This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Am I Infected

52 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello again,

I have run malwarebytes and adaware and my antivirus and have come up "clean", but I am having some web sites performing all of a sudden sluggish or non-responsive while others seem fine. When I sometimes click on submit buttons or next buttons nothing happens. Some general sluggishness is found all around as well. I primarily use firefox as my main browser with chrome secondary. I do not use IE very much at all any more. I do try to remember to go in and make sure I keep up with updates ……. I think most of these issues started when I upgraded firefox (which I really do not like). I also from time to time run CCleaner. Below is my hijack this log.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:29:09 PM, on 4/17/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\CSHelper.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\KM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\KM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\KM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\KM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\spider.exe
G:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Microsoft
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: FCTBPos00Pos - {614BDA1F-9BEF-4CD1-BDE4-FA4804929B4A} - C:\Program Files\MyPoints Point Finder\Toolbar.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: MyPoints Point Finder - {89A2510A-B4B6-4683-BEC9-1B96700BC7F1} - C:\Program Files\MyPoints Point Finder\Toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [PC Pitstop PC Matic Reminder] C:\Program Files\PCPitstop\PC Matic\Reminder-PCMatic.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\KM\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.facebook.com
O15 - Trusted Zone: http://www.hulu.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {445F47D7-E043-4BD6-82EB-7A1BD0EBA773} (CopyGuardCtrl Class) - http://www.psapoll.com/CopyGuardIE.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {A7846ED2-9DE6-4E8A-B116-A8ACEBFA7DB1} (Invoke Solutions MILiveParticipantPadHelper Control) - http://rms2.invokesolutions.com/events/bin…1452/MILive.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCPitstop Scheduling - PC Pitstop LLC - C:\Program Files\PCPitstop\PCPitstopScheduleService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 15002 bytes
Hi mickey7,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

I'm not seeing anything obvious.

Let's get a deeper scan:

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Here is the DDS: Run by [removed] at 18:16:20.21 on Tue 04/19/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.899 [GMT -4:00] . AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe svchost.exe C:\WINDOWS\Explorer.EXE svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\system32\CSHelper.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\WINDOWS\system32\FsUsbExService.Exe C:\WINDOWS\System32\GEARSec.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\WINDOWS\stsystra.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\PixArt\PAC7302\Monitor.exe C:\Program Files\Creative\Mixer\CTSVolFE.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\Pure Networks\Network Magic\nmapp.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Digital Line Detect\DLG.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\AVG\AVG9\avgtray.exe C:\Documents and Settings\KM\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ uWindow Title = Windows Internet Explorer provided by Microsoft uInternet Settings,ProxyOverride = uURLSearchHooks: H - No File uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll mWinlogon: Userinit=c:\windows\system32\userinit.exe BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll BHO: Freecause Toolbar BHO: {614bda1f-9bef-4cd1-bde4-fa4804929b4a} - c:\program files\mypoints point finder\Toolbar.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll TB: MyPoints Point Finder: {89a2510a-b4b6-4683-bec9-1b96700bc7f1} - c:\program files\mypoints point finder\Toolbar.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Google Update] "c:\documents and settings\km\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe" mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [PAC7302_Monitor] c:\windows\pixart\pac7302\Monitor.exe mRun: [CTSVolFE.exe] "c:\program files\creative\mixer\CTSVolFE.exe" /r mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe" mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash mRun: [NPSStartup] mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [PC Pitstop PC Matic Reminder] c:\program files\pcpitstop\pc matic\Reminder-PCMatic.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll Trusted Zone: facebook.com\www Trusted Zone: hulu.com\www DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {445F47D7-E043-4BD6-82EB-7A1BD0EBA773} - hxxp://www.psapoll.com/CopyGuardIE.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {A7846ED2-9DE6-4E8A-B116-A8ACEBFA7DB1} - hxxp://rms2.invokesolutions.com/events/bin/6.2.0.1452/MILive.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\kathry~1\applic~1\mozilla\firefox\profiles\q5ok45qo.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://us.yahoo.com FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=62133&p= FF - prefs.js: network.proxy.type - 0 FF - component: c:\documents and settings\km\application data\mozilla\firefox\profiles\q5ok45qo.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\components\XPATLCOM.dll FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: c:\documents and settings\km\application data\move networks\plugins\npqmp071503000010.dll FF - plugin: c:\documents and settings\km\application data\move networks\plugins\npqmp071505000010.dll FF - plugin: c:\documents and settings\km\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\documents and settings\km\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\documents and settings\km\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60129.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npArtistScope42.dll FF - plugin: c:\program files\mozilla firefox\plugins\npArtistScopeDRM11.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - plugin: c:\program files\wildtangent games\app\browserintegration\registered\1\NP_wtapp.dll . —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true ============= SERVICES / DRIVERS =============== . R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-5-3 64288] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-3 216400] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-5-3 29584] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-3 243024] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-15 308136] R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [2010-3-6 266240] R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-8-15 233472] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-7-12 1753048] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R3 AngelUsb;Angel USB MPEG Device;c:\windows\system32\drivers\AngelUsb.sys [2006-7-25 386560] R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-8-15 36608] R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-11 15232] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-10-26 517448] S3 GamesAppService;GamesAppService;c:\program files\wildtangent games\app\GamesAppService.exe [2010-10-12 206072] S3 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2010-10-18 90864] S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] . =============== Created Last 30 ================ . 2011-04-08 20:36:51 26112 —-a-w- c:\windows\system32\drivers\usbser.sys 2011-04-08 20:36:51 26112 —-a-w- c:\windows\system32\dllcache\usbser.sys 2011-04-01 22:27:37 ——– d—–w- c:\program files\EmSense 2011-04-01 22:24:26 ——– d—–w- c:\docume~1\kathry~1\applic~1\EmSense 2011-03-27 19:09:07 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll 2011-03-27 19:09:06 159744 —-a-w- c:\program files\mozilla firefox\plugins\npqtplugin7.dll 2011-03-27 19:09:06 159744 —-a-w- c:\program files\mozilla firefox\plugins\npqtplugin6.dll 2011-03-27 19:09:06 159744 —-a-w- c:\program files\mozilla firefox\plugins\npqtplugin5.dll 2011-03-27 19:09:06 159744 —-a-w- c:\program files\mozilla firefox\plugins\npqtplugin4.dll 2011-03-27 19:09:06 159744 —-a-w- c:\program files\mozilla firefox\plugins\npqtplugin3.dll 2011-03-27 19:09:06 159744 —-a-w- c:\program files\mozilla firefox\plugins\npqtplugin2.dll 2011-03-27 19:09:06 159744 —-a-w- c:\program files\mozilla firefox\plugins\npqtplugin.dll 2011-03-27 19:07:44 ——– d—–w- c:\docume~1\kathry~1\locals~1\applic~1\Apple 2011-03-27 19:07:30 ——– d—–w- c:\docume~1\kathry~1\locals~1\applic~1\Apple Computer 2011-03-24 21:30:28 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2011-03-24 21:30:27 781272 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll 2011-03-24 21:30:27 728024 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll 2011-03-24 21:30:27 1975768 —-a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll 2011-03-24 21:30:27 1893336 —-a-w- c:\program files\mozilla firefox\d3dx9_42.dll 2011-03-24 21:30:27 1874904 —-a-w- c:\program files\mozilla firefox\mozjs.dll 2011-03-24 21:30:27 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll 2011-03-24 21:30:27 142296 —-a-w- c:\program files\mozilla firefox\libEGL.dll 2011-03-21 22:21:25 ——– d—–w- c:\documents and settings\km\eApps . ==================== Find3M ==================== . 2011-04-07 07:59:03 16432 —-a-w- c:\windows\system32\lsdelete.exe 2011-03-07 05:33:50 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-04 06:37:06 420864 —-a-w- c:\windows\system32\vbscript.dll 2011-03-03 13:21:11 1857920 —-a-w- c:\windows\system32\win32k.sys 2011-02-22 23:06:29 916480 —-a-w- c:\windows\system32\wininet.dll 2011-02-22 23:06:29 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-02-22 23:06:29 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2011-02-22 22:22:41 398760 —-a-r- c:\windows\system32\cpnprt2.cid 2011-02-22 11:41:59 385024 —-a-w- c:\windows\system32\html.iec 2011-02-17 12:32:12 5120 —-a-w- c:\windows\system32\xpsp4res.dll 2011-02-15 12:56:39 290432 —-a-w- c:\windows\system32\atmfd.dll 2011-02-11 13:25:52 229888 —-a-w- c:\windows\system32\fxscover.exe 2011-02-08 13:33:55 978944 —-a-w- c:\windows\system32\mfc42.dll 2011-02-08 13:33:55 974848 —-a-w- c:\windows\system32\mfc42u.dll 2011-02-04 22:48:32 456192 —-a-w- c:\windows\system32\encdec.dll 2011-02-04 22:48:30 291840 —-a-w- c:\windows\system32\sbe.dll 2011-02-03 02:40:23 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-02-03 00:19:39 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-02-02 07:58:35 2067456 —-a-w- c:\windows\system32\mstscax.dll 2011-01-27 11:57:06 677888 —-a-w- c:\windows\system32\mstsc.exe 2011-01-21 14:44:37 439296 —-a-w- c:\windows\system32\shimgvw.dll . ============= FINISH: 18:17:19.07 =============== I cannot upload the attach.txt file it states: "Error Upload failed. The file was larger than the available space" although the file is only 18.7KB in size.
ok here is the attach.txt log: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 7/31/2006 8:29:17 PM System Uptime: 4/19/2011 6:02:08 PM (0 hours ago) . Motherboard: Dell Inc. | | 0XD720 Processor: Genuine Intel® CPU T2400 @ 1.83GHz | Microprocessor | 1828/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 37 GiB total, 6.301 GiB free. D: is FIXED (NTFS) - 13 GiB total, 1.554 GiB free. E: is CDROM () G: is FIXED (FAT32) - 75 GiB total, 15.889 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP47: 2/22/2011 5:51:42 PM - System Checkpoint RP48: 2/24/2011 5:44:21 PM - System Checkpoint RP49: 2/27/2011 10:22:34 AM - System Checkpoint RP50: 2/28/2011 5:47:24 PM - System Checkpoint RP51: 3/1/2011 7:31:26 PM - System Checkpoint RP52: 3/3/2011 5:45:04 PM - System Checkpoint RP53: 3/4/2011 5:46:01 PM - System Checkpoint RP54: 3/5/2011 5:51:00 PM - System Checkpoint RP55: 3/6/2011 8:07:28 PM - System Checkpoint RP56: 3/8/2011 5:50:20 PM - System Checkpoint RP57: 3/8/2011 11:19:27 PM - Software Distribution Service 3.0 RP58: 3/10/2011 5:41:13 PM - System Checkpoint RP59: 3/10/2011 10:19:47 PM - Software Distribution Service 3.0 RP60: 3/13/2011 10:17:36 AM - System Checkpoint RP61: 3/14/2011 5:25:07 PM - Avg Update RP62: 3/14/2011 5:25:57 PM - Avg Update RP63: 3/15/2011 5:51:02 PM - System Checkpoint RP64: 3/15/2011 10:34:46 PM - Software Distribution Service 3.0 RP65: 3/17/2011 5:46:13 PM - System Checkpoint RP66: 3/18/2011 10:44:34 PM - System Checkpoint RP67: 3/20/2011 8:11:22 PM - System Checkpoint RP68: 3/21/2011 6:17:59 PM - Installed EmSense RP69: 3/23/2011 5:48:40 PM - System Checkpoint RP70: 3/23/2011 10:47:20 PM - Software Distribution Service 3.0 RP71: 3/25/2011 8:25:55 AM - System Checkpoint RP72: 3/26/2011 8:09:01 PM - System Checkpoint RP73: 3/27/2011 3:08:23 PM - Installed QuickTime RP74: 3/28/2011 5:45:17 PM - System Checkpoint RP75: 3/29/2011 5:46:49 PM - System Checkpoint RP76: 3/30/2011 7:27:40 PM - System Checkpoint RP77: 4/1/2011 5:37:04 PM - System Checkpoint RP78: 4/1/2011 6:27:13 PM - Removed EmSense RP79: 4/1/2011 6:27:35 PM - Installed EmSense RP80: 4/2/2011 6:36:22 PM - System Checkpoint RP81: 4/3/2011 7:54:00 PM - System Checkpoint RP82: 4/5/2011 5:59:00 PM - System Checkpoint RP83: 4/6/2011 7:36:07 PM - System Checkpoint RP84: 4/8/2011 2:01:45 PM - System Checkpoint RP85: 4/9/2011 5:49:49 PM - System Checkpoint RP86: 4/10/2011 6:14:04 PM - System Checkpoint RP87: 4/12/2011 5:48:55 PM - System Checkpoint RP88: 4/14/2011 3:00:29 AM - Software Distribution Service 3.0 RP89: 4/14/2011 10:55:36 PM - Software Distribution Service 3.0 RP90: 4/17/2011 8:44:19 AM - System Checkpoint RP91: 4/18/2011 5:44:46 PM - System Checkpoint . ==== Installed Programs ====================== . . Ad-Aware Adobe AIR Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Community Help Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Media Player Adobe Photoshop CS5 Adobe Reader X (10.0.1) Adobe Shockwave Player 11.5 Amazon MP3 Downloader 1.0.9 Andrea VoiceCenter AOLIcon Apple Application Support Apple Software Update ArcSoft VideoImpression 2 ArtistScope Plugin FX AVG Free 9.0 Banctec Service Agreement Broadcom Management Programs BufferChm Bushnell ImageView CCleaner Cisco Network Magic Conexant HDA D110 MDC V.92 Modem Corel Photo Album 6 Coupon Printer for Windows Creative MediaSource Critical Update for Windows Media Player 11 (KB959772) CustomerResearchQFolder Dell Digital Jukebox Driver Dell Support 3.1 Destinations DeviceManagementQFolder Digital Content Portal Digital Line Detect DivX Content Uploader DivX Converter DivX Plus DirectShow Filters DivX Setup dj_taplugin dj6980 Documentation & Support Launcher EducateU ELIcon EmSense EmSense 1.14.3 ESET Online Scanner v3 ESPNMotion eSupportQFolder Games, Music, & Photos Launcher GemMaster Mystic Google Chrome High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Deskjet 6900 series HP Extended Capabilities 6.0 HP Imaging Device Functions 6.0 HP Photosmart Essential HP Product Assistant HP Solution Center and Imaging Support Tools 6.0 HP Update hpf_ProductContext HPProductAssistant Intel® PROSet/Wireless Software Invoke Solutions Participant 6.2.0.1452 Java Auto Updater Java™ 6 Update 20 Java™ 6 Update 24 K-Lite Codec Pack 5.9.0 (Basic) Learn2 Player (Uninstall Only) LP6980_Help LP6980Trb Macromedia Dreamweaver 4 Macromedia Extension Manager Malwarebytes' Anti-Malware MarketResearch mCore MCU mDrWiFi mHlpDell Microsoft .NET Framework 1.0 Hotfix (KB953295) Microsoft .NET Framework 1.0 Hotfix (KB979904) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2416447) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable - KB2467175 Microsoft_VC80_ATL_x86 Microsoft_VC80_CRT_x86 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFCLOC_x86 Microsoft_VC90_ATL_x86 Microsoft_VC90_CRT_x86 Microsoft_VC90_MFC_x86 mIWA Mixer mLogView mMHouse Modem Helper Move Media Player Mozilla Firefox 4.0 (x86 en-US) mPfMgr mPfWiz mProSafe mSSO MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB954459) Musicmatch for Windows Media Player Musicmatch® Jukebox mWlsSafe mWMI mXML MyPoints Point Finder MyPoints Toolbar 2.0 mZConfig NetWaiting Network Magic NetZeroInstallers NVIDIA Drivers Otto PC Connectivity Solution PC Matic [removed] PC VGA Camer@ Plus PDF Settings CS5 PhotoSuite 4 (Remove Only) PowerDVD 5.7 Pure Networks Platform QuickSet QuickTime Readme RealPlayer Basic SAMSUNG Mobile Composite Device Software SAMSUNG Mobile Modem Driver Set Samsung Mobile phone USB driver Software SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software Samsung New PC Studio SamsungConnectivityCableDriver Search Assist Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2466156) Security Update for 2007 Microsoft Office System (KB2509488) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft Office Excel 2007 (KB2464583) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2464594) Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2491683) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Skype web features Skype™ 4.1 SolutionCenter Sonic Audio module Sonic DLA Sonic Encoders Sonic MyDVD LE Sonic RecordNow Copy Sonic RecordNow Data Sonic Update Manager Sound Blaster ADVANCED MB Drivers Sound Blaster Audigy ADVANCED MB Demo Status Synaptics Pointing Device Driver TBS WMP Plug-in TrayApp Unity Web Player Unload Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Windows (KB971513) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB980182) Update for Windows Media Player 10 (KB910393) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update Installer for WildTangent Games App Update Rollup 2 for Windows XP Media Center Edition 2005 URL Assistant User Support VC80CRTRedist - 8.0.50727.4053 Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebEx Support Manager for Internet Explorer WebFldrs XP WebReg WIDCOMM Bluetooth Software WildTangent Games WildTangent Games App (Dell Games) WildTangent Web Driver Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0) Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0) Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] Windows Media Player 11 Windows Media Player Firefox Plugin Windows Presentation Foundation Windows XP Media Center Edition 2005 KB2502898 Windows XP Media Center Edition 2005 KB908246 Windows XP Media Center Edition 2005 KB925766 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 WinZip 15.0 WordPerfect Office 12 XML Paper Specification Shared Components Pack 1.0 Yahoo! BrowserPlus 2.9.8 Yahoo! Install Manager Yahoo! Software Update Yahoo! Toolbar . ==== Event Viewer Messages From Past Week ======== . 4/14/2011 8:19:05 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep 4/14/2011 5:41:33 PM, error: Service Control Manager [7034] - The HP Port Resolver service terminated unexpectedly. It has done this 1 time(s). 4/14/2011 5:18:32 PM, error: DCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool. 4/14/2011 10:47:07 PM, error: Srv [2000] - The server's call to a system service failed unexpectedly. . ==== End Of File ===========================
mickey7,

I'm not really seeing any malware on there. However you have some old Java components.

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.

Once you've pasted the log… go ahead and get an online scan.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
The Java scan: JavaRa 1.16 Removal Log. Report follows after line. ———————————— The JavaRa removal process was started on Tue Apr 19 23:17:34 2011 Found and removed: C:\Program Files\Java\j2re1.4.2_03 Found and removed: C:\Program Files\Java\jre1.6.0_20 Found and removed: C:\Documents and Settings\KM\Application Data\Sun\Java\jre1.6.0_14 Found and removed: C:\Documents and Settings\KM\Application Data\Sun\Java\jre1.6.0_15 Found and removed: C:\Documents and Settings\KM\Application Data\Sun\Java\jre1.6.0_17 Found and removed: C:\Documents and Settings\KM\Application Data\Sun\Java\jre1.6.0_20 Found and removed: C:\Documents and Settings\KM\Application Data\Sun\Java\jre1.6.0_21 Found and removed: C:\Documents and Settings\KM\Application Data\Sun\Java\jre1.6.0_22 Found and removed: C:\Documents and Settings\KM\Application Data\Sun\Java\jre1.6.0_23 Found and removed: Applications\java.exe Found and removed: Applications\javaw.exe Found and removed: JavaPlugin.FamilyVersionSupport Found and removed: Installer\Products\4EA42A62D9304AC4784BF2381206020F Found and removed: CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC} Found and removed: CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} Found and removed: CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBB} Found and removed: CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC} Found and removed: JavaScript Found and removed: JavaScript Author Found and removed: JavaScript1.1 Found and removed: JavaScript1.1 Author Found and removed: JavaScript1.2 Found and removed: JavaScript1.2 Author Found and removed: Software\Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB} Found and removed: Software\Classes\JavaPlugin.160_20 Found and removed: Software\JavaSoft\Java Update Found and removed: Software\JavaSoft\Java Runtime Environment\1.5.0_08 Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_13 Found and removed: Software\JavaSoft\Java2D\1.5.0_08 Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC} Found and removed: SOFTWARE\Classes\JavaPlugin Found and removed: SOFTWARE\Classes\JavaPlugin.142_03 Found and removed: SOFTWARE\Classes\JavaPlugin.150_08 Found and removed: SOFTWARE\Classes\JavaPlugin.160_20 Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.4.2.0 Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_20 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_20 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_20 Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500} Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_20\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3412062B02 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3412062B03 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3412062F00 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3612062A00 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3612062B02 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3612062B03 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0357E4991DA5FF14F9615B3612062F00 Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.1 Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.1.1 Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.1.3 Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.2 Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.2.1 Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.3 Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.3.1 Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.4 Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.4.1 Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.5 JavaRa 1.16 Removal Log. Report follows after line. ———————————— The JavaRa removal process was started on Tue Apr 19 23:18:05 2011 Found and removed: CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA} ———————————— Finished reporting.
eset scan: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=12a4562ec303454fa9dd7c3ecdb0186c # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-05-22 10:41:05 # local_time=2010-05-22 06:41:05 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 27258932 27258932 0 0 # compatibility_mode=1024 16777191 100 0 12324029 12324029 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=77329 # found=13 # cleaned=0 # scan_time=6897 C:\Documents and Settings\KM\My Documents\floppystuff\buttons.exe probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I C:\Documents and Settings\KM\My Documents\floppystuff\heat.exe probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I C:\Documents and Settings\KM\My Documents\floppystuff\MONEY.EXE probably a variant of Win32/Hoax.Agent application 00000000000000000000000000000000 I C:\Documents and Settings\KM\My Documents\floppystuff\POSTAL.EXE probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I C:\Documents and Settings\KM\My Documents\floppystuff\viagra.exe probably a variant of Win32/TrojanDownloader.Zlob trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\KM\Application Data\Mozilla\Firefox\Core\install.rdf.vir JS/Spy.FFSpy.A trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP189\A0021028.exe probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP189\A0021080.exe probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP189\A0021110.EXE probably a variant of Win32/Hoax.Agent application 00000000000000000000000000000000 I C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP189\A0021123.EXE probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP189\A0021151.exe probably a variant of Win32/TrojanDownloader.Zlob trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP240\A0023557.exe JS/Spy.FFSpy.A trojan 00000000000000000000000000000000 I G:\gusetupnew.exe Win32/Induc virus 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6427 # api_version=3.0.2 # EOSSerial=12a4562ec303454fa9dd7c3ecdb0186c # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-04-20 05:22:39 # local_time=2011-04-20 01:22:39 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 55967988 55967988 0 0 # compatibility_mode=1024 16777191 100 0 41033085 41033085 0 0 # compatibility_mode=8192 67108863 100 0 28623100 28623100 0 0 # scanned=89338 # found=0 # cleaned=0 # scan_time=6733
Sorry for the delay. Seems a bit better. Firefox still takes forever and a day to open. Can't figure why. Also I do now have a jusched error that pops up on boot. any suggestions on that?
mickey7,

Please let me have a different log and I'll see if we can help that.

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
OLT.txt:

OTL logfile created on: 4/23/2011 5:01:44 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Kathryne Miller\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 6.71 Gb Free Space | 18.03% Space Free | Partition Type: NTFS
Drive D: | 12.55 Gb Total Space | 1.55 Gb Free Space | 12.38% Space Free | Partition Type: NTFS
Drive G: | 74.51 Gb Total Space | 15.89 Gb Free Space | 21.32% Space Free | Partition Type: FAT32

Computer Name: MICKEY7 | User Name: Kathryne Miller | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Kathryne Miller\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\CSHelper.exe ()
PRC - C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
PRC - C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\PixArt\PAC7302\Monitor.exe (PixArt Imaging Incorporation)
PRC - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\gearsec.exe (GEAR Software)
PRC - C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Kathryne Miller\desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (getPlusHelper) getPlus® – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (CSHelper) – C:\WINDOWS\system32\CSHelper.exe ()
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (Creative Labs Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)


========== Driver Services (SafeList) ==========

DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (IrBus) – C:\WINDOWS\system32\drivers\irbus.sys (Microsoft Corporation)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (PAC7302) – C:\WINDOWS\system32\drivers\PAC7302.SYS (PixArt Imaging Inc.)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTSERIAL) – C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (AngelUsb) – C:\WINDOWS\system32\drivers\AngelUsb.sys (Lumanate, Inc.)
DRV - (monfilt) – C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (CTUSFSYN) – C:\WINDOWS\system32\drivers\ctusfsyn.sys (Creative Technology Ltd.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========


FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2011/04/08 11:10:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/11/24 18:23:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/03/05 00:46:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/03/05 00:46:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/27 15:09:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/27 15:09:06 | 000,000,000 | —D | M]

[2009/05/03 10:52:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Extensions
[2011/04/08 16:33:23 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions
[2010/04/27 18:05:14 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/23 17:32:36 | 000,000,000 | —D | M] (MyPoints Point Finder) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\{51ef49d2-624b-4194-8b97-1c468e9b0efe}
[2011/03/25 08:43:50 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/03/06 11:08:12 | 000,000,000 | —D | M] ("Amazon Toolbar") – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\[removed]
[2011/03/14 19:19:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\[removed]
[2011/03/24 17:30:27 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/10/17 08:59:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/23 23:55:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/15 20:12:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/03/18 13:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2009/01/15 14:53:03 | 000,616,448 | —- | M] (ArtistScope) – C:\Program Files\Mozilla Firefox\plugins\npArtistScope42.dll
[2009/02/02 02:06:56 | 000,211,456 | —- | M] (ArtistScope) – C:\Program Files\Mozilla Firefox\plugins\npArtistScopeDRM11.dll
[2009/11/19 17:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2011/02/02 22:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 17:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2009/06/11 22:11:18 | 000,221,184 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2010/05/22 22:10:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Freecause Toolbar BHO) - {614BDA1F-9BEF-4CD1-BDE4-FA4804929B4A} - C:\Program Files\MyPoints Point Finder\Toolbar.dll ()
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (MyPoints Point Finder) - {89A2510A-B4B6-4683-BEC9-1B96700BC7F1} - C:\Program Files\MyPoints Point Finder\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (MyPoints Point Finder) - {89A2510A-B4B6-4683-BEC9-1B96700BC7F1} - C:\Program Files\MyPoints Point Finder\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
O4 - HKLM..\Run: [CTSVolFE.exe] C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [PC Pitstop PC Matic Reminder] C:\Program Files\PCPitstop\PC Matic\Reminder-PCMatic.exe (PC Pitstop LLC)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: facebook.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: hulu.com ([www] http in Trusted sites)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {445F47D7-E043-4BD6-82EB-7A1BD0EBA773} http://www.psapoll.com/CopyGuardIE.cab (CopyGuardCtrl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {A7846ED2-9DE6-4E8A-B116-A8ACEBFA7DB1} http://rms2.invokesolutions.com/events/bin…1452/MILive.cab (Invoke Solutions MILiveParticipantPadHelper Control)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 05:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{704431e8-dbb7-11de-aaac-0016cffb8b30}\Shell - "" = AutoRun
O33 - MountPoints2\{704431e8-dbb7-11de-aaac-0016cffb8b30}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{704431e8-dbb7-11de-aaac-0016cffb8b30}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/04/23 17:00:25 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kathryne Miller\Desktop\OTL.exe
[2011/04/19 23:23:42 | 002,322,184 | —- | C] (ESET) – C:\Documents and Settings\Kathryne Miller\Desktop\esetsmartinstaller_enu.exe
[2011/04/19 23:17:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Desktop\JavaRa
[2011/04/13 23:17:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Application Data\Apple Computer
[2011/04/08 16:36:51 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbser.sys
[2011/04/01 18:27:37 | 000,000,000 | —D | C] – C:\Program Files\EmSense
[2011/04/01 18:27:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\EmSense
[2011/04/01 18:24:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Application Data\EmSense
[2011/03/27 15:08:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/03/27 15:08:28 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/03/27 15:08:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2011/03/27 15:07:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/03/27 15:07:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Apple
[2011/03/27 15:07:41 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/03/27 15:07:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2011/03/27 15:07:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Apple Computer
[2009/10/02 19:58:06 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\vaodp202.dll

========== Files - Modified Within 30 Days ==========

[2011/04/23 17:00:24 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kathryne Miller\Desktop\OTL.exe
[2011/04/23 16:53:25 | 000,000,000 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\prvlcl.dat
[2011/04/23 16:41:56 | 075,045,523 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/04/23 16:38:48 | 000,062,940 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/04/23 16:38:48 | 000,044,184 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2011/04/23 16:38:31 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/04/23 16:38:27 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/23 16:37:45 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/22 23:10:00 | 000,001,018 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-385954157-1898415747-3273646295-1005UA.job
[2011/04/22 22:20:00 | 000,000,442 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{B9AA762D-6540-4CC0-BF6A-CA3B89302172}.job
[2011/04/21 18:10:00 | 000,000,966 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-385954157-1898415747-3273646295-1005Core.job
[2011/04/20 02:00:01 | 000,000,362 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-MICKEY7-Kathryne Miller.job
[2011/04/19 23:23:57 | 002,322,184 | —- | M] (ESET) – C:\Documents and Settings\Kathryne Miller\Desktop\esetsmartinstaller_enu.exe
[2011/04/19 23:13:30 | 000,159,877 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\JavaRa.zip
[2011/04/19 23:11:05 | 000,002,358 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\Google Chrome.lnk
[2011/04/19 23:11:05 | 000,002,336 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/04/19 18:12:38 | 000,625,664 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\dds.scr
[2011/04/15 18:52:05 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/04/14 08:22:32 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\rp_stats.dat
[2011/04/14 08:22:32 | 000,000,044 | —- | M] () – C:\WINDOWS\System32\rp_rules.dat
[2011/04/14 08:19:58 | 003,578,208 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/14 03:13:22 | 000,443,070 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/14 03:13:22 | 000,072,170 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/10 22:34:59 | 000,001,757 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Converter.lnk
[2011/04/10 22:34:58 | 000,001,499 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\DivX Movies.lnk
[2011/04/08 16:39:30 | 000,055,808 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/07 03:59:03 | 000,016,432 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2011/04/03 22:59:04 | 000,000,412 | —- | M] () – C:\Documents and Settings\Kathryne Miller\My Documents\spider.sav
[2011/04/01 18:27:43 | 000,000,788 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Update EmSense 1.14.3.lnk
[2011/03/27 15:08:52 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2011/03/27 15:07:45 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/24 17:30:34 | 000,000,742 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/24 17:30:34 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

========== Files Created - No Company Name ==========

[2011/04/19 23:13:38 | 000,159,877 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Desktop\JavaRa.zip
[2011/04/19 18:12:45 | 000,625,664 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Desktop\dds.scr
[2011/04/14 08:22:32 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/04/14 08:22:32 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/04/01 18:27:43 | 000,000,788 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Update EmSense 1.14.3.lnk
[2011/03/27 15:08:52 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2011/03/27 15:07:45 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/27 15:07:42 | 000,001,830 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/03/24 17:30:33 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2010/08/15 09:09:38 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/08/15 09:09:38 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/08/15 09:09:01 | 000,002,528 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\$_hpcst$.hpc
[2010/05/30 08:12:17 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2010/05/09 17:55:34 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.INI
[2010/03/06 15:16:16 | 000,000,000 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\prvlcl.dat
[2010/03/06 13:44:36 | 000,266,240 | —- | C] () – C:\WINDOWS\System32\CSHelper.exe
[2009/10/11 16:24:25 | 000,019,523 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\axep.db
[2009/10/11 16:24:25 | 000,019,401 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\ibyka.ban
[2009/10/11 16:24:25 | 000,016,950 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\yfofizyw.bat
[2009/10/11 16:24:25 | 000,016,206 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\synasexoza.scr
[2009/10/11 16:24:25 | 000,015,931 | —- | C] () – C:\Documents and Settings\All Users\Application Data\epidi.db
[2009/10/11 16:24:25 | 000,013,581 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\qily.dl
[2009/10/11 16:24:25 | 000,010,617 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\ekyq.db
[2009/10/11 16:24:25 | 000,010,051 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ilig.lib
[2009/10/02 19:58:07 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\aodp2022.dll
[2009/10/02 19:58:07 | 000,290,816 | —- | C] () – C:\WINDOWS\System32\aodp2023.dll
[2009/10/02 19:58:07 | 000,227,200 | —- | C] () – C:\WINDOWS\System32\drivers\aodp202.sys
[2009/10/02 19:58:07 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\daodp202.dll
[2009/10/02 19:58:07 | 000,015,584 | —- | C] () – C:\WINDOWS\aodp202.ini
[2009/10/02 19:58:06 | 000,020,480 | —- | C] () – C:\WINDOWS\daodp202.exe
[2009/10/02 19:55:41 | 000,028,747 | —- | C] () – C:\WINDOWS\System32\KMemoryMMX.dll
[2009/10/02 19:55:41 | 000,024,653 | —- | C] () – C:\WINDOWS\System32\KMemoryPIII.dll
[2009/10/02 19:55:41 | 000,024,632 | —- | C] () – C:\WINDOWS\System32\KMemory.dll
[2009/10/02 19:55:41 | 000,020,546 | —- | C] () – C:\WINDOWS\System32\KMemoryC.dll
[2009/10/02 19:55:19 | 000,000,002 | —- | C] () – C:\WINDOWS\PhotoSuite.ini
[2009/10/02 19:55:16 | 000,458,752 | —- | C] () – C:\WINDOWS\System32\Fpl.dll
[2009/10/02 19:55:16 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\EnrouteStitch.dll
[2009/10/02 19:55:16 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\CPUINF32.DLL
[2009/10/02 19:55:15 | 000,332,800 | —- | C] () – C:\WINDOWS\System32\FPXLIB.DLL
[2009/10/02 19:55:15 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\JPEGLIB.DLL
[2009/10/01 18:47:13 | 000,040,129 | —- | C] () – C:\WINDOWS\iccsigs.dat
[2009/08/04 19:38:58 | 008,892,928 | —- | C] () – C:\Documents and Settings\All Users\Application Data\atscie.msi
[2009/07/08 20:24:20 | 000,000,347 | —- | C] () – C:\WINDOWS\CTWave32.INI
[2009/07/08 20:24:19 | 000,000,029 | —- | C] () – C:\WINDOWS\sfbm.INI
[2009/07/06 17:22:47 | 000,022,629 | —- | C] () – C:\WINDOWS\System32\CiFilter.ini
[2009/05/14 17:27:18 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/05/05 14:13:59 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\CFD65FB0F8.sys
[2009/05/03 14:11:46 | 000,165,376 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/05/03 14:11:43 | 000,755,027 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/05/03 14:11:43 | 000,159,839 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/05/03 14:11:42 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/05/03 14:02:27 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/05/03 13:56:56 | 000,000,322 | —- | C] () – C:\WINDOWS\System32\Remover.ini
[2009/05/03 13:04:25 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2009/05/03 13:04:15 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/05/03 12:51:36 | 000,001,450 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/05/03 12:46:13 | 000,105,049 | —- | C] () – C:\WINDOWS\HPFins09.dat
[2009/05/03 12:46:13 | 000,003,732 | —- | C] () – C:\WINDOWS\hpfmdl09.dat
[2007/10/25 17:26:10 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/03/20 16:44:02 | 000,000,566 | —- | C] () – C:\WINDOWS\System32\SP7302.ini
[2006/09/12 18:50:32 | 000,055,808 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/24 11:09:56 | 000,061,678 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\PFP120JPR.{PB
[2006/08/24 11:09:56 | 000,012,358 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\PFP120JCM.{PB
[2006/08/24 11:09:21 | 000,004,808 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/08/24 11:09:21 | 000,000,056 | RHS- | C] () – C:\WINDOWS\System32\F8B05FD6CF.sys
[2006/08/19 17:29:06 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/07/31 20:29:29 | 000,000,138 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\fusioncache.dat
[2006/07/25 15:26:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/07/25 15:14:21 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/07/25 15:12:31 | 000,712,704 | —- | C] () – C:\WINDOWS\System32\DellSystemRestore.dll
[2006/07/25 15:08:54 | 000,000,280 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/07/25 15:07:36 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/07/25 15:00:22 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/07/25 14:40:27 | 000,044,184 | —- | C] () – C:\WINDOWS\System32\nvModes.dat
[2006/07/25 13:32:46 | 000,102,480 | —- | C] () – C:\WINDOWS\System32\EzRating.dll
[2006/07/25 13:32:46 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\EzdCoIns.dll
[2006/07/25 13:29:44 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2006/07/25 13:29:42 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/07/25 13:29:42 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/07/25 13:29:32 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/07/25 13:29:24 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/07/25 13:29:15 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2006/07/25 13:28:55 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2006/07/25 13:28:55 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/07/25 13:28:52 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2006/07/25 13:28:27 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/07/25 13:28:01 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2006/07/25 13:23:00 | 000,000,391 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/05/24 19:16:22 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2005/08/16 05:48:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/16 05:38:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/16 05:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 05:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/16 05:27:59 | 003,578,208 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/16 05:18:35 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/08/16 05:18:33 | 000,443,070 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/16 05:18:33 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005/08/16 05:18:33 | 000,072,170 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/16 05:18:33 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005/08/16 05:18:32 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005/08/16 05:18:30 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/08/16 05:18:28 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/08/16 05:18:23 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005/08/16 05:18:23 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005/08/16 05:18:15 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005/08/16 05:18:08 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2005/08/05 15:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/06/22 13:37:46 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/10/26 19:52:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/12/20 10:25:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/14 17:26:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2005/08/16 21:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2009/05/03 12:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2010/08/15 09:10:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/12/25 10:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/10/18 08:47:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstopDat
[2010/08/23 20:32:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/05/30 08:12:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/12/31 17:27:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2011/01/29 17:47:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/07/19 19:36:13 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/11/30 10:24:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\ActiSku
[2010/01/02 12:33:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Amazon
[2010/05/24 19:42:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\AVG9
[2011/03/05 00:47:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\DDMSettings
[2011/04/01 18:24:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\EmSense
[2009/12/13 18:35:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\FCTB000060497
[2009/06/21 22:56:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\GlarySoft
[2009/05/05 13:45:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\KompoZer
[2010/08/15 09:10:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\PC Suite
[2009/05/05 14:09:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Sam Francke
[2010/08/15 09:08:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Samsung
[2009/09/03 16:25:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Viewpoint
[2009/05/05 15:28:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\VSO
[2011/04/23 16:38:31 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/04/22 22:20:00 | 000,000,442 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{B9AA762D-6540-4CC0-BF6A-CA3B89302172}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/04/23 16:37:40 | 000,194,188 | —- | M] () – C:\aaw7boot.log
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/07/12 22:34:07 | 000,000,209 | —- | M] () – C:\Boot.bak
[2010/12/25 12:39:31 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/05/22 22:11:46 | 000,015,882 | —- | M] () – C:\ComboFix.txt
[2010/05/19 17:45:15 | 006,000,868 | —- | M] () – C:\ComboFix.zip
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/07/25 14:37:44 | 000,006,942 | RH– | M] () – C:\dell.sdr
[2006/08/22 18:30:36 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/07/25 15:08:43 | 000,000,827 | -H– | M] () – C:\IPH.PH
[2011/04/19 23:19:14 | 000,022,994 | —- | M] () – C:\JavaRa.log
[2010/05/21 18:57:00 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/10 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/06 18:10:04 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/04/23 16:37:40 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/05/21 18:56:26 | 000,000,490 | —- | M] () – C:\rkill.log
[2009/09/30 21:15:34 | 000,036,870 | —- | M] () – C:\ScanImage01.jpg
[2006/07/25 15:08:51 | 000,000,071 | —- | M] () – C:\SystemInfo.ini
[2010/05/22 23:42:50 | 000,004,608 | -HS- | M] () – C:\Thumbs.db
[2009/07/04 18:56:46 | 000,000,510 | —- | M] () – C:\updatedatfix.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/16 05:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/10/14 22:41:46 | 000,072,192 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2006/07/31 20:52:03 | 000,001,746 | -H– | M] () – C:\Documents and Settings\Kathryne Miller\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/08/16 05:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/16 05:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/16 05:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2006/07/25 15:02:47 | 000,001,760 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Creative MediaSource Go!.lnk
[2009/05/06 18:17:37 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2009/05/03 13:06:41 | 000,000,984 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\HP Solution Center.lnk
[2006/07/25 15:15:45 | 000,002,883 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Program Updates.lnk
[2009/05/06 18:17:37 | 000,001,563 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2005/08/16 05:43:10 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2009/05/03 10:44:28 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
[2011/01/29 17:41:04 | 000,001,732 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\WinZip.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2009/10/11 16:24:25 | 000,010,878 | —- | M] () – C:\WINDOWS\system32\uqaj.db

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2003/03/12 20:44:04 | 000,013,056 | —- | M] () – C:\WINDOWS\aodp202.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-20 21:30:28

< End of report >
Extras.txt:

OTL logfile created on: 4/23/2011 5:01:44 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Kathryne Miller\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 6.71 Gb Free Space | 18.03% Space Free | Partition Type: NTFS
Drive D: | 12.55 Gb Total Space | 1.55 Gb Free Space | 12.38% Space Free | Partition Type: NTFS
Drive G: | 74.51 Gb Total Space | 15.89 Gb Free Space | 21.32% Space Free | Partition Type: FAT32

Computer Name: MICKEY7 | User Name: Kathryne Miller | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Kathryne Miller\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\CSHelper.exe ()
PRC - C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
PRC - C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\PixArt\PAC7302\Monitor.exe (PixArt Imaging Incorporation)
PRC - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\gearsec.exe (GEAR Software)
PRC - C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Kathryne Miller\desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (getPlusHelper) getPlus® – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (CSHelper) – C:\WINDOWS\system32\CSHelper.exe ()
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (Creative Labs Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)


========== Driver Services (SafeList) ==========

DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (IrBus) – C:\WINDOWS\system32\drivers\irbus.sys (Microsoft Corporation)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (PAC7302) – C:\WINDOWS\system32\drivers\PAC7302.SYS (PixArt Imaging Inc.)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTSERIAL) – C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (AngelUsb) – C:\WINDOWS\system32\drivers\AngelUsb.sys (Lumanate, Inc.)
DRV - (monfilt) – C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (CTUSFSYN) – C:\WINDOWS\system32\drivers\ctusfsyn.sys (Creative Technology Ltd.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========


FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2011/04/08 11:10:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/11/24 18:23:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/03/05 00:46:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/03/05 00:46:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/27 15:09:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/27 15:09:06 | 000,000,000 | —D | M]

[2009/05/03 10:52:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Extensions
[2011/04/08 16:33:23 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions
[2010/04/27 18:05:14 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/23 17:32:36 | 000,000,000 | —D | M] (MyPoints Point Finder) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\{51ef49d2-624b-4194-8b97-1c468e9b0efe}
[2011/03/25 08:43:50 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/03/06 11:08:12 | 000,000,000 | —D | M] ("Amazon Toolbar") – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\[removed]
[2011/03/14 19:19:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\[removed]
[2011/03/24 17:30:27 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/10/17 08:59:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/23 23:55:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/15 20:12:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/03/18 13:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2009/01/15 14:53:03 | 000,616,448 | —- | M] (ArtistScope) – C:\Program Files\Mozilla Firefox\plugins\npArtistScope42.dll
[2009/02/02 02:06:56 | 000,211,456 | —- | M] (ArtistScope) – C:\Program Files\Mozilla Firefox\plugins\npArtistScopeDRM11.dll
[2009/11/19 17:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2011/02/02 22:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 17:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2009/06/11 22:11:18 | 000,221,184 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2010/05/22 22:10:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Freecause Toolbar BHO) - {614BDA1F-9BEF-4CD1-BDE4-FA4804929B4A} - C:\Program Files\MyPoints Point Finder\Toolbar.dll ()
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (MyPoints Point Finder) - {89A2510A-B4B6-4683-BEC9-1B96700BC7F1} - C:\Program Files\MyPoints Point Finder\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (MyPoints Point Finder) - {89A2510A-B4B6-4683-BEC9-1B96700BC7F1} - C:\Program Files\MyPoints Point Finder\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
O4 - HKLM..\Run: [CTSVolFE.exe] C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [PC Pitstop PC Matic Reminder] C:\Program Files\PCPitstop\PC Matic\Reminder-PCMatic.exe (PC Pitstop LLC)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: facebook.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: hulu.com ([www] http in Trusted sites)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {445F47D7-E043-4BD6-82EB-7A1BD0EBA773} http://www.psapoll.com/CopyGuardIE.cab (CopyGuardCtrl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {A7846ED2-9DE6-4E8A-B116-A8ACEBFA7DB1} http://rms2.invokesolutions.com/events/bin…1452/MILive.cab (Invoke Solutions MILiveParticipantPadHelper Control)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 05:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{704431e8-dbb7-11de-aaac-0016cffb8b30}\Shell - "" = AutoRun
O33 - MountPoints2\{704431e8-dbb7-11de-aaac-0016cffb8b30}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{704431e8-dbb7-11de-aaac-0016cffb8b30}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/04/23 17:00:25 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kathryne Miller\Desktop\OTL.exe
[2011/04/19 23:23:42 | 002,322,184 | —- | C] (ESET) – C:\Documents and Settings\Kathryne Miller\Desktop\esetsmartinstaller_enu.exe
[2011/04/19 23:17:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Desktop\JavaRa
[2011/04/13 23:17:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Application Data\Apple Computer
[2011/04/08 16:36:51 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbser.sys
[2011/04/01 18:27:37 | 000,000,000 | —D | C] – C:\Program Files\EmSense
[2011/04/01 18:27:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\EmSense
[2011/04/01 18:24:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Application Data\EmSense
[2011/03/27 15:08:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/03/27 15:08:28 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/03/27 15:08:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2011/03/27 15:07:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/03/27 15:07:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Apple
[2011/03/27 15:07:41 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/03/27 15:07:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2011/03/27 15:07:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Apple Computer
[2009/10/02 19:58:06 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\vaodp202.dll

========== Files - Modified Within 30 Days ==========

[2011/04/23 17:00:24 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kathryne Miller\Desktop\OTL.exe
[2011/04/23 16:53:25 | 000,000,000 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\prvlcl.dat
[2011/04/23 16:41:56 | 075,045,523 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/04/23 16:38:48 | 000,062,940 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/04/23 16:38:48 | 000,044,184 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2011/04/23 16:38:31 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/04/23 16:38:27 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/23 16:37:45 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/22 23:10:00 | 000,001,018 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-385954157-1898415747-3273646295-1005UA.job
[2011/04/22 22:20:00 | 000,000,442 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{B9AA762D-6540-4CC0-BF6A-CA3B89302172}.job
[2011/04/21 18:10:00 | 000,000,966 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-385954157-1898415747-3273646295-1005Core.job
[2011/04/20 02:00:01 | 000,000,362 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-MICKEY7-Kathryne Miller.job
[2011/04/19 23:23:57 | 002,322,184 | —- | M] (ESET) – C:\Documents and Settings\Kathryne Miller\Desktop\esetsmartinstaller_enu.exe
[2011/04/19 23:13:30 | 000,159,877 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\JavaRa.zip
[2011/04/19 23:11:05 | 000,002,358 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\Google Chrome.lnk
[2011/04/19 23:11:05 | 000,002,336 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/04/19 18:12:38 | 000,625,664 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\dds.scr
[2011/04/15 18:52:05 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/04/14 08:22:32 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\rp_stats.dat
[2011/04/14 08:22:32 | 000,000,044 | —- | M] () – C:\WINDOWS\System32\rp_rules.dat
[2011/04/14 08:19:58 | 003,578,208 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/14 03:13:22 | 000,443,070 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/14 03:13:22 | 000,072,170 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/10 22:34:59 | 000,001,757 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Converter.lnk
[2011/04/10 22:34:58 | 000,001,499 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\DivX Movies.lnk
[2011/04/08 16:39:30 | 000,055,808 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/07 03:59:03 | 000,016,432 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2011/04/03 22:59:04 | 000,000,412 | —- | M] () – C:\Documents and Settings\Kathryne Miller\My Documents\spider.sav
[2011/04/01 18:27:43 | 000,000,788 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Update EmSense 1.14.3.lnk
[2011/03/27 15:08:52 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2011/03/27 15:07:45 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/24 17:30:34 | 000,000,742 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/24 17:30:34 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

========== Files Created - No Company Name ==========

[2011/04/19 23:13:38 | 000,159,877 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Desktop\JavaRa.zip
[2011/04/19 18:12:45 | 000,625,664 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Desktop\dds.scr
[2011/04/14 08:22:32 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/04/14 08:22:32 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/04/01 18:27:43 | 000,000,788 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Update EmSense 1.14.3.lnk
[2011/03/27 15:08:52 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2011/03/27 15:07:45 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/27 15:07:42 | 000,001,830 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/03/24 17:30:33 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2010/08/15 09:09:38 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/08/15 09:09:38 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/08/15 09:09:01 | 000,002,528 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\$_hpcst$.hpc
[2010/05/30 08:12:17 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2010/05/09 17:55:34 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.INI
[2010/03/06 15:16:16 | 000,000,000 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\prvlcl.dat
[2010/03/06 13:44:36 | 000,266,240 | —- | C] () – C:\WINDOWS\System32\CSHelper.exe
[2009/10/11 16:24:25 | 000,019,523 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\axep.db
[2009/10/11 16:24:25 | 000,019,401 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\ibyka.ban
[2009/10/11 16:24:25 | 000,016,950 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\yfofizyw.bat
[2009/10/11 16:24:25 | 000,016,206 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\synasexoza.scr
[2009/10/11 16:24:25 | 000,015,931 | —- | C] () – C:\Documents and Settings\All Users\Application Data\epidi.db
[2009/10/11 16:24:25 | 000,013,581 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\qily.dl
[2009/10/11 16:24:25 | 000,010,617 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\ekyq.db
[2009/10/11 16:24:25 | 000,010,051 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ilig.lib
[2009/10/02 19:58:07 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\aodp2022.dll
[2009/10/02 19:58:07 | 000,290,816 | —- | C] () – C:\WINDOWS\System32\aodp2023.dll
[2009/10/02 19:58:07 | 000,227,200 | —- | C] () – C:\WINDOWS\System32\drivers\aodp202.sys
[2009/10/02 19:58:07 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\daodp202.dll
[2009/10/02 19:58:07 | 000,015,584 | —- | C] () – C:\WINDOWS\aodp202.ini
[2009/10/02 19:58:06 | 000,020,480 | —- | C] () – C:\WINDOWS\daodp202.exe
[2009/10/02 19:55:41 | 000,028,747 | —- | C] () – C:\WINDOWS\System32\KMemoryMMX.dll
[2009/10/02 19:55:41 | 000,024,653 | —- | C] () – C:\WINDOWS\System32\KMemoryPIII.dll
[2009/10/02 19:55:41 | 000,024,632 | —- | C] () – C:\WINDOWS\System32\KMemory.dll
[2009/10/02 19:55:41 | 000,020,546 | —- | C] () – C:\WINDOWS\System32\KMemoryC.dll
[2009/10/02 19:55:19 | 000,000,002 | —- | C] () – C:\WINDOWS\PhotoSuite.ini
[2009/10/02 19:55:16 | 000,458,752 | —- | C] () – C:\WINDOWS\System32\Fpl.dll
[2009/10/02 19:55:16 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\EnrouteStitch.dll
[2009/10/02 19:55:16 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\CPUINF32.DLL
[2009/10/02 19:55:15 | 000,332,800 | —- | C] () – C:\WINDOWS\System32\FPXLIB.DLL
[2009/10/02 19:55:15 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\JPEGLIB.DLL
[2009/10/01 18:47:13 | 000,040,129 | —- | C] () – C:\WINDOWS\iccsigs.dat
[2009/08/04 19:38:58 | 008,892,928 | —- | C] () – C:\Documents and Settings\All Users\Application Data\atscie.msi
[2009/07/08 20:24:20 | 000,000,347 | —- | C] () – C:\WINDOWS\CTWave32.INI
[2009/07/08 20:24:19 | 000,000,029 | —- | C] () – C:\WINDOWS\sfbm.INI
[2009/07/06 17:22:47 | 000,022,629 | —- | C] () – C:\WINDOWS\System32\CiFilter.ini
[2009/05/14 17:27:18 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/05/05 14:13:59 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\CFD65FB0F8.sys
[2009/05/03 14:11:46 | 000,165,376 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/05/03 14:11:43 | 000,755,027 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/05/03 14:11:43 | 000,159,839 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/05/03 14:11:42 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/05/03 14:02:27 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/05/03 13:56:56 | 000,000,322 | —- | C] () – C:\WINDOWS\System32\Remover.ini
[2009/05/03 13:04:25 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2009/05/03 13:04:15 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/05/03 12:51:36 | 000,001,450 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/05/03 12:46:13 | 000,105,049 | —- | C] () – C:\WINDOWS\HPFins09.dat
[2009/05/03 12:46:13 | 000,003,732 | —- | C] () – C:\WINDOWS\hpfmdl09.dat
[2007/10/25 17:26:10 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/03/20 16:44:02 | 000,000,566 | —- | C] () – C:\WINDOWS\System32\SP7302.ini
[2006/09/12 18:50:32 | 000,055,808 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/24 11:09:56 | 000,061,678 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\PFP120JPR.{PB
[2006/08/24 11:09:56 | 000,012,358 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\PFP120JCM.{PB
[2006/08/24 11:09:21 | 000,004,808 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/08/24 11:09:21 | 000,000,056 | RHS- | C] () – C:\WINDOWS\System32\F8B05FD6CF.sys
[2006/08/19 17:29:06 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/07/31 20:29:29 | 000,000,138 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\fusioncache.dat
[2006/07/25 15:26:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/07/25 15:14:21 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/07/25 15:12:31 | 000,712,704 | —- | C] () – C:\WINDOWS\System32\DellSystemRestore.dll
[2006/07/25 15:08:54 | 000,000,280 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/07/25 15:07:36 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/07/25 15:00:22 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/07/25 14:40:27 | 000,044,184 | —- | C] () – C:\WINDOWS\System32\nvModes.dat
[2006/07/25 13:32:46 | 000,102,480 | —- | C] () – C:\WINDOWS\System32\EzRating.dll
[2006/07/25 13:32:46 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\EzdCoIns.dll
[2006/07/25 13:29:44 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2006/07/25 13:29:42 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/07/25 13:29:42 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/07/25 13:29:32 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/07/25 13:29:24 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/07/25 13:29:15 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2006/07/25 13:28:55 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2006/07/25 13:28:55 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/07/25 13:28:52 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2006/07/25 13:28:27 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/07/25 13:28:01 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2006/07/25 13:23:00 | 000,000,391 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/05/24 19:16:22 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2005/08/16 05:48:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/16 05:38:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/16 05:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 05:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/16 05:27:59 | 003,578,208 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/16 05:18:35 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/08/16 05:18:33 | 000,443,070 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/16 05:18:33 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005/08/16 05:18:33 | 000,072,170 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/16 05:18:33 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005/08/16 05:18:32 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005/08/16 05:18:30 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/08/16 05:18:28 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/08/16 05:18:23 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005/08/16 05:18:23 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005/08/16 05:18:15 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005/08/16 05:18:08 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2005/08/05 15:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/06/22 13:37:46 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/10/26 19:52:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/12/20 10:25:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/14 17:26:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2005/08/16 21:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2009/05/03 12:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2010/08/15 09:10:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/12/25 10:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/10/18 08:47:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstopDat
[2010/08/23 20:32:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/05/30 08:12:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/12/31 17:27:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2011/01/29 17:47:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/07/19 19:36:13 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/11/30 10:24:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\ActiSku
[2010/01/02 12:33:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Amazon
[2010/05/24 19:42:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\AVG9
[2011/03/05 00:47:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\DDMSettings
[2011/04/01 18:24:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\EmSense
[2009/12/13 18:35:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\FCTB000060497
[2009/06/21 22:56:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\GlarySoft
[2009/05/05 13:45:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\KompoZer
[2010/08/15 09:10:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\PC Suite
[2009/05/05 14:09:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Sam Francke
[2010/08/15 09:08:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Samsung
[2009/09/03 16:25:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Viewpoint
[2009/05/05 15:28:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\VSO
[2011/04/23 16:38:31 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/04/22 22:20:00 | 000,000,442 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{B9AA762D-6540-4CC0-BF6A-CA3B89302172}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/04/23 16:37:40 | 000,194,188 | —- | M] () – C:\aaw7boot.log
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/07/12 22:34:07 | 000,000,209 | —- | M] () – C:\Boot.bak
[2010/12/25 12:39:31 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/05/22 22:11:46 | 000,015,882 | —- | M] () – C:\ComboFix.txt
[2010/05/19 17:45:15 | 006,000,868 | —- | M] () – C:\ComboFix.zip
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/07/25 14:37:44 | 000,006,942 | RH– | M] () – C:\dell.sdr
[2006/08/22 18:30:36 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/07/25 15:08:43 | 000,000,827 | -H– | M] () – C:\IPH.PH
[2011/04/19 23:19:14 | 000,022,994 | —- | M] () – C:\JavaRa.log
[2010/05/21 18:57:00 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/10 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/06 18:10:04 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/04/23 16:37:40 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/05/21 18:56:26 | 000,000,490 | —- | M] () – C:\rkill.log
[2009/09/30 21:15:34 | 000,036,870 | —- | M] () – C:\ScanImage01.jpg
[2006/07/25 15:08:51 | 000,000,071 | —- | M] () – C:\SystemInfo.ini
[2010/05/22 23:42:50 | 000,004,608 | -HS- | M] () – C:\Thumbs.db
[2009/07/04 18:56:46 | 000,000,510 | —- | M] () – C:\updatedatfix.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/16 05:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/10/14 22:41:46 | 000,072,192 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2006/07/31 20:52:03 | 000,001,746 | -H– | M] () – C:\Documents and Settings\Kathryne Miller\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/08/16 05:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/16 05:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/16 05:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2006/07/25 15:02:47 | 000,001,760 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Creative MediaSource Go!.lnk
[2009/05/06 18:17:37 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2009/05/03 13:06:41 | 000,000,984 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\HP Solution Center.lnk
[2006/07/25 15:15:45 | 000,002,883 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Program Updates.lnk
[2009/05/06 18:17:37 | 000,001,563 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2005/08/16 05:43:10 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2009/05/03 10:44:28 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
[2011/01/29 17:41:04 | 000,001,732 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\WinZip.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2009/10/11 16:24:25 | 000,010,878 | —- | M] () – C:\WINDOWS\system32\uqaj.db

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2003/03/12 20:44:04 | 000,013,056 | —- | M] () – C:\WINDOWS\aodp202.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-20 21:30:28

< End of report >
Extras.txt:

OTL logfile created on: 4/23/2011 5:01:44 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Kathryne Miller\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 45.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 6.71 Gb Free Space | 18.03% Space Free | Partition Type: NTFS
Drive D: | 12.55 Gb Total Space | 1.55 Gb Free Space | 12.38% Space Free | Partition Type: NTFS
Drive G: | 74.51 Gb Total Space | 15.89 Gb Free Space | 21.32% Space Free | Partition Type: FAT32

Computer Name: MICKEY7 | User Name: Kathryne Miller | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Kathryne Miller\desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\CSHelper.exe ()
PRC - C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
PRC - C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\PixArt\PAC7302\Monitor.exe (PixArt Imaging Incorporation)
PRC - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\gearsec.exe (GEAR Software)
PRC - C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Kathryne Miller\desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (getPlusHelper) getPlus® – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (PCPitstop Scheduling) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (CSHelper) – C:\WINDOWS\system32\CSHelper.exe ()
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (FsUsbExService) – C:\WINDOWS\system32\FsUsbExService.Exe (Teruten)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (Creative Labs Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)


========== Driver Services (SafeList) ==========

DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (FsUsbExDisk) – C:\WINDOWS\system32\FsUsbExDisk.Sys ()
DRV - (IrBus) – C:\WINDOWS\system32\drivers\irbus.sys (Microsoft Corporation)
DRV - (pccsmcfd) – C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (PAC7302) – C:\WINDOWS\system32\drivers\PAC7302.SYS (PixArt Imaging Inc.)
DRV - (sscdmdm) – C:\WINDOWS\system32\drivers\sscdmdm.sys (MCCI Corporation)
DRV - (sscdmdfl) – C:\WINDOWS\system32\drivers\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\sscdbus.sys (MCCI Corporation)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTSERIAL) – C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (AngelUsb) – C:\WINDOWS\system32\drivers\AngelUsb.sys (Lumanate, Inc.)
DRV - (monfilt) – C:\WINDOWS\system32\drivers\monfilt.sys (Creative Technology Ltd.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (CTUSFSYN) – C:\WINDOWS\system32\drivers\ctusfsyn.sys (Creative Technology Ltd.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========


FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2011/04/08 11:10:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/11/24 18:23:02 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/03/05 00:46:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/03/05 00:46:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/27 15:09:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/27 15:09:06 | 000,000,000 | —D | M]

[2009/05/03 10:52:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Extensions
[2011/04/08 16:33:23 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions
[2010/04/27 18:05:14 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/23 17:32:36 | 000,000,000 | —D | M] (MyPoints Point Finder) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\{51ef49d2-624b-4194-8b97-1c468e9b0efe}
[2011/03/25 08:43:50 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/03/06 11:08:12 | 000,000,000 | —D | M] ("Amazon Toolbar") – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\[removed]
[2011/03/14 19:19:30 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Kathryne Miller\Application Data\Mozilla\Firefox\Profiles\q5ok45qo.default\extensions\[removed]
[2011/03/24 17:30:27 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/10/17 08:59:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/23 23:55:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/15 20:12:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/03/18 13:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2009/01/15 14:53:03 | 000,616,448 | —- | M] (ArtistScope) – C:\Program Files\Mozilla Firefox\plugins\npArtistScope42.dll
[2009/02/02 02:06:56 | 000,211,456 | —- | M] (ArtistScope) – C:\Program Files\Mozilla Firefox\plugins\npArtistScopeDRM11.dll
[2009/11/19 17:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2011/02/02 22:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 17:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2009/06/11 22:11:18 | 000,221,184 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2010/05/22 22:10:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Freecause Toolbar BHO) - {614BDA1F-9BEF-4CD1-BDE4-FA4804929B4A} - C:\Program Files\MyPoints Point Finder\Toolbar.dll ()
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (MyPoints Point Finder) - {89A2510A-B4B6-4683-BEC9-1B96700BC7F1} - C:\Program Files\MyPoints Point Finder\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (MyPoints Point Finder) - {89A2510A-B4B6-4683-BEC9-1B96700BC7F1} - C:\Program Files\MyPoints Point Finder\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
O4 - HKLM..\Run: [CTSVolFE.exe] C:\Program Files\Creative\Mixer\CTSVolFE.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [PC Pitstop PC Matic Reminder] C:\Program Files\PCPitstop\PC Matic\Reminder-PCMatic.exe (PC Pitstop LLC)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: facebook.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: hulu.com ([www] http in Trusted sites)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {445F47D7-E043-4BD6-82EB-7A1BD0EBA773} http://www.psapoll.com/CopyGuardIE.cab (CopyGuardCtrl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {A7846ED2-9DE6-4E8A-B116-A8ACEBFA7DB1} http://rms2.invokesolutions.com/events/bin…1452/MILive.cab (Invoke Solutions MILiveParticipantPadHelper Control)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 05:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{704431e8-dbb7-11de-aaac-0016cffb8b30}\Shell - "" = AutoRun
O33 - MountPoints2\{704431e8-dbb7-11de-aaac-0016cffb8b30}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{704431e8-dbb7-11de-aaac-0016cffb8b30}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/04/23 17:00:25 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kathryne Miller\Desktop\OTL.exe
[2011/04/19 23:23:42 | 002,322,184 | —- | C] (ESET) – C:\Documents and Settings\Kathryne Miller\Desktop\esetsmartinstaller_enu.exe
[2011/04/19 23:17:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Desktop\JavaRa
[2011/04/13 23:17:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Application Data\Apple Computer
[2011/04/08 16:36:51 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbser.sys
[2011/04/01 18:27:37 | 000,000,000 | —D | C] – C:\Program Files\EmSense
[2011/04/01 18:27:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\EmSense
[2011/04/01 18:24:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Application Data\EmSense
[2011/03/27 15:08:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/03/27 15:08:28 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/03/27 15:08:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2011/03/27 15:07:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/03/27 15:07:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Apple
[2011/03/27 15:07:41 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/03/27 15:07:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2011/03/27 15:07:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\Apple Computer
[2009/10/02 19:58:06 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\vaodp202.dll

========== Files - Modified Within 30 Days ==========

[2011/04/23 17:00:24 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kathryne Miller\Desktop\OTL.exe
[2011/04/23 16:53:25 | 000,000,000 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\prvlcl.dat
[2011/04/23 16:41:56 | 075,045,523 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/04/23 16:38:48 | 000,062,940 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/04/23 16:38:48 | 000,044,184 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2011/04/23 16:38:31 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/04/23 16:38:27 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/23 16:37:45 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/22 23:10:00 | 000,001,018 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-385954157-1898415747-3273646295-1005UA.job
[2011/04/22 22:20:00 | 000,000,442 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{B9AA762D-6540-4CC0-BF6A-CA3B89302172}.job
[2011/04/21 18:10:00 | 000,000,966 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-385954157-1898415747-3273646295-1005Core.job
[2011/04/20 02:00:01 | 000,000,362 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-MICKEY7-Kathryne Miller.job
[2011/04/19 23:23:57 | 002,322,184 | —- | M] (ESET) – C:\Documents and Settings\Kathryne Miller\Desktop\esetsmartinstaller_enu.exe
[2011/04/19 23:13:30 | 000,159,877 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\JavaRa.zip
[2011/04/19 23:11:05 | 000,002,358 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\Google Chrome.lnk
[2011/04/19 23:11:05 | 000,002,336 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/04/19 18:12:38 | 000,625,664 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\dds.scr
[2011/04/15 18:52:05 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/04/14 08:22:32 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\rp_stats.dat
[2011/04/14 08:22:32 | 000,000,044 | —- | M] () – C:\WINDOWS\System32\rp_rules.dat
[2011/04/14 08:19:58 | 003,578,208 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/14 03:13:22 | 000,443,070 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/14 03:13:22 | 000,072,170 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/10 22:34:59 | 000,001,757 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Converter.lnk
[2011/04/10 22:34:58 | 000,001,499 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Desktop\DivX Movies.lnk
[2011/04/08 16:39:30 | 000,055,808 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/07 03:59:03 | 000,016,432 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2011/04/03 22:59:04 | 000,000,412 | —- | M] () – C:\Documents and Settings\Kathryne Miller\My Documents\spider.sav
[2011/04/01 18:27:43 | 000,000,788 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Update EmSense 1.14.3.lnk
[2011/03/27 15:08:52 | 000,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2011/03/27 15:07:45 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/24 17:30:34 | 000,000,742 | —- | M] () – C:\Documents and Settings\Kathryne Miller\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/24 17:30:34 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

========== Files Created - No Company Name ==========

[2011/04/19 23:13:38 | 000,159,877 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Desktop\JavaRa.zip
[2011/04/19 18:12:45 | 000,625,664 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Desktop\dds.scr
[2011/04/14 08:22:32 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/04/14 08:22:32 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2011/04/01 18:27:43 | 000,000,788 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Update EmSense 1.14.3.lnk
[2011/03/27 15:08:52 | 000,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2011/03/27 15:07:45 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/27 15:07:42 | 000,001,830 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2011/03/24 17:30:33 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2010/08/15 09:09:38 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/08/15 09:09:38 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/08/15 09:09:01 | 000,002,528 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\$_hpcst$.hpc
[2010/05/30 08:12:17 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2010/05/09 17:55:34 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.INI
[2010/03/06 15:16:16 | 000,000,000 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\prvlcl.dat
[2010/03/06 13:44:36 | 000,266,240 | —- | C] () – C:\WINDOWS\System32\CSHelper.exe
[2009/10/11 16:24:25 | 000,019,523 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\axep.db
[2009/10/11 16:24:25 | 000,019,401 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\ibyka.ban
[2009/10/11 16:24:25 | 000,016,950 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\yfofizyw.bat
[2009/10/11 16:24:25 | 000,016,206 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\synasexoza.scr
[2009/10/11 16:24:25 | 000,015,931 | —- | C] () – C:\Documents and Settings\All Users\Application Data\epidi.db
[2009/10/11 16:24:25 | 000,013,581 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\qily.dl
[2009/10/11 16:24:25 | 000,010,617 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\ekyq.db
[2009/10/11 16:24:25 | 000,010,051 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ilig.lib
[2009/10/02 19:58:07 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\aodp2022.dll
[2009/10/02 19:58:07 | 000,290,816 | —- | C] () – C:\WINDOWS\System32\aodp2023.dll
[2009/10/02 19:58:07 | 000,227,200 | —- | C] () – C:\WINDOWS\System32\drivers\aodp202.sys
[2009/10/02 19:58:07 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\daodp202.dll
[2009/10/02 19:58:07 | 000,015,584 | —- | C] () – C:\WINDOWS\aodp202.ini
[2009/10/02 19:58:06 | 000,020,480 | —- | C] () – C:\WINDOWS\daodp202.exe
[2009/10/02 19:55:41 | 000,028,747 | —- | C] () – C:\WINDOWS\System32\KMemoryMMX.dll
[2009/10/02 19:55:41 | 000,024,653 | —- | C] () – C:\WINDOWS\System32\KMemoryPIII.dll
[2009/10/02 19:55:41 | 000,024,632 | —- | C] () – C:\WINDOWS\System32\KMemory.dll
[2009/10/02 19:55:41 | 000,020,546 | —- | C] () – C:\WINDOWS\System32\KMemoryC.dll
[2009/10/02 19:55:19 | 000,000,002 | —- | C] () – C:\WINDOWS\PhotoSuite.ini
[2009/10/02 19:55:16 | 000,458,752 | —- | C] () – C:\WINDOWS\System32\Fpl.dll
[2009/10/02 19:55:16 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\EnrouteStitch.dll
[2009/10/02 19:55:16 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\CPUINF32.DLL
[2009/10/02 19:55:15 | 000,332,800 | —- | C] () – C:\WINDOWS\System32\FPXLIB.DLL
[2009/10/02 19:55:15 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\JPEGLIB.DLL
[2009/10/01 18:47:13 | 000,040,129 | —- | C] () – C:\WINDOWS\iccsigs.dat
[2009/08/04 19:38:58 | 008,892,928 | —- | C] () – C:\Documents and Settings\All Users\Application Data\atscie.msi
[2009/07/08 20:24:20 | 000,000,347 | —- | C] () – C:\WINDOWS\CTWave32.INI
[2009/07/08 20:24:19 | 000,000,029 | —- | C] () – C:\WINDOWS\sfbm.INI
[2009/07/06 17:22:47 | 000,022,629 | —- | C] () – C:\WINDOWS\System32\CiFilter.ini
[2009/05/14 17:27:18 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/05/05 14:13:59 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\CFD65FB0F8.sys
[2009/05/03 14:11:46 | 000,165,376 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/05/03 14:11:43 | 000,755,027 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/05/03 14:11:43 | 000,159,839 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/05/03 14:11:42 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/05/03 14:02:27 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/05/03 13:56:56 | 000,000,322 | —- | C] () – C:\WINDOWS\System32\Remover.ini
[2009/05/03 13:04:25 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2009/05/03 13:04:15 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/05/03 12:51:36 | 000,001,450 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/05/03 12:46:13 | 000,105,049 | —- | C] () – C:\WINDOWS\HPFins09.dat
[2009/05/03 12:46:13 | 000,003,732 | —- | C] () – C:\WINDOWS\hpfmdl09.dat
[2007/10/25 17:26:10 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2007/03/20 16:44:02 | 000,000,566 | —- | C] () – C:\WINDOWS\System32\SP7302.ini
[2006/09/12 18:50:32 | 000,055,808 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/24 11:09:56 | 000,061,678 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\PFP120JPR.{PB
[2006/08/24 11:09:56 | 000,012,358 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Application Data\PFP120JCM.{PB
[2006/08/24 11:09:21 | 000,004,808 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/08/24 11:09:21 | 000,000,056 | RHS- | C] () – C:\WINDOWS\System32\F8B05FD6CF.sys
[2006/08/19 17:29:06 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/07/31 20:29:29 | 000,000,138 | —- | C] () – C:\Documents and Settings\Kathryne Miller\Local Settings\Application Data\fusioncache.dat
[2006/07/25 15:26:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/07/25 15:14:21 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/07/25 15:12:31 | 000,712,704 | —- | C] () – C:\WINDOWS\System32\DellSystemRestore.dll
[2006/07/25 15:08:54 | 000,000,280 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/07/25 15:07:36 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/07/25 15:00:22 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/07/25 14:40:27 | 000,044,184 | —- | C] () – C:\WINDOWS\System32\nvModes.dat
[2006/07/25 13:32:46 | 000,102,480 | —- | C] () – C:\WINDOWS\System32\EzRating.dll
[2006/07/25 13:32:46 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\EzdCoIns.dll
[2006/07/25 13:29:44 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2006/07/25 13:29:42 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/07/25 13:29:42 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/07/25 13:29:32 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/07/25 13:29:24 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/07/25 13:29:15 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2006/07/25 13:28:55 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2006/07/25 13:28:55 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/07/25 13:28:52 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2006/07/25 13:28:27 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/07/25 13:28:01 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2006/07/25 13:23:00 | 000,000,391 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/05/24 19:16:22 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2005/08/16 05:48:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/16 05:38:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/16 05:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 05:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/16 05:27:59 | 003,578,208 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/16 05:18:35 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/08/16 05:18:33 | 000,443,070 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/16 05:18:33 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005/08/16 05:18:33 | 000,072,170 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/16 05:18:33 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005/08/16 05:18:32 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005/08/16 05:18:30 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/08/16 05:18:28 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/08/16 05:18:23 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005/08/16 05:18:23 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005/08/16 05:18:15 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005/08/16 05:18:08 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2005/08/05 15:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/06/22 13:37:46 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/10/26 19:52:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/12/20 10:25:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/14 17:26:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2005/08/16 21:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2009/05/03 12:03:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2010/08/15 09:10:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/12/25 10:19:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/10/18 08:47:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstopDat
[2010/08/23 20:32:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/05/30 08:12:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/12/31 17:27:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2011/01/29 17:47:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/07/19 19:36:13 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/11/30 10:24:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\ActiSku
[2010/01/02 12:33:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Amazon
[2010/05/24 19:42:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\AVG9
[2011/03/05 00:47:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\DDMSettings
[2011/04/01 18:24:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\EmSense
[2009/12/13 18:35:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\FCTB000060497
[2009/06/21 22:56:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\GlarySoft
[2009/05/05 13:45:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\KompoZer
[2010/08/15 09:10:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\PC Suite
[2009/05/05 14:09:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Sam Francke
[2010/08/15 09:08:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Samsung
[2009/09/03 16:25:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\Viewpoint
[2009/05/05 15:28:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Kathryne Miller\Application Data\VSO
[2011/04/23 16:38:31 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/04/22 22:20:00 | 000,000,442 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{B9AA762D-6540-4CC0-BF6A-CA3B89302172}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/04/23 16:37:40 | 000,194,188 | —- | M] () – C:\aaw7boot.log
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/07/12 22:34:07 | 000,000,209 | —- | M] () – C:\Boot.bak
[2010/12/25 12:39:31 | 000,000,279 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/05/22 22:11:46 | 000,015,882 | —- | M] () – C:\ComboFix.txt
[2010/05/19 17:45:15 | 006,000,868 | —- | M] () – C:\ComboFix.zip
[2005/08/16 05:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/07/25 14:37:44 | 000,006,942 | RH– | M] () – C:\dell.sdr
[2006/08/22 18:30:36 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/07/25 15:08:43 | 000,000,827 | -H– | M] () – C:\IPH.PH
[2011/04/19 23:19:14 | 000,022,994 | —- | M] () – C:\JavaRa.log
[2010/05/21 18:57:00 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2005/08/16 05:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/10 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/06 18:10:04 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/04/23 16:37:40 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/05/21 18:56:26 | 000,000,490 | —- | M] () – C:\rkill.log
[2009/09/30 21:15:34 | 000,036,870 | —- | M] () – C:\ScanImage01.jpg
[2006/07/25 15:08:51 | 000,000,071 | —- | M] () – C:\SystemInfo.ini
[2010/05/22 23:42:50 | 000,004,608 | -HS- | M] () – C:\Thumbs.db
[2009/07/04 18:56:46 | 000,000,510 | —- | M] () – C:\updatedatfix.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/16 05:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/10/14 22:41:46 | 000,072,192 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43a.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2006/07/31 20:52:03 | 000,001,746 | -H– | M] () – C:\Documents and Settings\Kathryne Miller\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/08/16 05:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/16 05:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/16 05:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2006/07/25 15:02:47 | 000,001,760 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Creative MediaSource Go!.lnk
[2009/05/06 18:17:37 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2009/05/03 13:06:41 | 000,000,984 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\HP Solution Center.lnk
[2006/07/25 15:15:45 | 000,002,883 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Program Updates.lnk
[2009/05/06 18:17:37 | 000,001,563 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2005/08/16 05:43:10 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2009/05/03 10:44:28 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
[2011/01/29 17:41:04 | 000,001,732 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\WinZip.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2009/10/11 16:24:25 | 000,010,878 | —- | M] () – C:\WINDOWS\system32\uqaj.db

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2003/03/12 20:44:04 | 000,013,056 | —- | M] () – C:\WINDOWS\aodp202.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-20 21:30:28

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI