This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

system freezes and is very slow

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

access to internet is slow, system freezes and I have to shutLogfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:46:40 AM, on 28/04/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\LeechGet 2007\LeechGet.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\AVG\AVG10\avgchsvx.exe
C:\Program Files\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Documents and Settings\Terry Laderoute\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.ca/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ca.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.ca/myway
R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - (no file)
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…t;ver=10.0.1204
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [AutoLaunch] C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe monthly
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\powerpoint\Office\OSA9.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Download using LeechGet - file://C:\Program Files\LeechGet 2007\\AddUrl.html
O8 - Extra context menu item: Download using LeechGet Wizard - file://C:\Program Files\LeechGet 2007\\Wizard.html
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Parse with LeechGet - file://C:\Program Files\LeechGet 2007\\Parser.html
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://fishingchamp.gamescampus.com/luncher/GamesCampus.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Peggle%20Nights/Images/stg_drm.ocx
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_4.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://pencilpeninkcanada.spaces.live.com/…ad/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192883129921
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.photolab.ca/Upload/ImageUploader4.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://sympatico.zone.msn.com/bingame/chnz…mjolauncher.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD…ap/PhtPkMSN.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (ZPA_TexasHoldem Object) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab55579.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://sympatico.zone.msn.com/bingame/jobo…ersion=1,0,0,10
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Escape%20Rosecliff%20Island/Images/armhelper.ocx
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} (CacheManager.CacheManagerCtrl) - http://www.candystand.com/assets/activex/v…acheManager.CAB
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

–
End of file - 16173 bytes
down to regain operating system, hoping this hijackthis log will prove helpful.
Hello Shybear575 and welcome to the WTT Form.
I'm RedCar92 and my name is Bill, I'll be glad to help you with your computer problems.

  • Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear. Malware removal can be stressful but we will clean it.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperative and could require a full reinstall of your OS, losing all your programs and data.

Stay with this topic until I give you the all clean post.
Thanks
Bill
In Training at WTT Classroom
Hello shybear575,
Please do the following:
  • Please download DDS from LINK 1 or LINK 2and save it to your desktop.
  • Double click dds.scr to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
  • Please include the contents of the following in your reply using Copy / Paste:
  • DDS.txt & Attach.txt

Next
  • Download aswMBR.exe ( 511KB ) to your desktop.
  • Double click the aswMBR.exe to run it
  • Click the "Scan" button to start scan
  • Click the "Save Log" in case of infection
  • Save the aswMBR.txt to the desktop

[external image: Posted Image]

[external image: Posted Image]

[external image: Posted Image]

Logs to post:
  • DDS.txt
  • Attach.txt
  • aswbmr.txt
Thanks
Bill
In Training at WTT Classroom
Hi Bill, my name is Terry, when I tried to upload the logs I received a message " Upload failed. Please ask administrator to ensure uploads directory is writeable.
Hello Terry,
Can you open the logs one at a time with notepad?
  • If so click on Edit on the menu bar, then click Select All.
  • The data should all highlight blue
  • In Edit on the menu bar click Copy
  • On your topic in the forum click Add Reply not Fast reply
  • Right click anywhere in the white message area and select Paste
  • Click Add Reply.
Thanks
Bill
In Training at WTT Classroom
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 0:39:33.04 on 29/04/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.279 [GMT -4:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\LeechGet 2007\LeechGet.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\AVG\AVG10\avgchsvx.exe
C:\Program Files\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Documents and Settings\Terry Laderoute\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Terry Laderoute\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://sympatico.msn.ca/
uSearch Page = hxxp://ca.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://ca.search.yahoo.com
uDefault_Page_URL = hxxp://www.dell.ca/myway
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearch Bar = about:blank
mDefault_Page_URL = hxxp://ca.yahoo.com
mDefault_Search_URL = hxxp://ca.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://ca.search.yahoo.com
mSearch Page = hxxp://ca.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://ca.search.yahoo.com
mStart Page = hxxp://ca.yahoo.com
mSearch Bar = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.dell.ca/myway
uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://ca.search.yahoo.com
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRunOnce: [AutoLaunch] c:\program files\lavasoft\ad-aware\AutoLaunch.exe monthly
mRun: [LVCOMS] c:\program files\common files\logitech\qcdriver\LVCOMS.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…t;ver=10.0.1204
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\powerpoint\office\OSA9.EXE
IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: Download using LeechGet - file://c:\program files\leechget 2007\\AddUrl.html
IE: Download using LeechGet Wizard - file://c:\program files\leechget 2007\\Wizard.html
IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM
IE: Parse with LeechGet - file://c:\program files\leechget 2007\\Parser.html
IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} - hxxp://fishingchamp.gamescampus.com/luncher/GamesCampus.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Peggle%20Nights/Images/stg_drm.ocx
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} - hxxp://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_4.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://pencilpeninkcanada.spaces.live.com//PhotoUpload/MsnPUpld.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1192883129921
DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} - hxxp://www.photolab.ca/Upload/ImageUploader4.cab
DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} - hxxp://sympatico.zone.msn.com/bingame/chnz/default/mjolauncher.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} - hxxp://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab55579.cab
DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} - hxxp://sympatico.zone.msn.com/bingame/jobo/default/AstoundLauncher.cab#version=1,0,0,10
DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} - hxxp://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Escape%20Rosecliff%20Island/Images/armhelper.ocx
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab55579.cab
DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} - hxxp://www.candystand.com/assets/activex/virtools/CacheManager.CAB
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-1-19 32464]
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2009-4-1 26624]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-25 64288]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-2-10 296400]
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-4 98304]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-9-26 54752]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-3-30 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216]
R3 XDva383;XDva383;\??\c:\windows\system32\xdva383.sys –> c:\windows\system32\XDva383.sys [?]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\documents and settings\terry laderoute\local settings\temp\{aee517dd-b221-4e88-b4d7-d618c957c4ff}\fsgk.sys –> c:\documents and settings\terry laderoute\local settings\temp\{aee517dd-b221-4e88-b4d7-d618c957c4ff}\fsgk.sys [?]
.
=============== Created Last 30 ================
.
2011-04-28 04:45:02 388096 —-a-r- c:\docume~1\terryl~1\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-04-28 04:45:00 ——– d—–w- c:\program files\Trend Micro
2011-04-27 19:04:07 ——– d—–w- c:\program files\MSECache
2011-04-27 15:56:57 ——– d—–w- c:\program files\SecondLifeViewer2
2011-04-23 16:01:52 ——– d—–w- c:\program files\SpywareBlaster
2011-04-23 15:19:33 ——– d—–w- c:\windows\NV20882388.TMP
2011-04-14 18:11:39 ——– d—–w- C:\gamigo
2011-04-08 21:28:09 ——– d–h–w- C:\$AVG
2011-04-08 08:27:52 ——– d—–w- c:\windows\system32\drivers\AVG
2011-04-08 07:55:24 ——– d—–w- c:\docume~1\alluse~1\applic~1\SecTaskMan
2011-04-08 07:55:17 ——– d—–w- c:\program files\Security Task Manager
2011-04-07 22:21:14 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-04-07 22:21:14 ——– d—–w- c:\windows\system32\wbem\Repository
2011-04-07 22:17:21 ——– d—–w- c:\program files\FlySim
2011-04-07 22:17:19 ——– d—–w- c:\program files\Caramba
2011-03-30 21:17:22 134480 —-a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
.
==================== Find3M ====================
.
2011-04-18 09:59:32 15880 —-a-w- c:\windows\system32\lsdelete.exe
2011-03-07 05:33:50 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37:06 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06:29 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06:29 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06:29 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41:59 385024 —-a-w- c:\windows\system32\html.iec
2011-02-17 12:32:12 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39 290432 —-a-w- c:\windows\system32\atmfd.dll
2011-02-11 13:25:52 229888 —-a-w- c:\windows\system32\fxscover.exe
2011-02-09 13:53:52 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 —-a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 —-a-w- c:\windows\system32\mfc42u.dll
2011-02-03 02:40:23 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-03 00:19:39 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58:35 2067456 —-a-w- c:\windows\system32\mstscax.dll
2006-01-20 22:38:22 774144 —-a-w- c:\program files\RngInterstitial.dll
.
============= FINISH: 0:41:49.09 ===============
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 20/01/2006 2:38:04 PM System Uptime: 27/04/2011 9:01:54 AM (39 hours ago) . Motherboard: Dell Inc. | | 0JC474 Processor: Intel® Pentium® 4 CPU 3.00GHz | Microprocessor | 2992/800mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 71 GiB total, 34.175 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP2347: 07/04/2011 1:24:55 AM - System Checkpoint RP2348: 07/04/2011 6:14:14 PM - Restore Operation RP2349: 08/04/2011 3:33:01 AM - Removed AVG 2011 RP2350: 08/04/2011 3:34:30 AM - Removed AVG 2011 RP2351: 08/04/2011 4:26:04 AM - Installed AVG 2011 RP2352: 08/04/2011 4:27:07 AM - Installed AVG 2011 RP2353: 09/04/2011 5:02:10 AM - System Checkpoint RP2354: 10/04/2011 5:05:47 AM - System Checkpoint RP2355: 11/04/2011 5:09:55 AM - System Checkpoint RP2356: 12/04/2011 6:09:59 AM - System Checkpoint RP2357: 13/04/2011 12:28:08 PM - System Checkpoint RP2358: 14/04/2011 2:39:44 PM - System Checkpoint RP2359: 15/04/2011 7:00:42 AM - Software Distribution Service 3.0 RP2360: 16/04/2011 8:31:14 AM - System Checkpoint RP2361: 17/04/2011 8:35:49 AM - System Checkpoint RP2362: 18/04/2011 8:48:28 AM - System Checkpoint RP2363: 19/04/2011 9:13:17 AM - System Checkpoint RP2364: 20/04/2011 11:35:07 AM - System Checkpoint RP2365: 21/04/2011 7:00:21 AM - Software Distribution Service 3.0 RP2366: 22/04/2011 11:41:31 AM - System Checkpoint RP2367: 22/04/2011 8:01:35 PM - System Checkpoint RP2368: 23/04/2011 9:05:26 PM - System Checkpoint RP2369: 24/04/2011 9:38:06 PM - System Checkpoint RP2370: 26/04/2011 12:46:08 AM - System Checkpoint RP2371: 26/04/2011 7:02:13 AM - Software Distribution Service 3.0 RP2372: 27/04/2011 7:02:29 AM - Software Distribution Service 3.0 RP2373: 27/04/2011 3:04:25 PM - Installed Compatibility Pack for the 2007 Office system RP2374: 28/04/2011 12:20:01 AM - Software Distribution Service 3.0 RP2375: 28/04/2011 12:44:59 AM - Installed HiJackThis . ==== Installed Programs ====================== . . Ad-Aware Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Photoshop Elements 3.0 Adobe Reader 8.2.6 Adobe Shockwave Player 11.5 Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft PhotoBase ArcSoft PhotoStudio 2000 Audacity 1.3.2 (Unicode) AVG 2011 Canon ScanGear Toolbox 3.0 CCleaner Compatibility Pack for the 2007 Office system Conexant D850 56K V.9x DFVc Modem Corel Painter Essentials 2 Critical Update for Windows Media Player 11 (KB959772) CTU: Marine Sharpshooter CustomerResearchQFolder Dell Digital Jukebox Driver Dell Driver Reset Tool Dell Support Center Dell System Restore DellSupport Digital Content Portal DivX Setup Driver Detective ebgcInfra ebgcRes ebgcSDK Electronic Arts Game Updater eSupportQFolder Family Trees Quick & Easy GameHouse GdiplusUpgrade GolfStar Google Update Helper Google Updater High Definition Audio Driver Package - KB835221 HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Deskjet 5400 series HP Extended Capabilities 5.0 HP Software Update HP Solution Center & Imaging Support Tools 5.0 HP Update HPDeskjet5400Series HPProductAssistant ieSpell Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections Drivers Intel® PROSet for Wired Connections Internet Explorer Default Page Java Auto Updater Java™ 6 Update 24 Junk Mail filter update Learn2 Player (Uninstall Only) LeechGet 2007 Version 2.1 Logitech QuickCam Malwarebytes' Anti-Malware MarketResearch MCU Medal of Honor Allied Assault Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Digital Image Library 9 - Blocker Microsoft Digital Image Standard 2006 Microsoft Digital Image Standard 2006 Editor Microsoft Digital Image Standard 2006 Library Microsoft Encarta Encyclopedia Standard 2006 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2000 Premium Microsoft Office Live Add-in 1.3 Microsoft Office XP Media Content Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Streets & Trips 2006 Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable - KB2467175 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Word 2002 Microsoft Works Microsoft Works Suite 2006 Setup Launcher Microsoft Works Suite Add-in for Microsoft Word Modem Helper MSN MSVCRT MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK Musicmatch for Windows Media Player Need For Speed - Porsche Unleashed Nero - Burning Rom NetWaiting nik Color Efex Pro 2.0 GE Nikon Message Center NVIDIA Drivers OmniPage Pro 9.0 Phoenix Viewer 1.5.2.1050 PictureProject PowerDVD 5.5 Pro Publisher Professional Business Labels QuickTime RealPlayer RealUpgrade 1.0 RegScrubXP 3.25 Ricochet Infinity Sandlot Games Client Services Scan Manager 5.2 SecondLifeViewer2 (remove only) Security Task Manager 1.8c Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2491683) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Segoe UI Shockwave ShotOnline International Soldier of Fortune II - Double Helix SolutionCenter Sonic DLA Sonic MyDVD LE Sonic RecordNow Audio Sonic RecordNow Copy Sonic RecordNow Data Spybot - Search & Destroy SpywareBlaster 4.4 System Requirements Lab Tablet Trojan Killer 1.4 Uniblue DriverScanner 2009 Uninstall 1.0.0.1 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB969497) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VC80CRTRedist - 8.0.50727.4053 Veoh Web Player Viewpoint Media Player Virtools 3D Life Player Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WeatherEye WebCyberCoach 3.2 Dell WebFldrs XP WebReg Windows Defender Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage v1.3.0254.0 Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Toolbar Windows Live Upload Tool Windows Live Writer Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 11 Windows XP Service Pack 3 Works Upgrade World War 2: Sniper Xvid 1.2.1 final uninstall Yahoo! Messenger . ==== Event Viewer Messages From Past Week ======== . 26/04/2011 8:06:34 AM, error: Service Control Manager [7034] - The TabletService service terminated unexpectedly. It has done this 1 time(s). 26/04/2011 6:45:15 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 26/04/2011 6:44:57 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 26/04/2011 6:44:41 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Avgldx86 Avgmfx86 Avgtdix Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip 26/04/2011 6:44:41 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 26/04/2011 6:44:41 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 26/04/2011 6:44:41 AM, error: Service Control Manager [7001] - The fssfltr service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 26/04/2011 6:44:41 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 26/04/2011 6:44:41 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 26/04/2011 6:44:41 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 26/04/2011 6:33:31 AM, error: System Error [1003] - Error code 100000d4, parameter1 a941e038, parameter2 0000001c, parameter3 00000001, parameter4 80502cd6. 24/04/2011 11:01:41 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC000009A' while processing the file 'screen_last.bmp' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 22/04/2011 9:28:59 AM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. . 22/04/2011 9:28:59 AM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\system32\SHELL32.dll. Reference error message: The operation completed successfully. . 22/04/2011 9:28:29 AM, error: Service Control Manager [7024] - The AVG WatchDog service terminated with service-specific error 3221685674 (0xC00705AA). 22/04/2011 9:28:26 AM, error: Service Control Manager [7031] - The AVG WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 22/04/2011 9:28:21 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC000009A' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 22/04/2011 7:23:21 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC000009A' while processing the file 'drivetable.txt' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 22/04/2011 7:23:21 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC000009A' while processing the file 'ba2a564a-f .. f.inv.gz.t' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 22/04/2011 6:18:32 PM, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:. 22/04/2011 6:16:18 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC000009A' while processing the file 'SecondLife.llerror_marker' on the volume 'Hardd .. lume2'. It has stopped monitoring the volume. 22/04/2011 6:09:22 PM, error: Srv [2019] - The server was unable to allocate from the system nonpaged pool because the pool was empty. . ==== End Of File ===========================
aswMBR version 0.9.5 Copyright© 2011 AVAST Software Run date: 2011-04-29 00:46:16 —————————– 00:46:16.984 OS Version: Windows 5.1.2600 Service Pack 3 00:46:16.984 Number of processors: 2 586 0x403 00:46:16.984 ComputerName: DJY99691 UserName: 00:46:17.640 Initialize success 00:46:21.765 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e 00:46:21.765 Disk 0 Vendor: WDC_WD800JD-75MSA1 10.01E01 Size: 76293MB BusType: 3 00:46:23.781 Disk 0 MBR read successfully 00:46:23.781 Disk 0 MBR scan 00:46:25.781 Disk 0 scanning sectors +156232125 00:46:25.796 Disk 0 scanning C:\WINDOWS\system32\drivers 00:46:38.734 Service scanning 00:46:41.015 Disk 0 trace - called modules: 00:46:41.031 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 00:46:41.031 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f83ab8] 00:46:41.031 3 CLASSPNP.SYS[f75fefd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x86f9bb00] 00:46:41.031 Scan finished successfully 00:46:48.687 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Terry Laderoute\Desktop\MBR.dat" 00:46:48.687 The log file has been saved successfully to "C:\Documents and Settings\Terry Laderoute\Desktop\aswMBR.txt"
Hello Terry,
So far your logs look clean, :thumbup: lets do this please:
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Next
Please use Internet Explorer to download and run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click on List of found threats.
  • Click Export to text file
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.


Next
Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.


Logs to post:
  • OTL.txt
  • Extras.txt
  • Eset results
  • Mbam.txt
Thanks
Bill
In Training at WTT Classroom
OTL logfile created on: 01/05/2011 7:45:42 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Terry Laderoute\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 379.00 Mb Available Physical Memory | 37.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 59.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.05 Gb Total Space | 33.71 Gb Free Space | 47.44% Space Free | Partition Type: NTFS

Computer Name: DJY99691 | User Name: Terry Laderoute | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Terry Laderoute\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\LeechGet 2007\LeechGet.exe ()
PRC - C:\WINDOWS\system32\Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe ()
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe (Logitech Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Terry Laderoute\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (TabletService) – C:\WINDOWS\system32\Tablet.exe (Wacom Technology, Corp.)
SRV - (AdobeActiveFileMonitor) – C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe ()
SRV - (PhotoshopElementsDeviceConnect) – C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (fsbts) – C:\WINDOWS\system32\Drivers\fsbts.sys ()
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (PenClass) – C:\WINDOWS\system32\Drivers\PenClass.sys (Wacom Technology Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (lusbaudio) – C:\WINDOWS\system32\drivers\LVSound2.sys (Logitech Inc.)
DRV - (LVBulk) – C:\WINDOWS\system32\drivers\LVBulk.sys (Logitech Inc.)
DRV - (LVVI500A) – C:\WINDOWS\system32\drivers\lvvi500a.sys (Tekom Technologies, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ca.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ca.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.ca/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ca.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
IE - HKCU\..\URLSearchHook: CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Ask"
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Ask"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.search.yahoo.com/?fr=w3i&type;=W3i_SP,205,0_0,StartPage,20110418,16960,0,19,0"
FF - prefs.js..extensions.enabledItems: [removed]:1.1.6
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1
FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:3.1.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.64
FF - prefs.js..extensions.enabledItems: [removed]:1.5.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209


FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/04/27 12:41:11 | 000,000,000 | —D | M]

[2009/06/10 17:40:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Terry Laderoute\Application Data\Mozilla\Extensions
[2009/06/10 17:40:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Terry Laderoute\Application Data\Mozilla\Extensions\[removed]
[2011/04/08 04:12:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Terry Laderoute\Application Data\Mozilla\Firefox\Profiles\5fsi1gas.default\extensions
[2010/04/27 23:46:32 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Terry Laderoute\Application Data\Mozilla\Firefox\Profiles\5fsi1gas.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/04/07 18:15:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Terry Laderoute\Application Data\Mozilla\Firefox\Profiles\5fsi1gas.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2009/12/18 08:37:11 | 000,000,000 | —D | M] (Dictionary Switcher) – C:\Documents and Settings\Terry Laderoute\Application Data\Mozilla\Firefox\Profiles\5fsi1gas.default\extensions\[removed]
[2011/04/07 18:15:33 | 000,000,000 | —D | M] (Canadian English Dictionary) – C:\Documents and Settings\Terry Laderoute\Application Data\Mozilla\Firefox\Profiles\5fsi1gas.default\extensions\[removed](2).org
[2010/05/23 22:24:20 | 000,000,000 | —D | M] (Veoh Video Compass) – C:\Documents and Settings\Terry Laderoute\Application Data\Mozilla\Firefox\Profiles\5fsi1gas.default\extensions\[removed]
[2008/09/21 00:31:40 | 000,000,681 | —- | M] () – C:\Documents and Settings\Terry Laderoute\Application Data\Mozilla\Firefox\Profiles\5fsi1gas.default\searchplugins\ask.xml
[2008/04/28 16:47:19 | 000,001,656 | —- | M] () – C:\Documents and Settings\Terry Laderoute\Application Data\Mozilla\Firefox\Profiles\5fsi1gas.default\searchplugins\video-search.xml
[2011/04/10 18:54:44 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/01/11 09:49:47 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/12 14:18:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\TERRY LADEROUTE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5FSI1GAS.DEFAULT\EXTENSIONS\{AE93811A-5C9A-4D34-8462-F7B864FC4696}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\TERRY LADEROUTE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5FSI1GAS.DEFAULT\EXTENSIONS\{C50CA3C4-5656-43C2-A061-13E717F73FC8}.XPI
[2011/04/27 12:41:11 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2010/05/14 14:15:04 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/09/15 02:52:13 | 000,210,944 | —- | M] () – C:\Program Files\Mozilla Firefox\components\rpff.dll
[2011/02/02 22:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/10/25 10:17:00 | 000,237,568 | —- | M] (Virtools SA) – C:\Program Files\Mozilla Firefox\plugins\npvirtools.dll

O1 HOSTS File: ([2009/11/01 19:13:24 | 000,348,853 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 11962 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [AutoLaunch] C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\powerpoint\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &ieSpell; Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling; - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Download using LeechGet - C:\Program Files\LeechGet 2007\AddUrl.html ()
O8 - Extra context menu item: Download using LeechGet Wizard - C:\Program Files\LeechGet 2007\Wizard.html ()
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O8 - Extra context menu item: Parse with LeechGet - C:\Program Files\LeechGet 2007\Parser.html ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} http://fishingchamp.gamescampus.com/luncher/GamesCampus.cab (GamesCampus Control)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Peggle%20Nights/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_4.cab (FixController Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://pencilpeninkcanada.spaces.live.com/…ad/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1192883129921 (MUWebControl Class)
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} http://www.photolab.ca/Upload/ImageUploader4.cab (Image Uploader Control)
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://sympatico.zone.msn.com/bingame/chnz…mjolauncher.cab (MJLauncherCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} http://appdirectory.messenger.msn.com/AppD…ap/PhtPkMSN.cab (PhotoPickConvert Class)
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} http://zone.msn.com/bingame/zpagames/zpa_txhe.cab55579.cab (ZPA_TexasHoldem Object)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} http://sympatico.zone.msn.com/bingame/jobo…ersion=1,0,0,10 (AstoundLauncher Control)
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab (CBankshotZoneCtrl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Escape%20Rosecliff%20Island/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} http://www.candystand.com/assets/activex/v…acheManager.CAB (CacheManager.CacheManagerCtrl)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Terry Laderoute\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Terry Laderoute\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 15:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/01 19:44:52 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Terry Laderoute\Desktop\OTL.exe
[2011/04/30 13:13:25 | 000,000,000 | —D | C] – C:\Program Files\File Type Assistant
[2011/04/30 13:12:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Terry Laderoute\Application Data\NetAssistant
[2011/04/30 13:11:58 | 000,000,000 | —D | C] – C:\Program Files\Free Offers from Freeze.com
[2011/04/29 16:50:55 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2011/04/29 00:46:05 | 000,567,296 | —- | C] (AVAST Software) – C:\Documents and Settings\Terry Laderoute\Desktop\aswMBR.exe
[2011/04/28 00:45:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Terry Laderoute\Start Menu\Programs\HiJackThis
[2011/04/28 00:45:00 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/04/27 15:04:07 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2011/04/27 11:57:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Second Life Viewer 2
[2011/04/27 11:56:57 | 000,000,000 | —D | C] – C:\Program Files\SecondLifeViewer2
[2011/04/23 12:01:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SpywareBlaster
[2011/04/23 12:01:52 | 000,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2011/04/22 18:32:11 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Terry Laderoute\Recent
[2011/04/14 14:11:39 | 000,000,000 | —D | C] – C:\gamigo
[2011/04/08 17:28:09 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/04/08 04:27:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/04/08 03:55:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2011/04/08 03:55:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Security Task Manager
[2011/04/08 03:55:17 | 000,000,000 | —D | C] – C:\Program Files\Security Task Manager
[2011/04/07 18:17:21 | 000,000,000 | —D | C] – C:\Program Files\FlySim
[2011/04/07 18:17:19 | 000,000,000 | —D | C] – C:\Program Files\Caramba
[2011/04/06 21:21:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Terry Laderoute\Start Menu\Programs\Zuma
[2006/01/20 18:38:29 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/01 19:44:54 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Terry Laderoute\Desktop\OTL.exe
[2011/05/01 19:37:53 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/05/01 19:37:52 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2011/05/01 19:37:51 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2011/05/01 19:37:49 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2011/05/01 19:37:48 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2011/05/01 19:35:14 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/01 19:32:34 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/01 19:31:37 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/05/01 19:31:07 | 000,176,287 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/05/01 19:30:33 | 000,016,137 | —- | M] () – C:\WINDOWS\System32\tablet.dat
[2011/05/01 19:30:21 | 000,000,298 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3116237007-3362448852-429834905-1006.job
[2011/05/01 19:30:20 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/05/01 19:30:18 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/01 19:29:39 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/01 17:19:00 | 113,928,874 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/05/01 12:43:58 | 000,000,000 | —- | M] () – C:\Documents and Settings\Terry Laderoute\Local Settings\Application Data\prvlcl.dat
[2011/05/01 08:47:39 | 000,001,984 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/30 14:29:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/30 07:05:58 | 000,475,026 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/30 07:05:58 | 000,077,084 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/29 16:24:54 | 000,410,288 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/29 00:46:48 | 000,000,512 | —- | M] () – C:\Documents and Settings\Terry Laderoute\Desktop\MBR.dat
[2011/04/29 00:46:08 | 000,567,296 | —- | M] (AVAST Software) – C:\Documents and Settings\Terry Laderoute\Desktop\aswMBR.exe
[2011/04/29 00:38:54 | 000,625,664 | —- | M] () – C:\Documents and Settings\Terry Laderoute\Desktop\dds.scr
[2011/04/28 23:05:03 | 000,000,306 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3116237007-3362448852-429834905-1006.job
[2011/04/28 00:45:25 | 000,002,467 | —- | M] () – C:\Documents and Settings\Terry Laderoute\Desktop\HiJackThis.lnk
[2011/04/27 15:05:14 | 000,017,460 | —- | M] () – C:\Documents and Settings\Terry Laderoute\Application Data\wklnhst.dat
[2011/04/27 12:41:12 | 000,000,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/04/27 11:57:35 | 000,000,807 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Second Life Viewer 2.lnk
[2011/04/25 06:47:31 | 000,000,865 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Phoenix Viewer.lnk
[2011/04/23 12:01:56 | 000,000,690 | —- | M] () – C:\Documents and Settings\Terry Laderoute\Desktop\SpywareBlaster.lnk
[2011/04/18 05:59:32 | 000,015,880 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2011/04/14 14:18:27 | 000,000,650 | —- | M] () – C:\Documents and Settings\Terry Laderoute\Desktop\GolfStar.lnk
[2011/04/11 13:44:46 | 000,001,208 | —- | M] () – C:\Documents and Settings\Terry Laderoute\Desktop\Free Online Games (FOG).url
[2011/04/06 21:21:43 | 000,000,191 | —- | M] () – C:\Documents and Settings\Terry Laderoute\Desktop\More SpinTop Games.url
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/01 17:19:00 | 113,928,874 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/04/29 00:46:48 | 000,000,512 | —- | C] () – C:\Documents and Settings\Terry Laderoute\Desktop\MBR.dat
[2011/04/29 00:38:53 | 000,625,664 | —- | C] () – C:\Documents and Settings\Terry Laderoute\Desktop\dds.scr
[2011/04/28 00:45:01 | 000,002,467 | —- | C] () – C:\Documents and Settings\Terry Laderoute\Desktop\HiJackThis.lnk
[2011/04/27 11:57:35 | 000,000,807 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Second Life Viewer 2.lnk
[2011/04/23 12:01:56 | 000,000,690 | —- | C] () – C:\Documents and Settings\Terry Laderoute\Desktop\SpywareBlaster.lnk
[2011/04/14 14:18:24 | 000,000,650 | —- | C] () – C:\Documents and Settings\Terry Laderoute\Desktop\GolfStar.lnk
[2011/04/11 13:44:46 | 000,001,208 | —- | C] () – C:\Documents and Settings\Terry Laderoute\Desktop\Free Online Games (FOG).url
[2011/04/08 04:32:51 | 000,000,690 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2010/11/03 12:05:37 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2010/11/03 12:05:37 | 000,000,039 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2010/09/22 18:09:15 | 000,815,104 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/09/22 18:09:15 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2010/06/10 10:49:43 | 000,000,021 | —- | C] () – C:\WINDOWS\phbase.ini
[2010/06/10 10:46:22 | 000,000,021 | —- | C] () – C:\WINDOWS\Ps_setup.ini
[2009/12/09 01:18:10 | 000,000,000 | —- | C] () – C:\Documents and Settings\Terry Laderoute\Local Settings\Application Data\prvlcl.dat
[2009/04/05 07:20:20 | 000,000,022 | —- | C] () – C:\WINDOWS\iexplore.ini
[2009/04/01 22:09:44 | 000,026,624 | —- | C] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2009/02/25 22:39:48 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2008/11/04 19:11:48 | 000,000,000 | —- | C] () – C:\WINDOWS\popcreg.dat
[2008/11/04 18:03:38 | 000,000,042 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2008/10/12 22:37:08 | 000,000,100 | —- | C] () – C:\WINDOWS\Iout10.bin
[2007/11/14 14:58:17 | 000,001,984 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/11/05 16:09:08 | 000,000,256 | —- | C] () – C:\WINDOWS\onlineeye.INI
[2007/05/21 11:16:44 | 000,000,060 | —- | C] () – C:\WINDOWS\ZDDBView.INI
[2007/05/21 11:16:39 | 000,000,071 | —- | C] () – C:\WINDOWS\zdbui32.ini
[2007/04/12 15:40:39 | 000,086,304 | —- | C] () – C:\WINDOWS\RHVIDEO.DLL
[2007/04/06 23:59:02 | 000,106,549 | —- | C] () – C:\WINDOWS\system86.dll
[2007/04/06 23:59:02 | 000,035,840 | —- | C] () – C:\WINDOWS\drvmgt.dll
[2007/04/06 23:59:02 | 000,028,400 | —- | C] () – C:\WINDOWS\secdrv.sys
[2007/03/22 22:52:26 | 000,000,077 | —- | C] () – C:\WINDOWS\Sierra.ini
[2007/03/21 15:13:01 | 000,016,137 | —- | C] () – C:\WINDOWS\System32\tablet.dat
[2007/03/05 13:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/12/26 10:00:14 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2006/11/23 23:19:53 | 000,000,004 | —- | C] () – C:\WINDOWS\System32\proc625010911.bin
[2006/11/12 19:03:43 | 000,000,238 | —- | C] () – C:\WINDOWS\cncscore.ini
[2006/11/03 16:10:41 | 000,000,770 | —- | C] () – C:\WINDOWS\Sof2.INI
[2006/09/18 16:25:13 | 001,630,208 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2006/09/18 16:25:12 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/09/18 16:25:12 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/09/18 16:25:10 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/09/18 16:25:08 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/09/18 16:25:06 | 001,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/09/18 16:25:06 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2006/09/18 16:25:06 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/09/18 16:25:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2006/09/18 16:24:57 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2006/09/08 16:51:33 | 000,000,000 | —- | C] () – C:\WINDOWS\pool.INI
[2006/07/15 00:51:30 | 000,000,064 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2006/07/06 17:02:01 | 000,001,126 | —- | C] () – C:\WINDOWS\yahtzee.ini
[2006/07/01 08:15:55 | 000,003,046 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/06/14 17:06:06 | 000,005,649 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/05/23 12:58:39 | 000,743,016 | —- | C] () – C:\WINDOWS\System32\GoogleDesktopSearchSetup.exe
[2006/05/23 12:01:58 | 000,012,288 | —- | C] () – C:\Documents and Settings\Terry Laderoute\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/23 18:51:46 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/04/23 18:50:47 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/03/24 08:47:59 | 000,000,044 | —- | C] () – C:\WINDOWS\liveup.ini
[2006/03/24 08:21:37 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006/03/20 00:29:44 | 000,000,094 | -H– | C] () – C:\WINDOWS\System32\tbd_G1ssg.ini
[2006/02/13 23:23:36 | 000,001,089 | —- | C] () – C:\WINDOWS\eReg.dat
[2006/02/08 18:26:33 | 000,000,094 | -H– | C] () – C:\WINDOWS\System32\tlr_WAasw.ini
[2006/01/22 19:52:57 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2006/01/22 11:20:13 | 000,000,571 | —- | C] () – C:\WINDOWS\maxlink.ini
[2006/01/22 11:19:18 | 000,000,000 | —- | C] () – C:\WINDOWS\OP70.INI
[2006/01/22 11:14:52 | 000,001,511 | —- | C] () – C:\WINDOWS\pstudio.ini
[2006/01/22 11:14:52 | 000,000,028 | —- | C] () – C:\WINDOWS\album.ini
[2006/01/21 13:50:44 | 000,079,648 | —- | C] () – C:\WINDOWS\hpfins05.dat
[2006/01/21 13:50:44 | 000,001,350 | —- | C] () – C:\WINDOWS\hpfmdl05.dat
[2006/01/21 13:50:24 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/01/20 19:14:25 | 000,017,460 | —- | C] () – C:\Documents and Settings\Terry Laderoute\Application Data\wklnhst.dat
[2006/01/20 15:59:35 | 000,002,516 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/01/20 15:59:35 | 000,000,056 | RHS- | C] () – C:\WINDOWS\System32\74741EAEEC.sys
[2006/01/20 15:45:09 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/01/15 11:36:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/01/15 11:30:46 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/01/15 11:29:18 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/01/15 11:26:52 | 000,000,304 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/01/15 11:22:55 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/01/15 11:00:38 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/01/15 11:00:20 | 000,000,493 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/04/09 19:04:54 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 15:12:05 | 000,000,831 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 15:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 15:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 15:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 14:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 14:57:15 | 000,410,288 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 14:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 14:51:20 | 000,475,026 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 14:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 14:51:20 | 000,077,084 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 14:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 14:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 14:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 14:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 14:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 14:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 14:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 14:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/03/14 12:00:26 | 000,038,567 | —- | C] () – C:\WINDOWS\System32\pcpbios.exe
[1999/01/22 22:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== LOP Check ==========

[2007/03/11 15:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\55-68-75-o0-2o-66
[2009/02/28 22:18:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AdventureChronicles1
[2010/12/26 17:17:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
[2011/04/08 04:36:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/17 20:17:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2007/04/12 16:06:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund LLC
[2006/12/25 11:20:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2007/06/19 21:13:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CaveDays
[2006/07/23 14:22:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Chasing Dogs Studios
[2010/10/17 20:32:34 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/11/05 21:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverScanner
[2006/02/09 20:22:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EA
[2007/06/18 14:23:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Escape From Paradise
[2009/01/30 10:47:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
[2008/10/28 19:22:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2010/07/18 21:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Floodlight Games
[2007/05/26 17:47:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FloodLightGames
[2008/10/09 23:39:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2009/07/14 03:01:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gamers Digital
[2008/11/06 21:21:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gogii
[2008/12/04 22:01:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gogii Games
[2006/12/08 18:40:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HipSoft
[2009/07/17 06:15:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\hitpointstudios
[2007/05/03 18:49:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2006/10/16 11:58:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Leenie Games
[2011/04/08 04:39:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/04/05 07:20:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2007/04/01 22:35:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2009/05/18 07:06:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2007/07/15 18:31:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/03/09 21:20:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayPond
[2008/11/04 18:03:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2009/01/23 10:10:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2011/04/08 03:55:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2007/03/22 22:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sierra
[2008/10/28 23:57:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2007/08/21 18:06:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SugarGames
[2007/10/20 08:53:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2011/04/06 22:23:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/04/09 21:08:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TERMINAL Studio
[2006/06/17 21:07:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ThwartPoker Software
[2007/06/14 06:13:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/05/04 16:36:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zylom
[2009/11/05 21:40:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}
[2009/10/30 05:58:24 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2006/02/17 21:43:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\7Wonders
[2009/07/17 04:31:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Aisle 5 Games, Inc
[2011/02/03 21:28:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Alawar
[2009/12/06 22:45:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Audacity
[2010/10/17 20:35:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\AVG10
[2006/10/21 18:17:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Balloon Express
[2006/05/23 12:59:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Beep
[2006/11/02 20:43:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Beep Industries
[2008/03/16 19:07:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\BloodTies
[2010/07/26 15:00:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Boolat Games
[2010/06/10 11:37:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Canon
[2006/07/23 14:22:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Chasing Dogs Studios
[2007/01/04 14:43:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Chessmaster Challenge
[2007/05/03 18:23:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\DiVision Studios - Escaping Atlantis
[2006/02/09 20:22:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\EA
[2009/11/05 07:23:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\ElevatedDiagnostics
[2008/03/29 18:55:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\fizzy
[2008/10/28 19:22:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Flood Light Games
[2010/07/18 21:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Floodlight Games
[2007/05/26 17:47:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\FloodLightGames
[2007/03/31 17:13:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\FlowPlay
[2009/02/02 17:47:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Friday's games
[2008/11/06 16:23:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\funkitron
[2008/11/08 19:07:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\GameHouse
[2008/11/07 02:17:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\GameHousev1005
[2009/07/14 03:01:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Gamers Digital
[2008/12/04 22:01:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Gogii Games
[2007/01/13 00:36:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\ieSpell
[2006/05/03 20:36:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Image Zone Express
[2006/01/22 18:09:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Individual Software
[2008/01/07 08:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\ISP Monitor
[2008/10/27 16:27:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\iWin
[2006/01/20 21:02:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Leadertech
[2007/04/25 22:57:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Magic Academy
[2007/04/06 21:57:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\MagicBall3
[2010/08/23 20:35:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\MagicIndie
[2007/08/28 18:21:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\mobileweapon
[2006/01/25 20:10:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\MSNInstaller
[2007/08/18 14:05:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Mysteryville2
[2011/04/30 13:12:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\NetAssistant
[2006/02/01 12:26:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Nikon
[2006/11/12 19:17:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Nology
[2007/03/19 13:32:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\OfficeUpdate12
[2010/05/23 22:24:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\OpenCandy
[2006/12/30 22:18:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Pi Eye Games
[2007/03/07 20:08:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\pixelStorm
[2009/01/22 21:59:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\PlayFirst
[2011/02/04 19:22:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Pogo Games
[2011/03/26 17:28:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\SecondLife
[2007/03/22 22:56:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Sierra
[2008/10/12 21:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Skip-Bo
[2008/10/13 00:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\SpinTop
[2009/07/17 03:22:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Spintop 3 Days Zoo Mystery
[2010/12/23 21:42:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\SpinTop Games
[2008/05/29 22:51:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\SystemRequirementsLab
[2006/04/28 10:45:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Template
[2006/06/17 21:07:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\ThwartPoker Software
[2009/03/20 15:31:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Total Eclipse
[2009/10/30 03:45:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Uniblue
[2007/06/14 06:13:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Viewpoint
[2006/06/03 19:44:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Wildfire
[2006/11/22 23:29:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Terry Laderoute\Application Data\Zen Puzzle Garden
[2011/05/01 19:37:48 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
[2011/05/01 19:37:49 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
[2011/05/01 19:37:51 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
[2011/05/01 19:37:52 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
[2011/05/01 19:37:53 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:581C05D1
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB2A7E51
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8AA50F13
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:54997B77
@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:047D0F14
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EAB3DBA7
@Alternate Data Stream - 94 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C5E4F943
@Alternate Data Stream - 94 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:95DE6783
@Alternate Data Stream - 94 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:36E6A05E
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B7A5DE6E
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E87F4522
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E65BB25A
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA8ADCCD
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8C08E7E
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DED60D49
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8402E62C
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F488E44F
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BF4CC16B
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:56EE2CAF
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:16A851AD
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F6424B89
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CBAC4FD8
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C24B973A
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1C77FDF4
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1AE68282
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D6CC3E51
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A916C041
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:618BF152
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:13095727
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B8AF0F0F
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6444780F
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D2C51E3D
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4220A65C
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:87F524B2
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:83E716F0
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7B60301F
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B00070D
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F5A3657A
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DA723860
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:78AFAE94
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC9ECE7B
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2EBBBA95
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BEC3E79A
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8AB6C1D7
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:10769EA7
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B9000539
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AB779CF8
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B618BFFE
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:13D82150
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FE09DDA8
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C99F6ECA
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7B212553
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:478FEFC3
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3E69E337
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F00E008B
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BB24555F
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E8AD7B8D
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DA3C6C07
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D09AEE3D
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7C60A173
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FD6B3FC3
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CE8F70B0
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5E7801FF
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1A6AFE3D
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:174CD35A
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FFFCB9A9
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E736CE6B
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:ADF211B1
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8BB2EC84
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2EF63291
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A42CF494
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8F43582B
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:77A023CE
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2FAF48B0
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4A0EF59B
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D853F961
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:712DCF50
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:540BAA06
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D650D56C
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:52A6151E
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:15FBBE31

< End of report >
OTL Extras logfile created on: 01/05/2011 7:45:42 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Terry Laderoute\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 379.00 Mb Available Physical Memory | 37.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 59.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.05 Gb Total Space | 33.71 Gb Free Space | 47.44% Space Free | Partition Type: NTFS

Computer Name: DJY99691 | User Name: Terry Laderoute | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1"
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1"
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Disabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client – (Hewlett-Packard)
"C:\Program Files\ASAP Games\Pearl Harbor - Zero Hour\PHarbor.exe" = C:\Program Files\ASAP Games\Pearl Harbor - Zero Hour\PHarbor.exe:*:Enabled:PHarbor
"C:\Program Files\Infogrames\Pacific Gunner\PacificGunner.exe" = C:\Program Files\Infogrames\Pacific Gunner\PacificGunner.exe:*:Enabled:Sunrise
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\3DO\Gulf War\exes\D3D_R.exe" = C:\Program Files\3DO\Gulf War\exes\D3D_R.exe:*:Enabled:D3D_R
"C:\Program Files\DigitalFusion\Beach Head - Desert War\BH2Game\BH2.exe" = C:\Program Files\DigitalFusion\Beach Head - Desert War\BH2Game\BH2.exe:*:Disabled:BH2
"C:\Program Files\Grisoft\AVG7\avginet.exe" = C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe" = C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe
"C:\Program Files\Grisoft\AVG7\avgcc.exe" = C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe
"C:\Program Files\Pando Networks\Pando\pando.exe" = C:\Program Files\Pando Networks\Pando\pando.exe:*:Disabled:pando
"C:\Program Files\3d Mini Golf\3D Mini Golf.exe" = C:\Program Files\3d Mini Golf\3D Mini Golf.exe:*:Disabled:3D Mini Golf
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Disabled:LimeWire
"C:\StubInstaller.exe" = C:\StubInstaller.exe:*:Disabled:LimeWire swarmed installer – (LimeWire)
"C:\Program Files\Yahoo! Games\Magic Ball\MagicBall.exe" = C:\Program Files\Yahoo! Games\Magic Ball\MagicBall.exe:*:Disabled:MagicBall
"C:\Program Files\EA GAMES\MOHAA\MOHAA.exe" = C:\Program Files\EA GAMES\MOHAA\MOHAA.exe:*:Disabled:Medal of Honor Allied Assault
"C:\Program Files\Paltalk Messenger\paltalk.exe" = C:\Program Files\Paltalk Messenger\paltalk.exe:*:Disabled:Paltalk Messenger 8.2
"C:\Program Files\Yahoo! Games\Yahoo! Pin High Country Club Golf\Course1.exe" = C:\Program Files\Yahoo! Games\Yahoo! Pin High Country Club Golf\Course1.exe:*:Disabled:Skyworks Pin High Country Club Golf
"C:\Program Files\LeechGet 2007\LeechGet.exe" = C:\Program Files\LeechGet 2007\LeechGet.exe:*:Enabled:LeechGet Download Manager – ()
"C:\Program Files\SecondLife\SLVoice.exe" = C:\Program Files\SecondLife\SLVoice.exe:*:Enabled:SLVoice
"C:\Program Files\SecondLifeWindLight\SLVoice.exe" = C:\Program Files\SecondLifeWindLight\SLVoice.exe:*:Enabled:SLVoice
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" = C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client
"C:\Program Files\SecondLife\SecondLife.exe" = C:\Program Files\SecondLife\SecondLife.exe:*:Enabled:Second Life
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Emerald Viewer\SLVoice.exe" = C:\Program Files\Emerald Viewer\SLVoice.exe:*:Enabled:SLVoice
"C:\Program Files\Phoenix Viewer\SLVoice.exe" = C:\Program Files\Phoenix Viewer\SLVoice.exe:*:Enabled:SLVoice – ()
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player – (Veoh Networks)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
"C:\gamigo\Golfstar\GSPatcherLoader.exe" = C:\gamigo\Golfstar\GSPatcherLoader.exe:*:Enabled:GolfStar_Patcher_Updater – ()
"C:\gamigo\Golfstar\GolfStarPatcher.exe" = C:\gamigo\Golfstar\GolfStarPatcher.exe:*:Enabled:GolfStar_Patcher – (Com2uS)
"C:\gamigo\Golfstar\GolfStar.exe" = C:\gamigo\Golfstar\GolfStar.exe:*:Enabled:GolfStar – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{06040048-3E21-46D6-9A91-D927BA08F41D}" = Microsoft Encarta Encyclopedia Standard 2006
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1266764D-FC4F-4FA7-B63B-884D53B1680F}" = NetAssistant
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{13AD768A-9E04-499D-AE80-967A65DCCBA5}" = ebgcSDK
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{17E3A651-12B9-4149-BAE8-E6FB9A5ADC4F}" = Microsoft Works Suite Add-in for Microsoft Word
"{18709D89-3957-46BD-BAEB-7E1632428C8F}" = ebgcRes
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD LE
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24
"{26DB09BC-6EB5-4CE0-A05D-D4DECE60E189}_is1" = Phoenix Viewer 1.5.2.1050
"{28E7B64D-150F-4A9E-B7A3-5A6AC8C2F822}" = ebgcSDK
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{39B1BD87-561E-4762-AED9-7C5213B06C24}" = ebgcInfra
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C0BAFCA-BDB8-492B-8845-DC0A4B4C1823}" = HPDeskjet5400Series
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{403EF592-953B-4794-BCEF-ECAB835C2095}" =
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B622B7A-60FB-4630-B11D-F121D20BCCD6}" = MarketResearch
"{5B782FFA-6A95-480D-8E0A-0954A14693D6}" =
"{5D95AD35-368F-47D5-B63A-A082DDF00116}" = Microsoft Digital Image Standard 2006 Editor
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6076AA59-9E37-47C9-8902-3AF310ED3098}_is1" = Trojan Killer 1.4
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.5
"{691F4068-81BF-49E3-B32E-FE3E16400112}" = Microsoft Digital Image Standard 2006 Library
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D3B268B-B33F-4D09-8365-31B82DF37066}" = ebgcRes
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7395D650-AE5D-4D68-B8FE-D3FA6B51467F}" = Driver Detective
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77E70C3C-DBB9-4C47-8663-1E1F81FEC623}" = Logitech QuickCam
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83ED1E80-A1B7-4226-BCF1-AC4A88151A6B}" = Microsoft Streets & Trips 2006
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel® PROSet for Wired Connections
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{851C67EF-068A-4060-9EF5-2E3DDCD68382}" = Adobe Photoshop Elements 3.0
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A0C7FBA0-4966-40E0-BD64-9367FFFF8F1D}" = Pro Publisher Professional Business Labels
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{A64FF1D4-9CBC-467C-8D11-C1AFAA0B8AFF}" = AVG 2011
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.6
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B702CCCE-3176-4DBF-B932-D1B8F402F330}" = Digital Content Portal
"{B8C54AB1-7E1A-40E8-B794-EDB6E8921F3A}" = Dell Support Center
"{B946D46E-1302-48B4-84EE-B74C3191D975}" = Corel Painter Essentials 2
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C427E746-4EC9-4E3C-AACB-C6BB1F714D7F}" = Uniblue DriverScanner 2009
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D4E53304-1F6C-4111-9872-1BCD2CF5B642}" = AVG 2011
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DE1AF137-C455-494A-A817-EFE44BCCFDEE}" = Works Upgrade
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E0A1559B-9886-11D4-8D06-0050DA284A39}" = Scan Manager 5.2
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EB57A16E-500D-43d7-85B9-FBE279EBBA6E}" = HP Deskjet 5400 series
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F857B51E-CED7-48C9-BE93-D586D8257CD8}" = ebgcRes
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"Ad-Aware" = Ad-Aware
"AddressBook" =
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ArcSoft PhotoBase" = ArcSoft PhotoBase
"ArcSoft PhotoStudio 2000" = ArcSoft PhotoStudio 2000
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.2 (Unicode)
"AudioPlugin.dll" =
"AVG" = AVG 2011
"Branding" =
"Canon ScanGear Toolbox 3.0" = Canon ScanGear Toolbox 3.0
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Connection Manager" =
"CopyNow.dll" =
"CTU: Marine Sharpshooter" = CTU: Marine Sharpshooter
"DataPlugin.dll" =
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"DirectAnimation" =
"DirectDrawEx" =
"DivX Setup.divx.com" = DivX Setup
"dlatray.exe" =
"DXM_Runtime" =
"Electronic Arts Game Updater" = Electronic Arts Game Updater
"Family Trees Quick & Easy" = Family Trees Quick & Easy
"Fontcore" =
"GameHouse" = GameHouse
"GolfStar" = GolfStar
"Google Updater" = Google Updater
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.0
"HPExtendedCapabilities" = HP Extended Capabilities 5.0
"ICW" =
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"IE40" =
"IE4Data" =
"IE5BAKEX" =
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IEData" =
"ieSpell" = ieSpell
"InstallShield Uninstall Information" =
"InstallShield_{7395D650-AE5D-4D68-B8FE-D3FA6B51467F}" = Driver Detective
"LeechGet 2007_is1" = LeechGet 2007 Version 2.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Interactive Training" =
"MobileOptionPack" =
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSI30a-KB884016" =
"MSI30-Beta1" =
"MSI30-Beta2" =
"MSI30-KB884016" =
"MSI30-RC1" =
"MSI30-RC2" =
"MSI31-Beta" =
"MSI31-RC1" =
"MSNINST" = MSN
"Need For Speed - Porsche Unleashed" = Need For Speed - Porsche Unleashed
"NetMeeting" =
"nik Color Efex Pro 2.0 GE" = nik Color Efex Pro 2.0 GE
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OmniPagePro9.0DeinstKey" = OmniPage Pro 9.0
"OutlookExpress" =
"PCHealth" =
"PictureItPrem_v11" = Microsoft Digital Image Standard 2006
"PROSet" = Intel® PRO Network Connections Drivers
"RealPlayer 12.0" = RealPlayer
"RegScrubXP_is1" = RegScrubXP 3.25
"Ricochet Infinity" = Ricochet Infinity
"Sandlot Games Client Services_is1" = Sandlot Games Client Services
"SchedulingAgent" =
"SecondLifeViewer2" = SecondLifeViewer2 (remove only)
"Security Task Manager" = Security Task Manager 1.8c
"Shockwave" = Shockwave
"ShotOnline International" = ShotOnline International
"Soldier of Fortune II - Double Helix" = Soldier of Fortune II - Double Helix
"SpywareBlaster_is1" = SpywareBlaster 4.4
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SystemRequirementsLab" = System Requirements Lab
"Tablet Driver" = Tablet
"Trusted Software Assistant_is1" = File Type Assistant
"Uniblue DriverScanner 2009" = Uniblue DriverScanner 2009
"Uninstall_is1" = Uninstall 1.0.0.1
"Veoh Web Player Beta" = Veoh Web Player
"ViewpointMediaPlayer" = Viewpoint Media Player
"Virtools3DLifePlayer" = Virtools 3D Life Player
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMCSetup" =
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2006Setup" = Microsoft Works Suite 2006 Setup Launcher
"World War 2: Sniper" = World War 2: Sniper
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.1 final uninstall
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"NetAssistant" = NetAssistant for Firefox
"WeatherEye" = WeatherEye

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 28/04/2011 12:00:46 PM | Computer Name = DJY99691 | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 29/04/2011 6:08:32 AM | Computer Name = DJY99691 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 29/04/2011 6:10:15 AM | Computer Name = DJY99691 | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 29/04/2011 6:15:27 AM | Computer Name = DJY99691 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 29/04/2011 6:15:41 AM | Computer Name = DJY99691 | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 01/05/2011 7:40:29 PM | Computer Name = DJY99691 | Source = nview_info | ID = 11141121
Description =

Error - 01/05/2011 7:40:29 PM | Computer Name = DJY99691 | Source = nview_info | ID = 11141121
Description =

Error - 01/05/2011 7:40:31 PM | Computer Name = DJY99691 | Source = nview_info | ID = 11141121
Description =

Error - 01/05/2011 7:40:31 PM | Computer Name = DJY99691 | Source = nview_info | ID = 11141121
Description =

Error - 01/05/2011 7:40:31 PM | Computer Name = DJY99691 | Source = nview_info | ID = 11141121
Description =

[ System Events ]
Error - 01/05/2011 8:42:35 AM | Computer Name = DJY99691 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 01/05/2011 8:44:37 AM | Computer Name = DJY99691 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MSIServer with
arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}

Error - 01/05/2011 8:53:44 AM | Computer Name = DJY99691 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 01/05/2011 8:53:54 AM | Computer Name = DJY99691 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 01/05/2011 8:57:35 AM | Computer Name = DJY99691 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 01/05/2011 8:58:22 AM | Computer Name = DJY99691 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 01/05/2011 9:01:26 AM | Computer Name = DJY99691 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 01/05/2011 9:01:43 AM | Computer Name = DJY99691 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 01/05/2011 9:02:02 AM | Computer Name = DJY99691 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 01/05/2011 9:05:18 AM | Computer Name = DJY99691 | Source = System Error | ID = 1003
Description = Error code 100000d4, parameter1 a941e038, parameter2 0000001c, parameter3
00000001, parameter4 80502cd6.


< End of report >
C:\My Music\Happy Wanderer Polka.wma a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Program Files\Mozilla Firefox\components\rpff.dll probably a variant of Win32/Adware.GabPath.AH application
Copy of eset scan results C:\My Music\Happy Wanderer Polka.wma a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Program Files\Mozilla Firefox\components\rpff.dll probably a variant of Win32/Adware.GabPath.AH application
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6487 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 01/05/2011 10:27:36 PM mbam-log-2011-05-01 (22-27-36).txt Scan type: Quick scan Objects scanned: 163511 Time elapsed: 6 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hello Terry, Good job so far :thumbup:
Do this next please:
Please go to one of the below sites to scan the following files:
jotti.org
Kaspersky Virus File Scanner
Virus Total
Click on Browse, and upload the following files for analysis:
C:\My Music\Happy Wanderer Polka.wma
C:\Program Files\Mozilla Firefox\components\rpff.dll


Then click Submit. Allow the files to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

Next
Your Java appears to be down level.
Navigate to Control Panel then open on Programs and Features.
Highlight eachJava then click on Uninstall in tool bar.
Visit this site to down load and install the latest Java.

Next
Your Adobe appears to be downl level.
Visit this site http://www.adobe.com/downloads/ click on Adobe Reader, you will be given the latest Adobe reader for your system.
Download and install.

Next
Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Next
Download and run Puran Disk Defragmenter

Please post the results of the files scan and let me know how your PC is behaving now.

Thanks
Bill
In Training at WTT Classroom

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI