktop\hosts-perm.bat
[2011/03/14 09:01:45 | 000,033,906 | —- | M] () – C:\Users\Mike\Documents\comcastnov509.rtf

========== Files Created - No Company Name ==========

[2011/04/09 08:01:52 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/04/08 08:34:53 | 000,002,521 | —- | C] () – C:\Users\Mike\Desktop\HiJackThis.lnk
[2011/04/08 08:29:26 | 2136,133,632 | -HS- | C] () – C:\hiberfil.sys
[2011/04/07 17:24:13 | 000,000,680 | —- | C] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2011/04/07 17:06:01 | 000,000,511 | —- | C] () – C:\Users\Mike\Desktop\08-recruit-questionnaire.pdf - Shortcut.lnk
[2011/04/07 17:00:30 | 001,402,880 | —- | C] () – C:\Users\Mike\Desktop\HiJackThis.msi
[2011/04/07 16:41:27 | 001,006,778 | —- | C] () – C:\Users\Mike\Desktop\rkill.com
[2011/04/07 11:35:49 | 000,000,761 | —- | C] () – C:\Users\Mike\Desktop\hosts
[2011/04/07 10:56:39 | 000,000,134 | —- | C] () – C:\Users\Mike\Desktop\hosts-perm.bat
[2011/01/26 22:02:42 | 000,148,891 | —- | C] () – C:\Windows\hpoins19.dat
[2011/01/26 22:02:28 | 000,026,952 | —- | C] () – C:\Windows\hpomdl19.dat
[2010/11/13 13:21:21 | 000,024,206 | —- | C] () – C:\Users\Mike\AppData\Roaming\UserTile.png
[2009/09/19 20:06:21 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2009/09/19 03:00:40 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/09/18 08:42:32 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/18 08:42:31 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/04/28 21:25:04 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/09/24 05:16:13 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/09/01 06:08:47 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2008/09/01 06:08:47 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2008/09/01 06:08:47 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2008/08/03 13:27:19 | 000,022,328 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2008/08/03 13:27:14 | 000,107,832 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2008/08/03 13:26:51 | 000,066,872 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2008/05/16 11:58:04 | 000,012,632 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2008/01/30 23:27:18 | 000,274,432 | —- | C] () – C:\Windows\System32\LXBLinst.dll
[2008/01/19 10:01:50 | 000,000,552 | —- | C] () – C:\Users\Mike\AppData\Local\d3d8caps.dat
[2008/01/15 20:26:09 | 000,023,345 | —- | C] () – C:\Windows\War3Unin.dat
[2008/01/02 17:57:36 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2008/01/02 17:47:22 | 001,953,696 | —- | C] () – C:\Windows\System32\igklg400.dll
[2008/01/02 17:47:22 | 001,533,360 | —- | C] () – C:\Windows\System32\igklg450.dll
[2007/12/25 00:19:30 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2007/12/24 23:35:10 | 000,052,224 | —- | C] () – C:\Users\Mike\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/24 22:44:37 | 000,047,104 | —- | C] () – C:\Windows\System32\KMVIDC32.DLL
[2007/12/13 11:05:55 | 001,238,832 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2007/12/13 11:05:55 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1322.dll
[2007/12/13 11:05:55 | 000,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2007/12/13 03:20:42 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2007/02/22 19:32:00 | 000,344,064 | —- | C] () – C:\Windows\System32\lxblcoin.dll
[2006/11/10 06:26:12 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/07 12:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,316,904 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,607,168 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,104,808 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/09/16 22:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 22:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2005/09/07 14:44:34 | 000,040,960 | —- | C] () – C:\Windows\System32\lxblvs.dll
[2004/07/22 10:51:34 | 003,432,656 | —- | C] () – C:\Program Files\ManagedDX.CAB
[2004/07/19 22:58:36 | 001,156,363 | —- | C] () – C:\Program Files\BDANT.cab
[2004/07/19 22:53:26 | 000,976,020 | —- | C] () – C:\Program Files\BDAXP.cab
[2004/07/09 14:17:16 | 013,265,040 | —- | C] () – C:\Program Files\dxnt.cab
[2004/07/09 09:13:48 | 015,493,481 | —- | C] () – C:\Program Files\DirectX.cab
[2004/07/09 09:13:46 | 000,703,080 | —- | C] () – C:\Program Files\BDA.cab

< End of report >
Only after you have uninstalled Spiral Frog than run this fix





Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    PRC - C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
    O4 - HKLM..\Run: [SpiralFrog] C:\Program Files\SpiralFrog\Spiralfrog.exe (SpiralFrog)
    
    :Services
    
    :Reg
    
    :Files
    C:\Program Files\SpiralFrog
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces.
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
All processes killed ========== PROCESSES ========== ========== OTL ========== No active process named Spiralfrog.exe was found! Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SpiralFrog not found. File C:\Program Files\SpiralFrog\Spiralfrog.exe not found. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\Program Files\SpiralFrog folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: adam ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Jake ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Mike ->Temp folder emptied: 179473 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 43816741 bytes ->Flash cache emptied: 456 bytes User: Public ->Temp folder emptied: 0 bytes User: TEMP ->Temp folder emptied: 0 bytes User: TEMP.Dell ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 4296 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 42.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 04102011_071245 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
OTL logfile created on: 4/10/2011 7:17:58 AM - Run 5
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Mike\Desktop\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.97 Gb Total Space | 99.42 Gb Free Space | 71.54% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.89 Gb Free Space | 58.88% Space Free | Partition Type: NTFS
Drive E: | 1.05 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: DELL | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mike\Desktop\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (Eastman Kodak Company)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\SentrilockCardUtility\SentriLockCardUtility.exe (SentriLock LLC)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\lxblcoms.exe ( )
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()


========== Modules (SafeList) ==========

MOD - C:\Users\Mike\Desktop\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (GoogleDesktopManager-110309-193829) – File not found
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – C:\Windows\System32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (lxbl_device) – C:\Windows\System32\lxblcoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (SCR3XX2K) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (SCR3xx USB Smart Card Reader) – C:\Windows\System32\drivers\SCR3XX2K.sys (SCM Microsystems Inc.)
DRV - (BVRPMPR5) – C:\Windows\System32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (datunidr) – C:\Windows\System32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://partnerpage.google.com/smallbiz.del…amp;ibd=2071213
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 09:52:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/08 09:13:37 | 000,000,000 | —D | M]

[2008/08/30 07:19:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Extensions
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions
[2009/09/17 19:00:57 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/09/22 07:48:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2009/09/22 07:48:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2008/10/29 13:48:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/08/20 17:00:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008/01/24 21:59:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2009/01/13 21:39:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/02/17 09:58:45 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2009/08/20 17:08:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/03/05 19:02:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\staged-xpis
[2010/11/30 11:40:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2008/12/17 22:57:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\oxmnlibu.default\extensions\[removed]
[2011/04/09 07:58:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/20 21:16:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/28 06:42:36 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/26 22:31:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/04/09 07:58:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/04/26 19:09:24 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2008/10/29 13:52:34 | 000,057,240 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2011/04/09 18:15:47 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O24 - Desktop WallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Mike\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = ComFile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/04/09 08:10:59 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/04/09 08:10:57 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/04/09 08:01:47 | 000,000,000 | —D | C] – C:\ComboFix
[2011/04/09 08:01:27 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\swxcacls.exe
[2011/04/09 08:01:01 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Local\Adobe
[2011/04/09 07:58:41 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/04/09 07:58:32 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/04/09 07:58:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/04/09 07:58:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/04/09 05:42:46 | 000,000,000 | —D | C] – C:\_OTL
[2011/04/08 08:36:05 | 000,000,000 | —D | C] – C:\ProgramData\HP Product Assistant
[2011/04/08 08:34:53 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/04/07 07:55:32 | 000,000,000 | —D | C] – C:\ProgramData\jGk06511aKeNd06511
[2011/03/31 18:19:12 | 000,000,000 | —D | C] – C:\Users\Mike\Documents\walmart pics
[2011/03/25 06:17:23 | 000,000,000 | —D | C] – C:\Users\Mike\AppData\Roaming\HpUpdate
[2011/03/25 06:17:20 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2011/03/22 12:53:11 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/22 12:53:11 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2008/01/30 23:27:17 | 000,995,328 | —- | C] ( ) – C:\Windows\System32\lxblusb1.dll
[2008/01/30 23:27:17 | 000,413,696 | —- | C] ( ) – C:\Windows\System32\lxblinpa.dll
[2008/01/30 23:27:17 | 000,397,312 | —- | C] ( ) – C:\Windows\System32\lxbliesc.dll
[2008/01/30 23:27:17 | 000,323,584 | —- | C] ( ) – C:\Windows\System32\LXBLhcp.dll
[2008/01/30 23:27:16 | 001,224,704 | —- | C] ( ) – C:\Windows\System32\lxblserv.dll
[2008/01/30 23:27:16 | 000,696,320 | —- | C] ( ) – C:\Windows\System32\lxblhbn3.dll
[2008/01/30 23:27:16 | 000,643,072 | —- | C] ( ) – C:\Windows\System32\lxblpmui.dll
[2008/01/30 23:27:16 | 000,585,728 | —- | C] ( ) – C:\Windows\System32\lxbllmpm.dll
[2008/01/30 23:27:16 | 000,385,968 | —- | C] ( ) – C:\Windows\System32\lxblih.exe
[2008/01/30 23:27:16 | 000,163,840 | —- | C] ( ) – C:\Windows\System32\lxblprox.dll
[2008/01/30 23:27:16 | 000,094,208 | —- | C] ( ) – C:\Windows\System32\lxblpplc.dll
[2008/01/30 23:27:15 | 000,684,032 | —- | C] ( ) – C:\Windows\System32\lxblcomc.dll
[2008/01/30 23:27:15 | 000,537,520 | —- | C] ( ) – C:\Windows\System32\lxblcoms.exe
[2008/01/30 23:27:15 | 000,421,888 | —- | C] ( ) – C:\Windows\System32\lxblcomm.dll
[2008/01/30 23:27:15 | 000,381,872 | —- | C] ( ) – C:\Windows\System32\lxblcfg.exe
[2004/07/09 04:08:36 | 000,472,576 | —- | C] (Microsoft Corporation) – C:\Program Files\dxsetup.exe
[2004/07/09 04:08:34 | 002,242,560 | —- | C] (Microsoft Corporation) – C:\Program Files\dsetup32.dll
[2004/07/09 03:03:10 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Program Files\DSETUP.dll

========== Files - Modified Within 30 Days ==========

[2011/04/10 07:13:56 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/10 07:13:56 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/10 07:13:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/10 07:13:47 | 2136,133,632 | -HS- | M] () – C:\hiberfil.sys
[2011/04/10 07:12:54 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2011/04/09 18:22:31 | 000,607,168 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/09 18:22:31 | 000,104,808 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/09 18:15:47 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2011/04/08 09:13:37 | 000,001,889 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/04/08 08:37:58 | 000,002,521 | —- | M] () – C:\Users\Mike\Desktop\HiJackThis.lnk
[2011/04/07 17:26:13 | 000,000,680 | —- | M] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2011/04/07 17:06:01 | 000,000,511 | —- | M] () – C:\Users\Mike\Desktop\08-recruit-questionnaire.pdf - Shortcut.lnk
[2011/04/07 17:00:42 | 001,402,880 | —- | M] () – C:\Users\Mike\Desktop\HiJackThis.msi
[2011/04/07 16:41:15 | 001,006,778 | —- | M] () – C:\Users\Mike\Desktop\rkill.com
[2011/04/07 11:35:59 | 000,000,761 | —- | M] () – C:\Users\Mike\Desktop\hosts
[2011/04/07 11:02:39 | 000,000,134 | —- | M] () – C:\Users\Mike\Desktop\hosts-perm.bat
[2011/03/14 09:01:45 | 000,033,906 | —- | M] () – C:\Users\Mike\Documents\comcastnov509.rtf

========== Files Created - No Company Name ==========

[2011/04/09 08:01:52 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/04/08 08:34:53 | 000,002,521 | —- | C] () – C:\Users\Mike\Desktop\HiJackThis.lnk
[2011/04/08 08:29:26 | 2136,133,632 | -HS- | C] () – C:\hiberfil.sys
[2011/04/07 17:24:13 | 000,000,680 | —- | C] () – C:\Users\Mike\AppData\Local\d3d9caps.dat
[2011/04/07 17:06:01 | 000,000,511 | —- | C] () – C:\Users\Mike\Desktop\08-recruit-questionnaire.pdf - Shortcut.lnk
[2011/04/07 17:00:30 | 001,402,880 | —- | C] () – C:\Users\Mike\Desktop\HiJackThis.msi
[2011/04/07 16:41:27 | 001,006,778 | —- | C] () – C:\Users\Mike\Desktop\rkill.com
[2011/04/07 11:35:49 | 000,000,761 | —- | C] () – C:\Users\Mike\Desktop\hosts
[2011/04/07 10:56:39 | 000,000,134 | —- | C] () – C:\Users\Mike\Desktop\hosts-perm.bat
[2011/01/26 22:02:42 | 000,148,891 | —- | C] () – C:\Windows\hpoins19.dat
[2011/01/26 22:02:28 | 000,026,952 | —- | C] () – C:\Windows\hpomdl19.dat
[2010/11/13 13:21:21 | 000,024,206 | —- | C] () – C:\Users\Mike\AppData\Roaming\UserTile.png
[2009/09/19 20:06:21 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2009/09/19 03:00:40 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/09/18 08:42:32 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/18 08:42:31 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/04/28 21:25:04 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2008/09/24 05:16:13 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2008/09/01 06:08:47 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2008/09/01 06:08:47 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2008/09/01 06:08:47 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2008/08/03 13:27:19 | 000,022,328 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2008/08/03 13:27:14 | 000,107,832 | —- | C] () – C:\Windows\System32\PnkBstrB.exe
[2008/08/03 13:26:51 | 000,066,872 | —- | C] () – C:\Windows\System32\PnkBstrA.exe
[2008/05/16 11:58:04 | 000,012,632 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2008/01/30 23:27:18 | 000,274,432 | —- | C] () – C:\Windows\System32\LXBLinst.dll
[2008/01/19 10:01:50 | 000,000,552 | —- | C] () – C:\Users\Mike\AppData\Local\d3d8caps.dat
[2008/01/15 20:26:09 | 000,023,345 | —- | C] () – C:\Windows\War3Unin.dat
[2008/01/02 17:57:36 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2008/01/02 17:47:22 | 001,953,696 | —- | C] () – C:\Windows\System32\igklg400.dll
[2008/01/02 17:47:22 | 001,533,360 | —- | C] () – C:\Windows\System32\igklg450.dll
[2007/12/25 00:19:30 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2007/12/24 23:35:10 | 000,052,224 | —- | C] () – C:\Users\Mike\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/24 22:44:37 | 000,047,104 | —- | C] () – C:\Windows\System32\KMVIDC32.DLL
[2007/12/13 11:05:55 | 001,238,832 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2007/12/13 11:05:55 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1322.dll
[2007/12/13 11:05:55 | 000,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2007/12/13 03:20:42 | 000,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2007/02/22 19:32:00 | 000,344,064 | —- | C] () – C:\Windows\System32\lxblcoin.dll
[2006/11/10 06:26:12 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/07 12:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,316,904 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,607,168 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,104,808 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/09/16 22:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 22:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2005/09/07 14:44:34 | 000,040,960 | —- | C] () – C:\Windows\System32\lxblvs.dll
[2004/07/22 10:51:34 | 003,432,656 | —- | C] () – C:\Program Files\ManagedDX.CAB
[2004/07/19 22:58:36 | 001,156,363 | —- | C] () – C:\Program Files\BDANT.cab
[2004/07/19 22:53:26 | 000,976,020 | —- | C] () – C:\Program Files\BDAXP.cab
[2004/07/09 14:17:16 | 013,265,040 | —- | C] () – C:\Program Files\dxnt.cab
[2004/07/09 09:13:48 | 015,493,481 | —- | C] () – C:\Program Files\DirectX.cab
[2004/07/09 09:13:46 | 000,703,080 | —- | C] () – C:\Program Files\BDA.cab

< End of report >
Good,


ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
I ran eset twice. The first time it found a threat called registry booster. The second time it found no threats. I was unable to find the log file when the scan completed. ;)
Seems to be running fine. I did some other reading on the site and downloaded Microsoft essentials. Perhaps you could tell me why Erunt is not working properly when I boot up. It gives me error messages. It doesn't appear to be able to copy files on startup. I also get a message about blocked programs on startup. When I click on the balloon, it shows mbam as being blocked. I cant find where it is blocked though. The box is checked as a startup program.
When you run ERUNT, try right clicking on it and select RUN AS ADMINISTRATOR Go to Start > Run and type in msconfig > Enter and then go to the Start Up folder and see if any of the programs you want to start are blocked, you can check or uncheck the ones you want to start . If there is one ( and there will be ) that your note sure what it is than leave it alone
Most excellent! Things are looking quite groovy! :D Are there any other things that you see that I should install or be aware of? I sent a small donation to your paypal account btw. Thanks again!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI