This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Phony Microsoft XP Security dialog boxes

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a laptop that started showing phony Microsoft XP Security dialog boxes that told me I had 25 infected files. I ran an avira virus scan and it deleted some things but now the computer will not run any exe files. I tried to open Microsoft Outlook and I got the "Choose the program you want to use to open this file" dialog box. I tried to run HiJackThis to post a log here and got the same dialog box. Same with OTL. Any help would be GREATLY appreciated! Scott
Ok….I used exehelper from this forum and got OTL to run. Log is attached below…Thanks for any help!




OTL logfile created on: 5/4/2011 3:21:15 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Scott\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.00 Mb Total Physical Memory | 129.00 Mb Available Physical Memory | 26.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.50 Gb Total Space | 11.73 Gb Free Space | 14.57% Space Free | Partition Type: NTFS
Drive D: | 11.62 Gb Total Space | 1.37 Gb Free Space | 11.78% Space Free | Partition Type: FAT32

Computer Name: LAPTOP | User Name: Scott | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/05/02 17:01:02 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Scott\Desktop\OTL.exe
PRC - [2009/07/21 14:34:33 | 000,185,089 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009/05/13 16:48:22 | 000,108,289 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/08/09 02:27:52 | 000,073,728 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe
PRC - [2006/05/09 16:11:10 | 000,176,128 | —- | M] (Starz Entertainment Group LLC) – C:\Program Files\Vongo\VongoService.exe
PRC - [2006/03/30 09:15:44 | 000,096,341 | —- | M] (Canon Inc.) – C:\Program Files\Canon\CAL\CALMAIN.exe


========== Modules (SafeList) ==========

MOD - [2011/05/02 17:01:02 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Scott\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - [2009/07/21 14:34:33 | 000,185,089 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2009/05/13 16:48:22 | 000,108,289 | —- | M] (Avira GmbH) [Auto | Running] – C:\Program Files\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2008/08/29 10:00:30 | 000,033,752 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe – (getPlus® Helper) getPlus®
SRV - [2008/06/06 15:47:24 | 000,085,096 | —- | M] (Autodesk) [On_Demand | Stopped] – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe – (Autodesk Licensing Service)
SRV - [2007/08/09 02:27:52 | 000,073,728 | —- | M] (HP) [Auto | Running] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2006/06/12 15:27:28 | 000,126,976 | —- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe – (AddFiltr)
SRV - [2006/05/09 16:11:10 | 000,176,128 | —- | M] (Starz Entertainment Group LLC) [Auto | Running] – C:\Program Files\Vongo\VongoService.exe – (Vongo Service)
SRV - [2006/03/30 09:15:44 | 000,096,341 | —- | M] (Canon Inc.) [Auto | Running] – C:\Program Files\Canon\CAL\CALMAIN.exe – (CCALib8)


========== Driver Services (SafeList) ==========

DRV - [2009/12/07 17:33:15 | 000,056,816 | —- | M] (Avira GmbH) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\avgntflt.sys – (avgntflt)
DRV - [2009/05/11 10:12:24 | 000,028,520 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ssmdrv.sys – (ssmdrv)
DRV - [2009/03/30 10:33:07 | 000,096,104 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avipbb.sys – (avipbb)
DRV - [2009/02/13 12:35:05 | 000,011,608 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\Program Files\Avira\AntiVir Desktop\avgio.sys – (avgio)
DRV - [2009/02/04 20:19:34 | 000,018,560 | —- | M] (LeapFrog) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\FlyUsb.sys – (FlyUsb)
DRV - [2008/05/08 09:02:52 | 000,203,136 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\rmcast.sys – (RMCAST)
DRV - [2008/04/13 13:39:44 | 000,092,544 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mqac.sys – (MQAC)
DRV - [2007/02/24 10:35:27 | 000,012,464 | —- | M] (Macrovision Europe Ltd) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\CdaD10BA.SYS – (CdaD10BA)
DRV - [2006/11/02 08:00:08 | 000,039,368 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\winusb.sys – (WinUSB)
DRV - [2006/06/02 10:02:36 | 000,572,928 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\CHDAud.sys – (HdAudAddService)
DRV - [2006/05/12 15:05:02 | 000,057,320 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btwusb.sys – (BTWUSB)
DRV - [2006/04/28 12:12:00 | 000,429,184 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2006/04/21 12:06:24 | 001,429,632 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\w39n51.sys – (w39n51) Intel®
DRV - [2006/04/20 11:03:20 | 000,995,712 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DPV.sys – (HSF_DPV)
DRV - [2006/04/20 11:02:40 | 000,208,000 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWAZL.sys – (HSFHWAZL)
DRV - [2006/04/20 11:02:36 | 000,727,296 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2005/12/22 12:02:22 | 000,051,840 | —- | M] (REDC) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2005/11/16 15:28:32 | 000,028,928 | —- | M] (REDC) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2005/11/01 13:08:00 | 000,308,992 | —- | M] (REDC) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2005/09/19 16:24:20 | 000,005,760 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\EabUsb.sys – (eabusb)
DRV - [2005/09/19 16:24:10 | 000,009,344 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\CPQBttn.sys – (HBtnKey)
DRV - [2005/09/19 16:23:52 | 000,007,808 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\eabfiltr.sys – (eabfiltr)
DRV - [2004/08/04 01:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.jsonline.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50370
FF - prefs.js..network.proxy.type: 1

FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/01/04 15:48:22 | 000,000,000 | —D | M]

[2009/09/12 07:03:35 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Scott\Application Data\Mozilla\Extensions
[2009/10/29 19:10:11 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\liyu9nuq.default\extensions
[2009/09/12 07:06:40 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\liyu9nuq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/21 16:56:23 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2008/01/30 14:48:38 | 000,074,280 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npsharedview.dll

O1 HOSTS File: ([2010/12/06 17:39:01 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe ()
O4 - HKLM..\Run: [HP Software Update] File not found
O4 - HKLM..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPHUPD05] C:\Program Files\HP\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe ()
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\Scott\Start Menu\Programs\StartUp\Vongo Tray.lnk = C:\Documents and Settings\Scott\Application Data\Microsoft\Installer\{DB7E00C9-6DEF-489A-8112-D8F81614F45A}\NewShortcut2_DB7E00C96DEF489A8112D8F81614F45A.exe (Macrovision Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB (Hewlett-Packard Online Support Services)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://mypoints.worldwinner.com/games/v46/…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} http://www.infospace.com/mypoints.main/tba…pointsSetup.exe (Reg Error: Key error.)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Groove Control)
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file:///C:/Program%20Files/AutoCAD%202002/AcDcToday.ocx (AcDcToday Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control)
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} file:///C:/Program%20Files/AutoCAD%202002/InstBanr.ocx (NOXLATE-BANR)
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} file:///C:/Program%20Files/AutoCAD%202002/InstFred.ocx (InstaFred)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file:///C:/Program%20Files/AutoCAD%202002/AcPreview.ocx (AcPreview Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Scott\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Scott\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 22:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/02 17:00:56 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Scott\Desktop\OTL.exe
[2011/05/02 16:59:21 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Scott\Desktop\HiJackThis.exe
[2011/04/11 19:50:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Scott\Desktop\pig
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/04 15:19:33 | 000,294,400 | —- | M] () – C:\Documents and Settings\Scott\Desktop\exeHelper.com
[2011/05/04 15:03:18 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/04 15:02:08 | 000,002,301 | —- | M] () – C:\Documents and Settings\Scott\Start Menu\Programs\StartUp\Vongo Tray.lnk
[2011/05/04 15:01:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/04 15:01:54 | 526,438,400 | -HS- | M] () – C:\hiberfil.sys
[2011/05/02 17:01:02 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Scott\Desktop\OTL.exe
[2011/05/02 16:59:29 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Scott\Desktop\HiJackThis.exe
[2011/05/01 13:49:46 | 000,013,848 | -HS- | M] () – C:\Documents and Settings\Scott\Local Settings\Application Data\3o0c6os3k3qwg6hdqqf84dawvuh515sg
[2011/05/01 13:49:46 | 000,013,848 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\3o0c6os3k3qwg6hdqqf84dawvuh515sg
[2011/04/14 20:06:10 | 000,455,802 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/14 20:06:10 | 000,075,750 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/13 15:03:03 | 000,000,792 | —- | M] () – C:\Documents and Settings\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/04/13 03:40:33 | 000,384,816 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/13 03:18:28 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/04 15:19:32 | 000,294,400 | —- | C] () – C:\Documents and Settings\Scott\Desktop\exeHelper.com
[2011/05/01 06:41:22 | 000,013,848 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\3o0c6os3k3qwg6hdqqf84dawvuh515sg
[2011/05/01 06:41:21 | 000,013,848 | -HS- | C] () – C:\Documents and Settings\Scott\Local Settings\Application Data\3o0c6os3k3qwg6hdqqf84dawvuh515sg
[2010/12/03 17:08:17 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\7lRL0ux1i.dat
[2010/05/08 17:43:54 | 000,103,193 | —- | C] () – C:\WINDOWS\hpoins08.dat
[2010/05/08 17:43:54 | 000,004,445 | —- | C] () – C:\WINDOWS\hpomdl08.dat
[2010/03/07 09:06:36 | 000,000,034 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/09/12 07:03:25 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/04/17 09:00:51 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/06/21 10:26:30 | 000,303,680 | —- | C] () – C:\Program Files\07-Seems to Want to Hurt This Time-Donna the Buffalo.mp3
[2008/06/21 10:15:04 | 007,825,688 | —- | C] () – C:\Program Files\06-If You Only Could-Donna the Buffalo.mp3
[2008/06/21 10:13:47 | 009,167,340 | —- | C] () – C:\Program Files\05-Riddle of the Universe-Donna the Buffalo.mp3
[2008/06/21 10:09:10 | 011,456,620 | —- | C] () – C:\Program Files\04-Family Picture-Donna the Buffalo.mp3
[2008/06/21 10:03:55 | 015,836,080 | —- | C] () – C:\Program Files\03-America-Donna the Buffalo.mp3
[2008/06/21 10:00:56 | 009,014,965 | —- | C] () – C:\Program Files\02-Tides of Time-Donna the Buffalo.mp3
[2008/06/21 09:59:02 | 008,899,735 | —- | C] () – C:\Program Files\01-In This Life-Donna the Buffalo.mp3
[2008/06/21 09:55:19 | 012,488,565 | —- | C] () – C:\Program Files\11-Narada Muni-GODFREY TOWNSEND.mp3
[2008/06/21 09:48:43 | 007,041,860 | —- | C] () – C:\Program Files\10-Cold-GODFREY TOWNSEND.mp3
[2008/06/21 09:47:14 | 009,003,275 | —- | C] () – C:\Program Files\09-Whitefeather-GODFREY TOWNSEND.mp3
[2008/06/21 09:45:06 | 012,240,570 | —- | C] () – C:\Program Files\08-The Apostle-GODFREY TOWNSEND.mp3
[2008/06/21 09:44:14 | 007,997,935 | —- | C] () – C:\Program Files\07-Gaga Over Raga-GODFREY TOWNSEND.mp3
[2008/06/21 09:38:14 | 008,451,340 | —- | C] () – C:\Program Files\06-Easy Journey To Other Planets-GODFREY TOWNSEND.mp3
[2008/06/21 09:30:51 | 009,054,210 | —- | C] () – C:\Program Files\05-Hazel Street-GODFREY TOWNSEND.mp3
[2008/06/21 09:29:33 | 010,911,250 | —- | C] () – C:\Program Files\04-Long Misty Bridge-GODFREY TOWNSEND.mp3
[2008/06/21 09:26:42 | 008,027,995 | —- | C] () – C:\Program Files\02-Closer 2 U-GODFREY TOWNSEND.mp3
[2008/06/21 09:20:34 | 003,824,605 | —- | C] () – C:\Program Files\01-Astral Progression-GODFREY TOWNSEND.mp3
[2008/06/21 09:14:18 | 012,205,057 | —- | C] () – C:\Program Files\05 Internet Song.mp3
[2008/06/21 09:14:09 | 020,486,195 | —- | C] () – C:\Program Files\07-For Today-Camel.mp3
[2008/06/21 09:08:56 | 015,413,570 | —- | C] () – C:\Program Files\06-Squigely Fair-Camel.mp3
[2008/06/21 09:03:31 | 006,856,490 | —- | C] () – C:\Program Files\05-The Miller's Tale-Camel.mp3
[2008/06/21 08:48:28 | 021,629,310 | —- | C] () – C:\Program Files\01-A Nod and a Wink-Camel.mp3
[2008/06/21 08:48:28 | 017,875,150 | —- | C] () – C:\Program Files\04-Fox Hill-Camel.mp3
[2008/06/21 08:48:28 | 014,076,735 | —- | C] () – C:\Program Files\03-A Boy's Life-Camel.mp3
[2008/06/21 08:48:28 | 010,593,115 | —- | C] () – C:\Program Files\02-Simple Pleasures-Camel.mp3
[2008/06/12 20:39:50 | 000,018,944 | R— | C] () – C:\WINDOWS\eraser.exe
[2008/01/14 17:47:06 | 000,099,712 | —- | C] () – C:\WINDOWS\HPBroker.dll
[2007/10/09 15:21:53 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/09/07 15:53:17 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007/05/04 00:54:44 | 000,000,016 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2007/03/19 16:33:16 | 000,000,785 | —- | C] () – C:\WINDOWS\checkip.dat
[2007/02/10 12:20:06 | 000,000,000 | —- | C] () – C:\WINDOWS\Setup32.INI
[2007/01/10 17:12:46 | 000,000,478 | —- | C] () – C:\Documents and Settings\Scott\Application Data\wklnhst.dat
[2006/12/27 17:55:49 | 000,019,739 | —- | C] () – C:\WINDOWS\HPHins02.dat
[2006/12/27 17:55:48 | 000,004,284 | —- | C] () – C:\WINDOWS\hphmdl02.dat
[2006/12/27 17:55:23 | 000,364,544 | —- | C] () – C:\WINDOWS\System32\hphped05.exe
[2006/12/27 17:55:12 | 000,006,478 | —- | C] () – C:\WINDOWS\System32\hphmon05.dat
[2006/12/27 14:15:03 | 000,081,408 | —- | C] () – C:\Documents and Settings\Scott\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/27 10:34:37 | 000,000,128 | —- | C] () – C:\Documents and Settings\Scott\Local Settings\Application Data\fusioncache.dat
[2006/09/12 03:53:13 | 000,000,174 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/09/12 03:49:07 | 000,045,929 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/09/12 03:49:07 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/09/12 03:35:40 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/09/12 03:24:46 | 000,028,836 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/06/29 14:18:28 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/06/29 14:18:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/29 13:49:18 | 000,087,268 | —- | C] () – C:\WINDOWS\hpqins69.dat
[2006/06/29 13:46:56 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/06/29 13:43:40 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/06/29 13:27:08 | 000,455,802 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/06/29 13:27:08 | 000,075,750 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/06/29 13:18:06 | 000,384,816 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/06/29 13:13:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/06/29 13:08:28 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/03/15 23:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/03/15 23:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/03/15 23:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/03/15 23:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/03/15 23:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/03/15 23:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/03/15 23:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/03/15 23:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/03/04 02:07:34 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/12/02 13:09:10 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/26 15:28:20 | 000,024,576 | —- | C] () – C:\WINDOWS\shortcut.exe
[2005/08/26 14:28:34 | 000,143,360 | —- | C] () – C:\WINDOWS\unzip.exe
[2005/08/26 14:27:58 | 000,045,056 | —- | C] () – C:\WINDOWS\devenum.exe
[2005/05/06 13:06:32 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2004/09/16 15:24:26 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2003/01/07 17:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/05/28 16:55:42 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/05/28 16:54:40 | 000,004,605 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/04/23 02:07:28 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\mtstack.exe
[2000/09/18 17:50:28 | 000,202,752 | —- | C] () – C:\WINDOWS\System32\zlib.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C46995DA

< End of report >
Hi stryvn,

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

There should have also been a notepad named Extra.txt created when you ran OTL. It should be on your desktop. Please post it's contents in your next reply.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
FF - prefs.js..network.proxy.http_port: 50370
[2011/05/01 06:41:22 | 000,013,848 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\3o0c6os3k3qwg6hdqqf84dawvuh515sg
[2011/05/01 06:41:21 | 000,013,848 | -HS- | C] () – C:\Documents and Settings\Scott\Local Settings\Application Data\3o0c6os3k3qwg6hdqqf84dawvuh515sg
[2010/12/03 17:08:17 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\7lRL0ux1i.dat

:Files
ipconfig /flushdns /c

:Commands
[createrestorepoint]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Next

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Please post back with
  • OTL fix log
  • Extra.txt
  • MBR.dat (zipped and attached)
  • aswMBR log
How's the computer?
Thank you Oldman….it is going to be about 12 hours before I can get back to that machine but I will do as directed and respond asap!
In the order you requested them-



All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Prefs.js: 50370 removed from network.proxy.http_port
C:\Documents and Settings\All Users\Application Data\3o0c6os3k3qwg6hdqqf84dawvuh515sg moved successfully.
C:\Documents and Settings\Scott\Local Settings\Application Data\3o0c6os3k3qwg6hdqqf84dawvuh515sg moved successfully.
C:\Documents and Settings\All Users\Application Data\7lRL0ux1i.dat moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Scott\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Scott\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
Unable to start service SrService!

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes

User: Jodi
->Temp folder emptied: 166252180 bytes
->Java cache emptied: 30091730 bytes
->FireFox cache emptied: 40956905 bytes
->Flash cache emptied: 257337 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Flash cache emptied: 66550 bytes

User: NetworkService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 48849 bytes

User: Scott
->Temp folder emptied: 64601484 bytes
->Temporary Internet Files folder emptied: 33922796 bytes
->Java cache emptied: 146610 bytes
->FireFox cache emptied: 12565475 bytes
->Flash cache emptied: 74232 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 7881745 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2397460 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 12919428 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 118270271 bytes

Total Files Cleaned = 468.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 05052011_183529

Files\Folders moved on Reboot…
C:\Documents and Settings\Scott\Temporary Internet Files\Content.IE5\MBPKPZUO\index[3].htm moved successfully.
C:\Documents and Settings\Scott\Temporary Internet Files\Content.IE5\MBPKPZUO\like[1].htm moved successfully.
C:\Documents and Settings\Scott\Temporary Internet Files\Content.IE5\8EA9UK5N\iframe[1].htm moved successfully.

Registry entries deleted on Reboot…





OTL Extras logfile created on: 5/4/2011 3:21:15 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Scott\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.00 Mb Total Physical Memory | 129.00 Mb Available Physical Memory | 26.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 65.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.50 Gb Total Space | 11.73 Gb Free Space | 14.57% Space Free | Partition Type: NTFS
Drive D: | 11.62 Gb Total Space | 1.37 Gb Free Space | 11.78% Space Free | Partition Type: FAT32

Computer Name: LAPTOP | User Name: Scott | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Digital Photo Professional] – C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"" =
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"" =
"C:\Program Files\Vongo\VongoService.exe" = C:\Program Files\Vongo\VongoService.exe:*:enabled:VongoService – (Starz Entertainment Group LLC)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\ProENGINEER Student Edition\i486_nt\obj\pro_comm_msg.exe" = C:\Program Files\ProENGINEER Student Edition\i486_nt\obj\pro_comm_msg.exe:*:Enabled:pro_comm_msg – (PTC)
"C:\Program Files\ProENGINEER Student Edition\i486_nt\obj\xtop.exe" = C:\Program Files\ProENGINEER Student Edition\i486_nt\obj\xtop.exe:*:Enabled:xtop – (PTC)
"C:\Program Files\ProENGINEER Student Edition\i486_nt\nms\nmsd.exe" = C:\Program Files\ProENGINEER Student Edition\i486_nt\nms\nmsd.exe:*:Enabled:nmsd – (PTC)
"C:\Program Files\HP Rhapsody\rhapsody.exe" = C:\Program Files\HP Rhapsody\rhapsody.exe:*:Disabled:Rhapsody – (RealNetworks, Inc.)
"C:\Program Files\LeechFTP\Leechftp.exe" = C:\Program Files\LeechFTP\Leechftp.exe:*:Enabled:LeechFTP – (jan debis)
"C:\Program Files\Canon\EOS Utility\WFTPairing\EOSUPNPSV.exe" = C:\Program Files\Canon\EOS Utility\WFTPairing\EOSUPNPSV.exe:LocalSubNet:Enabled:Canon EOS UPNP Detector – (Canon Inc.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{09D8492A-C8E2-421E-927D-46800FB327A3}" = Wireless Home Network Setup
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
"{17424F35-8B77-4ADF-BC63-BF9B81418539}" = Apple Application Support
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1CB34CE9-0E6B-493F-BB66-3425E5DF76E5}" = CP_CalendarTemplates1
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{24BEBF2E-73F3-4599-840B-EDC612CCDD0D}" = Destinations
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{27555031-A116-4EC6-9991-7B400142A936}" = HP PSC & OfficeJet 6.1.A
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2A548002-9042-4083-A270-B67473DE1073}" = SkinsHP1
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon Camera WIA Driver
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.10 A2
"{34F3FCF1-817B-4D61-B6AF-19D9486AFEA0}" = Unload
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FE0CFAB-584A-4AA5-B8CD-C32284CFA308}" = RandMap
"{4041C245-7099-4C96-9738-5EBC23827B3C}" = BufferChm
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 2.3
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{494D17B5-3369-4905-8C4B-80C972C5E0FF}" = CP_Panorama1Config
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4DA4012B-39AF-48c2-B23B-A4D570D233A6}" = cp_LightScribeConfig
"{4E868D3D-6EEB-4273-926C-2287236B5B79}" = 3DVIA player 4.1
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{52FBAE98-D389-4281-8C14-21B4046CCB4E}" = SonicAC3Encoder
"{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}" = Photosmart 140,240,7200,7600,7700,7900 Series
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{54F0998F-73C8-4b51-8286-FE903C231BED}" = cp_PosterPrintConfig
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{5783F2D7-0101-0409-0000-0060B0CE6BBA}" = AutoCAD 2002
"{5783F2D7-7001-0409-0002-0060B0CE6BBA}" = AutoCAD 2009 - English
"{60859BF2-5151-473C-8F76-7F3A232CF7E7}" = MM Number Heroes
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{652C4ADF-0A29-4B02-9211-EE61675847DE}" = Canon Camera WIA Driver
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{6A28AB0B-22B1-494C-AF61-B386EA1736C0}" = LightScribe 1.4.97.1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{766633B3-1AFA-44B6-A3FC-1DE991CD9C52}" = CP_Package_Basic1
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{79F8E1D4-36C1-439C-95FA-F695050B5B07}" = Sonic_PrimoSDK
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{80AE27BA-B0ED-4288-A8B9-D8194BCF4115}" = cp_UpdateProjectsConfig
"{838A1BC9-95CA-4880-9BE3-2A7D23600A2B}" = Macromedia Shockwave Player
"{869C3062-4745-4949-B6C9-98AF24D89030}" = PhotoGallery
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{939F8208-C8CE-4AFF-B7BA-ACEB2E74A6CB}" =
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D4ABB0C-F60B-44A6-956C-A4A63D5495C9}" = CueTour
"{A01FC76F-CC09-4658-9E37-5C2F635EE708}" = TourSetup
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{B11E71BA-498C-42D4-9F1A-9D7A89D9DA61}" = CP_AtenaShokunin1Config
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B16AF568-A644-483C-A6DA-5028CD019C8C}" = SonicMPEGEncoder
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon Camera WIA Driver
"{BBD3BF67-5B89-4CBB-BA58-5818ED5F3290}" = cp_OnlineProjectsConfig
"{BE247E71-C143-40BB-ADF2-A465DF062BAB}" = HP User Guides 0035
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C424D5B8-BDE9-48FD-805E-FF276FCC76DF}" = ACL Desktop Education Edition
"{C6812939-B117-48E6-A3BA-1709C14A3C8C}" = Scan
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DB7E00C9-6DEF-489A-8112-D8F81614F45A}" = Vongo
"{DE2EBD6F-81B6-4E9A-B137-C11FD6790CFF}" = PSShortcutsP
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E6DE9A54-8514-446E-9D11-530DC599C355}" = Microsoft SharedView
"{E8843212-F0FC-4C3B-BFF3-D51829CB4F19}" = iTunes
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{EFE26D3B-2789-4068-A5BB-77E389FAEB98}" = PSUsage
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6B2ED65-7378-4065-802D-F2E5689F3A4E}" = Photo Viewer
"{FC8D25A7-FF1B-41BB-BB3B-9A06C0A60AE0}" = InstantShareDevices
"0E5906722E3ECA13747F1633D3F55E9F47120424" = Windows Driver Package - LeapFrog (FlyUsb) USB (06/15/2007 1.0.0.6)
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"3DGroove" = 3D Groove Playback Engine
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AnswerWorks" = AnswerWorks Runtime
"AutoCAD 2009 - English" = AutoCAD 2009 - English
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"CCleaner" = CCleaner
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_PCI_VEN_14F1&DEV_5045_at8ven5m" = Soft Data Fax Modem with SmartCP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CSCLIB" = Canon Camera Support Core Library
"DPP" = Canon Utilities Digital Photo Professional 3.0
"EOS Utility" = Canon Utilities EOS Utility
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"FileZilla Client" = FileZilla Client 3.3.5
"HijackThis" = HijackThis 2.0.2
"Hijackthis_is1" = Hijackthis 1.99.1
"HP Imaging Device Functions" = HP Imaging Device Functions 6.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.0
"HP Rhapsody" = HP Rhapsody
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon EOS Kiss_N REBEL_XT 350D WIA Driver
"InstallShield_{652C4ADF-0A29-4B02-9211-EE61675847DE}" = Canon EOS-1Ds Mark II WIA Driver
"InstallShield_{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon EOS 5D WIA Driver
"LeechFTP" = LeechFTP
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Money2006b" = Microsoft Money 2006
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ODSK" = Canon Utilities Original Data Security Tools
"PhotoStitch" = Canon Utilities PhotoStitch
"Pro/ENGINEER Student Edition Release Wildfire 3.0 Datecode M020" = Pro/ENGINEER Student Edition Release Wildfire 3.0 Datecode M020
"PROSet" = Intel® PRO Network Connections Drivers
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 12.0" = RealPlayer
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SkillJam SecurePlayer" = Secure Game Player
"Treasures of Knowledge" = Treasures of Knowledge
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WFTK" = Canon Utilities WFT-E1/E2 Utility
"WIC" = Windows Imaging Component
"WildTangent CDA" = WildTangent Web Driver
"WildTangent hplaptop Master Uninstall" = My HP Games
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"winusb0100" = Microsoft WinUsb 1.0
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/1/2011 6:24:04 PM | Computer Name = LAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/1/2011 6:24:04 PM | Computer Name = LAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/1/2011 6:24:04 PM | Computer Name = LAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/5/2011 9:33:51 PM | Computer Name = LAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/7/2011 3:57:59 PM | Computer Name = LAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/24/2011 10:48:08 AM | Computer Name = LAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application OUTLOOK.EXE, version 11.0.8326.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/24/2011 10:48:08 AM | Computer Name = LAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application OUTLOOK.EXE, version 11.0.8326.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/28/2011 2:16:23 PM | Computer Name = LAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/28/2011 2:16:25 PM | Computer Name = LAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/28/2011 2:16:31 PM | Computer Name = LAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 5/1/2011 4:02:50 AM | Computer Name = LAPTOP | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC90.DebugCRT. Reference
error message: The referenced assembly is not installed on your system. .

Error - 5/1/2011 4:02:50 AM | Computer Name = LAPTOP | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll.
Reference
error message: The operation completed successfully. .

Error - 5/1/2011 6:57:04 AM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2

Error - 5/1/2011 6:57:48 AM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.

Error - 5/1/2011 6:57:49 AM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053

Error - 5/1/2011 7:54:47 AM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2

Error - 5/1/2011 12:48:22 PM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2

Error - 5/2/2011 5:06:33 PM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2

Error - 5/2/2011 9:09:19 PM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2

Error - 5/4/2011 4:03:01 PM | Computer Name = LAPTOP | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2


< End of report >






aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-05 18:47:12
—————————–
18:47:12.718 OS Version: Windows 5.1.2600 Service Pack 3
18:47:12.718 Number of processors: 1 586 0xE08
18:47:12.718 ComputerName: LAPTOP UserName: Scott
18:47:13.468 Initialize success
18:47:25.093 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
18:47:25.109 Disk 0 Vendor: FUJITSU_ 892C Size: 95396MB BusType: 3
18:47:25.125 Disk 0 MBR read successfully
18:47:25.140 Disk 0 MBR scan
18:47:25.140 Disk 0 unknown MBR code
18:47:25.156 Disk 0 scanning sectors +195366465
18:47:25.187 Disk 0 scanning C:\WINDOWS\system32\drivers
18:47:36.843 Service scanning
18:47:38.218 Disk 0 trace - called modules:
18:47:38.234 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys
18:47:38.234 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82b47030]
18:47:38.234 3 CLASSPNP.SYS[f84d5fd7] -> nt!IofCallDriver -> \Device\0000007f[0x82b5d2a8]
18:47:38.234 5 ACPI.sys[f834c620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x82b48030]
18:47:38.234 Scan finished successfully
18:47:55.859 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Scott\Desktop\MBR.dat"
18:47:55.875 The log file has been saved successfully to "C:\Documents and Settings\Scott\Desktop\aswMBR.txt"



Ok, Oldman. I hope I've got everything there. The machine is doing much better. None of the symptoms that were present a few days ago seem to be there today.

Attachments:

Hi stryvn,

What brand of computer is this?

Please make sure System Restore is turned on.

Please
  • Click Start, right-click My Computer, and then click Properties
  • In the System Properties dialog box, click the System Restore tab
  • Make sure there isn't a check mark in the Turn off System Restore check box. Or, Turn off System Restore on all drives check box
  • If there is click the box to clear the check mark.
  • Click OK
After a few moments, the System Properties dialog box will close. Please wait for it to close as it is creating a restore point.

You have some very old vulnerable java install. Please go to start button > Control Panel > Add/Remove programs and uninstall

J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 11


Do not uninstall Java TM 6 Update 22


Still in Control Panel
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.


You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • MBAM log
Any problems?

Thanks
This is an old HP Compaq machine….but works well for me. Mb log below…. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6518 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 5/6/2011 9:10:13 PM mbam-log-2011-05-06 (21-10-02).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 342375 Time elapsed: 1 hour(s), 35 minute(s), 35 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 4 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\Software\ere94fe5o32 (Trojan.FakeAV) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Scott\Local Settings\Application Data\bbm.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Machine seems to be working well. Pretty fast and the original symptoms no longer an issue
Hi stryvn,

This is an old HP Compaq machine….but works well for me.
Nothing wrong with older computers, got one myself.


•Make sure that everything is checked, and click Remove Selected.

From the MBAM instructions.

Please rerun MBAM and let it remove what it found. Please pot the log

Thanks
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6518 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 5/8/2011 6:23:55 AM mbam-log-2011-05-08 (06-23-55).txt Scan type: Quick scan Objects scanned: 194406 Time elapsed: 12 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 4 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\Software\ere94fe5o32 (Trojan.FakeAV) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Scott\Local Settings\Application Data\bbm.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi stryvn,

That's better.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6427 # api_version=3.0.2 # EOSSerial=fb437d015187af49a91c34dd52114cf2 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-05-09 03:41:55 # local_time=2011-05-08 10:41:55 (-0600, Central Daylight Time) # country="United States" # lang=9 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 70654642 70654642 0 0 # compatibility_mode=1797 16775141 100 100 181328 78852664 0 0 # compatibility_mode=8192 67108863 100 0 12297890 12297890 0 0 # scanned=173444 # found=2 # cleaned=0 # scan_time=6016 C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\HCTT27TP\i[9].js HTML/Iframe.B.Gen virus (unable to clean) 00000000000000000000000000000000 I C:\WINDOWS\system32\12543.js JS/TrojanDownloader.Agent.NWG trojan (unable to clean) 00000000000000000000000000000000 I
Hi stryvn,

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\Documents and Settings\Scott\Local Settings\Application Data\bbm.exe
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\HCTT27TP\i[9].js
C:\WINDOWS\system32\12543.js

:Commands
[createrestorepoint]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Next

Please open OTL if it is not opened after the reboot.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt.

Please post back with
  • OTL fix log
  • OTL.txt
Any problems?

Thanks
The machine seems to be ok, Oldman. I am not noticing anything abnormal anymore.



All processes killed
========== SERVICES/DRIVERS ==========
========== FILES ==========
File\Folder C:\Documents and Settings\Scott\Local Settings\Application Data\bbm.exe not found.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\HCTT27TP\i[9].js moved successfully.
C:\WINDOWS\system32\12543.js moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point (0)

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes

User: Jodi
->Temp folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Scott
->Temp folder emptied: 11386841 bytes
->Temporary Internet Files folder emptied: 29973486 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 1297 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6808 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 37437 bytes

Total Files Cleaned = 39.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 05092011_152940

Files\Folders moved on Reboot…
C:\Documents and Settings\Scott\Temporary Internet Files\Content.IE5\PUANDXZN\iframe[1].htm moved successfully.
C:\Documents and Settings\Scott\Temporary Internet Files\Content.IE5\BM6GW9TR\index[3].htm moved successfully.
C:\Documents and Settings\Scott\Temporary Internet Files\Content.IE5\BM6GW9TR\like[1].htm moved successfully.

Registry entries deleted on Reboot…




OTL logfile created on: 5/9/2011 3:39:47 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Scott\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.00 Mb Total Physical Memory | 201.00 Mb Available Physical Memory | 40.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.50 Gb Total Space | 11.95 Gb Free Space | 14.84% Space Free | Partition Type: NTFS
Drive D: | 11.62 Gb Total Space | 1.37 Gb Free Space | 11.78% Space Free | Partition Type: FAT32
Unable to calculate disk information.

Computer Name: LAPTOP | User Name: Scott | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Scott\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Vongo\VongoService.exe (Starz Entertainment Group LLC)
PRC - C:\Program Files\Vongo\Tray.exe (Starz)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\WINDOWS\system32\hphmon05.exe (Hewlett-Packard)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Scott\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (getPlus® Helper) getPlus® – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (AddFiltr) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe (Hewlett-Packard Development Company, L.P.)
SRV - (Vongo Service) – C:\Program Files\Vongo\VongoService.exe (Starz Entertainment Group LLC)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (FlyUsb) – C:\WINDOWS\system32\drivers\FlyUsb.sys (LeapFrog)
DRV - (RMCAST) – C:\WINDOWS\system32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (MQAC) – C:\WINDOWS\system32\drivers\mqac.sys (Microsoft Corporation)
DRV - (CdaD10BA) – C:\WINDOWS\system32\drivers\CdaD10BA.SYS (Macrovision Europe Ltd)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\CHDAud.sys (Conexant Systems Inc.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (eabusb) – C:\WINDOWS\system32\drivers\EabUsb.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\WINDOWS\system32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)
DRV - (eabfiltr) – C:\WINDOWS\system32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.jsonline.com/
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: ""
FF - prefs.js..network.proxy.type: 1

FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/01/04 15:48:22 | 000,000,000 | —D | M]

[2009/09/12 07:03:35 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Scott\Application Data\Mozilla\Extensions
[2009/10/29 19:10:11 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\liyu9nuq.default\extensions
[2009/09/12 07:06:40 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Scott\Application Data\Mozilla\Firefox\Profiles\liyu9nuq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/21 16:56:23 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2008/01/30 14:48:38 | 000,074,280 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npsharedview.dll

O1 HOSTS File: ([2010/12/06 17:39:01 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe ()
O4 - HKLM..\Run: [HP Software Update] File not found
O4 - HKLM..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPHUPD05] C:\Program Files\HP\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe ()
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\Scott\Start Menu\Programs\StartUp\Vongo Tray.lnk = C:\Documents and Settings\Scott\Application Data\Microsoft\Installer\{DB7E00C9-6DEF-489A-8112-D8F81614F45A}\NewShortcut2_DB7E00C96DEF489A8112D8F81614F45A.exe (Macrovision Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB (Hewlett-Packard Online Support Services)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://mypoints.worldwinner.com/games/v46/…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} http://www.infospace.com/mypoints.main/tba…pointsSetup.exe (Reg Error: Key error.)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Groove Control)
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file:///C:/Program%20Files/AutoCAD%202002/AcDcToday.ocx (AcDcToday Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control)
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} file:///C:/Program%20Files/AutoCAD%202002/InstBanr.ocx (NOXLATE-BANR)
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} file:///C:/Program%20Files/AutoCAD%202002/InstFred.ocx (InstaFred)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file:///C:/Program%20Files/AutoCAD%202002/AcPreview.ocx (AcPreview Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Scott\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Scott\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 22:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/06 04:41:28 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/05/06 04:41:28 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/05/06 04:41:28 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/05/05 18:46:47 | 000,589,632 | —- | C] (AVAST Software) – C:\Documents and Settings\Scott\Desktop\aswMBR.exe
[2011/05/05 18:35:29 | 000,000,000 | —D | C] – C:\_OTL
[2011/05/02 17:00:56 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Scott\Desktop\OTL.exe
[2011/05/02 16:59:21 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Scott\Desktop\HiJackThis.exe
[2011/04/11 19:50:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Scott\Desktop\pig

========== Files - Modified Within 30 Days ==========

[2011/05/09 15:33:32 | 000,002,301 | —- | M] () – C:\Documents and Settings\Scott\Start Menu\Programs\StartUp\Vongo Tray.lnk
[2011/05/09 15:33:19 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/09 15:32:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/09 15:31:59 | 526,438,400 | -HS- | M] () – C:\hiberfil.sys
[2011/05/05 18:52:22 | 000,000,596 | —- | M] () – C:\Documents and Settings\Scott\Desktop\MBR.zip
[2011/05/05 18:47:55 | 000,000,512 | —- | M] () – C:\Documents and Settings\Scott\Desktop\MBR.dat
[2011/05/05 18:46:54 | 000,589,632 | —- | M] (AVAST Software) – C:\Documents and Settings\Scott\Desktop\aswMBR.exe
[2011/05/04 15:19:33 | 000,294,400 | —- | M] () – C:\Documents and Settings\Scott\Desktop\exeHelper.com
[2011/05/02 17:01:02 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Scott\Desktop\OTL.exe
[2011/05/02 16:59:29 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Scott\Desktop\HiJackThis.exe
[2011/04/14 20:06:10 | 000,455,802 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/14 20:06:10 | 000,075,750 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/14 05:08:11 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/04/14 05:08:10 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/04/14 05:08:09 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/04/14 05:07:59 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/04/14 02:40:22 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/04/13 15:03:03 | 000,000,792 | —- | M] () – C:\Documents and Settings\Scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/04/13 03:40:33 | 000,384,816 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/13 03:18:28 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK

========== Files Created - No Company Name ==========

[2011/05/05 18:52:22 | 000,000,596 | —- | C] () – C:\Documents and Settings\Scott\Desktop\MBR.zip
[2011/05/05 18:47:55 | 000,000,512 | —- | C] () – C:\Documents and Settings\Scott\Desktop\MBR.dat
[2011/05/04 15:19:32 | 000,294,400 | —- | C] () – C:\Documents and Settings\Scott\Desktop\exeHelper.com
[2010/05/08 17:43:54 | 000,103,193 | —- | C] () – C:\WINDOWS\hpoins08.dat
[2010/05/08 17:43:54 | 000,004,445 | —- | C] () – C:\WINDOWS\hpomdl08.dat
[2010/03/07 09:06:36 | 000,000,034 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/09/12 07:03:25 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/04/17 09:00:51 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/06/21 10:26:30 | 000,303,680 | —- | C] () – C:\Program Files\07-Seems to Want to Hurt This Time-Donna the Buffalo.mp3
[2008/06/21 10:15:04 | 007,825,688 | —- | C] () – C:\Program Files\06-If You Only Could-Donna the Buffalo.mp3
[2008/06/21 10:13:47 | 009,167,340 | —- | C] () – C:\Program Files\05-Riddle of the Universe-Donna the Buffalo.mp3
[2008/06/21 10:09:10 | 011,456,620 | —- | C] () – C:\Program Files\04-Family Picture-Donna the Buffalo.mp3
[2008/06/21 10:03:55 | 015,836,080 | —- | C] () – C:\Program Files\03-America-Donna the Buffalo.mp3
[2008/06/21 10:00:56 | 009,014,965 | —- | C] () – C:\Program Files\02-Tides of Time-Donna the Buffalo.mp3
[2008/06/21 09:59:02 | 008,899,735 | —- | C] () – C:\Program Files\01-In This Life-Donna the Buffalo.mp3
[2008/06/21 09:55:19 | 012,488,565 | —- | C] () – C:\Program Files\11-Narada Muni-GODFREY TOWNSEND.mp3
[2008/06/21 09:48:43 | 007,041,860 | —- | C] () – C:\Program Files\10-Cold-GODFREY TOWNSEND.mp3
[2008/06/21 09:47:14 | 009,003,275 | —- | C] () – C:\Program Files\09-Whitefeather-GODFREY TOWNSEND.mp3
[2008/06/21 09:45:06 | 012,240,570 | —- | C] () – C:\Program Files\08-The Apostle-GODFREY TOWNSEND.mp3
[2008/06/21 09:44:14 | 007,997,935 | —- | C] () – C:\Program Files\07-Gaga Over Raga-GODFREY TOWNSEND.mp3
[2008/06/21 09:38:14 | 008,451,340 | —- | C] () – C:\Program Files\06-Easy Journey To Other Planets-GODFREY TOWNSEND.mp3
[2008/06/21 09:30:51 | 009,054,210 | —- | C] () – C:\Program Files\05-Hazel Street-GODFREY TOWNSEND.mp3
[2008/06/21 09:29:33 | 010,911,250 | —- | C] () – C:\Program Files\04-Long Misty Bridge-GODFREY TOWNSEND.mp3
[2008/06/21 09:26:42 | 008,027,995 | —- | C] () – C:\Program Files\02-Closer 2 U-GODFREY TOWNSEND.mp3
[2008/06/21 09:20:34 | 003,824,605 | —- | C] () – C:\Program Files\01-Astral Progression-GODFREY TOWNSEND.mp3
[2008/06/21 09:14:18 | 012,205,057 | —- | C] () – C:\Program Files\05 Internet Song.mp3
[2008/06/21 09:14:09 | 020,486,195 | —- | C] () – C:\Program Files\07-For Today-Camel.mp3
[2008/06/21 09:08:56 | 015,413,570 | —- | C] () – C:\Program Files\06-Squigely Fair-Camel.mp3
[2008/06/21 09:03:31 | 006,856,490 | —- | C] () – C:\Program Files\05-The Miller's Tale-Camel.mp3
[2008/06/21 08:48:28 | 021,629,310 | —- | C] () – C:\Program Files\01-A Nod and a Wink-Camel.mp3
[2008/06/21 08:48:28 | 017,875,150 | —- | C] () – C:\Program Files\04-Fox Hill-Camel.mp3
[2008/06/21 08:48:28 | 014,076,735 | —- | C] () – C:\Program Files\03-A Boy's Life-Camel.mp3
[2008/06/21 08:48:28 | 010,593,115 | —- | C] () – C:\Program Files\02-Simple Pleasures-Camel.mp3
[2008/06/12 20:39:50 | 000,018,944 | R— | C] () – C:\WINDOWS\eraser.exe
[2008/01/14 17:47:06 | 000,099,712 | —- | C] () – C:\WINDOWS\HPBroker.dll
[2007/10/09 15:21:53 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/09/07 15:53:17 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2007/05/04 00:54:44 | 000,000,016 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2007/03/19 16:33:16 | 000,000,785 | —- | C] () – C:\WINDOWS\checkip.dat
[2007/02/10 12:20:06 | 000,000,000 | —- | C] () – C:\WINDOWS\Setup32.INI
[2007/01/10 17:12:46 | 000,000,478 | —- | C] () – C:\Documents and Settings\Scott\Application Data\wklnhst.dat
[2006/12/27 17:55:49 | 000,019,739 | —- | C] () – C:\WINDOWS\HPHins02.dat
[2006/12/27 17:55:48 | 000,004,284 | —- | C] () – C:\WINDOWS\hphmdl02.dat
[2006/12/27 17:55:23 | 000,364,544 | —- | C] () – C:\WINDOWS\System32\hphped05.exe
[2006/12/27 17:55:12 | 000,006,478 | —- | C] () – C:\WINDOWS\System32\hphmon05.dat
[2006/12/27 14:15:03 | 000,081,408 | —- | C] () – C:\Documents and Settings\Scott\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/12/27 10:34:37 | 000,000,128 | —- | C] () – C:\Documents and Settings\Scott\Local Settings\Application Data\fusioncache.dat
[2006/09/12 03:53:13 | 000,000,174 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/09/12 03:49:07 | 000,045,929 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/09/12 03:49:07 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/09/12 03:35:40 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/09/12 03:24:46 | 000,028,836 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/06/29 14:18:28 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/06/29 14:18:14 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/29 13:49:18 | 000,087,268 | —- | C] () – C:\WINDOWS\hpqins69.dat
[2006/06/29 13:46:56 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/06/29 13:43:40 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/06/29 13:27:08 | 000,455,802 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/06/29 13:27:08 | 000,075,750 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/06/29 13:18:06 | 000,384,816 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/06/29 13:13:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/06/29 13:08:28 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/03/15 23:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/03/15 23:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/03/15 23:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/03/15 23:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/03/15 23:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/03/15 23:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/03/15 23:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/03/15 23:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/03/04 02:07:34 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/12/02 13:09:10 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/26 15:28:20 | 000,024,576 | —- | C] () – C:\WINDOWS\shortcut.exe
[2005/08/26 14:28:34 | 000,143,360 | —- | C] () – C:\WINDOWS\unzip.exe
[2005/08/26 14:27:58 | 000,045,056 | —- | C] () – C:\WINDOWS\devenum.exe
[2005/05/06 13:06:32 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2004/09/16 15:24:26 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2003/01/07 17:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/05/28 16:55:42 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/05/28 16:54:40 | 000,004,605 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/04/23 02:07:28 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\mtstack.exe
[2000/09/18 17:50:28 | 000,202,752 | —- | C] () – C:\WINDOWS\System32\zlib.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C46995DA

< End of report >
Hi stryvn,

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.

:Commands
[CLEARALLRESTOREPOINTS]


Then click the Run Fix button at the top
  • Let the program run unhindered
No need to post the log.


We'll clean up the tools and send you on your way.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • aswMBR.exe
  • exeHelper.com
  • MBR.xip
  • MBR.dat

I suggest you keep MBAM. Keep it updated and use it regularly.

ESET online scan can be removed via add/remove programs.


Next

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.



Updates and upgrades

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7.1.0 first. Be sure to move any PDF documents to another folder first though.


Some Recommendations and prevention tips
Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

For an antispyware program with resident (real time) scanning. I suggest
Windows Defender

OR

Winpatrol

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Make sure you have reset Automatic Updates to your chosen optionClick your start button > Control Panel > System


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

Please post back if you have any problems.

Take care

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI