This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with searchqu

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hoping for help. I ran the program as per instructions:

OTL logfile created on: 5/4/2011 10:34:30 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Richard Sinclair\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 69.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 124.95 Gb Free Space | 53.65% Space Free | Partition Type: NTFS

Computer Name: TOSHIBA-USER | User Name: Richard Sinclair | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Richard Sinclair\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Windows Savevid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - c:\Program Files\real\realplayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
PRC - C:\Program Files\Protector Suite QL\psqltray.exe (UPEK Inc.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
PRC - C:\Program Files\Synaptics\SynTP\Toshiba.exe (Synaptics, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\TOSHIBA\Tvs\TvsTray.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe (TOSHIBA Corporation)
PRC - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
PRC - C:\WINDOWS\system32\TPSMain.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\TOSHIBA\IVP\ISM\pinger.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TDispVol.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
PRC - C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
PRC - C:\Program Files\Hewlett-Packard\hp business inkjet 1200 series\Toolbox\HPWNTBX.exe (Hewlett-Packard Company)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Richard Sinclair\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\TDispVol.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (aspnet_state) – File not found
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (TAPPSRV) – C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
SRV - (Swupdtmr) – c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)


========== Driver Services (SafeList) ==========

DRV - (FdRedir) – C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys (UPEK Inc.)
DRV - (FileDisk2) – C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys (UPEK Inc.)
DRV - (smihlp) – C:\Program Files\Protector Suite QL\smihlp.sys (UPEK Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (Tvs) – C:\WINDOWS\system32\drivers\Tvs.sys (TOSHIBA Corporation)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (TVALD) – C:\WINDOWS\system32\drivers\NBSMI.sys (Toshiba Corporation)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (tosrfec) – C:\WINDOWS\system32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (tbiosdrv) – C:\WINDOWS\system32\drivers\tbiosdrv.sys ()
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (KR10N) – C:\WINDOWS\system32\drivers\KR10N.sys (TOSHIBA CORPORATION)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/405
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/02/07 12:48:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/29 15:33:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/24 13:28:27 | 000,000,000 | —D | M]

[2011/04/24 09:41:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard Sinclair\Application Data\Mozilla\Extensions
[2011/02/05 23:20:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard Sinclair\Application Data\Mozilla\Extensions\[removed]
[2011/04/25 15:26:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard Sinclair\Application Data\Mozilla\Firefox\Profiles\i6ozt9ar.default\extensions
[2011/02/10 11:36:43 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Richard Sinclair\Application Data\Mozilla\Firefox\Profiles\i6ozt9ar.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/03/24 13:28:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard Sinclair\Application Data\Mozilla\Firefox\Profiles\i6ozt9ar.default\extensions\nostmp
[2011/04/25 00:27:52 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/01/31 23:54:49 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/29 15:33:11 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/01/31 23:54:41 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2010/12/09 11:17:40 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml

O1 HOSTS File: ([2004/08/10 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows Savevid Toolbar\ToolBar\searchqudtx.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows Savevid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows Savevid Toolbar\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CFSServ.exe] File not found
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows Savevid Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [HPWNTOOLBOX] C:\Program Files\Hewlett-Packard\hp business inkjet 1200 series\Toolbox\HPWNTBX.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [PadTouch] File not found
O4 - HKLM..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\Protector Suite QL\launcher.exe (UPEK Inc.)
O4 - HKLM..\Run: [Recordpad] C:\Program Files\NCH Swift Sound\Recordpad\recordpad.exe (NCH Software)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TDispVol] C:\WINDOWS\System32\TDispVol.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [THotkey] C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [DW6] File not found
O4 - HKCU..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google; Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1
O20 - AppInit_DLLs: (C:\PROGRA~1\WI0498~1\Datamngr\datamngr.dll) - C:\Program Files\Windows Savevid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI0498~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows Savevid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\psfus: DllName - psqlpwd.dll - C:\WINDOWS\System32\psqlpwd.dll (UPEK Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/02/15 11:38:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/04/30 16:34:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\get.cfm_files
[2011/04/27 22:49:08 | 000,000,000 | R-SD | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Safe
[2011/04/27 00:25:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Application Data\searchquband
[2011/04/26 09:57:03 | 000,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\um34scan.dll
[2011/04/26 09:57:03 | 000,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um34scan.dll
[2011/04/25 10:59:31 | 000,000,000 | —D | C] – C:\Program Files\Savevid
[2011/04/24 21:43:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Picasa2
[2011/04/24 21:43:18 | 000,000,000 | —D | C] – C:\Program Files\Picasa2
[2011/04/24 09:41:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Application Data\searchqutoolbar
[2011/04/24 09:40:57 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{4DC9D39F-E342-4826-8E99-5A0EFA8682D7}
[2011/04/24 09:37:13 | 000,000,000 | —D | C] – C:\Program Files\Windows Savevid Toolbar
[2011/04/24 09:37:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\PackageAware
[2011/04/22 09:41:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\RCF Presbytery 4-2011
[2011/04/22 08:32:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Application Data\Sonic
[2011/04/16 12:54:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\ZGhost
[2011/04/16 12:54:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\ZBackup info
[2011/04/16 12:54:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\ZApplication Downloads
[2011/04/16 12:53:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\When I Return from Sabbatical
[2011/04/16 12:53:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Vision Folder
[2011/04/16 12:53:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Updater5
[2011/04/16 12:51:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\TomTom
[2011/04/16 12:50:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Timothy Center
[2011/04/16 12:50:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\commandments_files
[2011/04/16 12:50:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\command_introduction_files
[2011/04/16 12:47:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - edited aud_data
[2011/04/16 12:47:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\GCC Audio Files
[2011/04/16 12:47:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\Tom Pahler - April 2011
[2011/04/16 12:46:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 4-14-2009
[2011/04/16 12:46:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 4-1-08
[2011/04/16 12:42:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 3-30-2011
[2011/04/16 12:42:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 1-28-2011
[2011/04/16 12:42:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 1-15-2011
[2011/04/16 12:42:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 1-12-2011
[2011/04/16 12:40:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 1-4-2010
[2011/04/16 12:11:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Teaching- Training
[2011/04/16 08:35:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\TaxCut
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\SightSpeed Recordings
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Sibelius Files
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\ShareContacts
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Scores
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Recordpad
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Pradis
[2011/04/16 06:30:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\PERSONAL
[2011/04/15 22:58:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\PcSetup
[2011/04/15 22:58:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Nolo Documents Backup
[2011/04/15 22:57:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\New Folder
[2011/04/15 22:57:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Videos
[2011/04/15 22:57:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Practice Files
[2011/04/15 22:57:43 | 000,000,000 | R–D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Pictures
[2011/04/15 22:49:40 | 000,000,000 | R–D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Music
[2011/04/15 22:49:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Data Sources
[2011/04/15 22:45:50 | 000,000,000 | R–D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My 2011 Pix
[2011/04/15 22:44:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\GCC Moira
[2011/04/15 22:44:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Ministries, Fellowships, etc
[2011/04/15 22:44:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Master Planning
[2011/04/15 22:39:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Kid's Files
[2011/04/15 22:38:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Individuals
[2011/04/15 22:38:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\HRBlock
[2011/04/15 22:38:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\gegl-0.0
[2011/04/15 22:38:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Forms-Tools
[2011/04/15 22:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Finale-Sibelius Files
[2011/04/15 22:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Fax
[2011/04/15 22:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\DVD X Studios
[2011/04/15 22:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\DSSPlayer
[2011/04/15 22:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\DRConfig
[2011/04/15 22:37:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Downloads
[2011/04/15 22:35:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Desktop stuff 9-10-2008
[2011/04/15 22:35:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Darlene's File
[2011/04/15 22:35:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Computer info & Shopping
[2011/04/15 22:31:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\CFC
[2011/04/15 22:31:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Books
[2011/04/13 18:40:10 | 004,284,416 | —- | C] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2011/04/11 11:50:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Application Data\InterVideo
[2006/02/15 12:25:00 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\DLLVGA.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/04 22:18:25 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-4281795085-2703001846-136500816-1005.job
[2011/05/04 22:18:25 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-4281795085-2703001846-136500816-1005.job
[2011/05/04 22:06:22 | 000,023,729 | —- | M] () – C:\Documents and Settings\Richard Sinclair\.recently-used.xbel
[2011/05/04 09:59:17 | 000,000,312 | —- | M] () – C:\WINDOWS\tasks\recordpadShakeIcon.job
[2011/05/04 09:59:07 | 2137,051,136 | -HS- | M] () – C:\hiberfil.sys
[2011/05/04 09:59:07 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/03 14:11:28 | 000,000,789 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Shortcut to Town of Madrid - Zoning Issues.lnk
[2011/05/01 08:46:09 | 000,000,060 | —- | M] () – C:\WINDOWS\wpd99.drv
[2011/04/30 16:53:11 | 000,281,144 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\healthrisksSSA.pdf
[2011/04/30 16:34:25 | 000,071,493 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\get.cfm.htm
[2011/04/30 15:16:02 | 000,114,118 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\deathofmarriage.pdf
[2011/04/30 11:54:47 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/04/30 11:54:47 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2011/04/26 12:21:02 | 000,000,026 | —- | M] () – C:\WINDOWS\Debug.ini
[2011/04/26 12:21:02 | 000,000,016 | —- | M] () – C:\WINDOWS\Temp.ini
[2011/04/26 12:20:53 | 000,000,553 | —- | M] () – C:\WINDOWS\umaxuapi.ini
[2011/04/26 00:52:59 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/24 21:43:40 | 000,057,344 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/24 21:43:29 | 000,000,695 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa2.lnk
[2011/04/24 21:43:29 | 000,000,677 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Picasa2.lnk
[2011/04/24 09:48:13 | 022,402,972 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\The Death and Resurrection of Jesus Christ - Twitter style [HD].flv
[2011/04/22 08:20:38 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\switchShakeIcon.job
[2011/04/17 09:31:10 | 023,074,908 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-17-2011.WMA
[2011/04/15 03:23:29 | 000,294,864 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/15 03:06:23 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/15 03:05:30 | 002,005,471 | —- | M] () – C:\WINDOWS\iis6.BAK
[2011/04/13 18:40:10 | 004,284,416 | —- | M] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2011/04/11 22:37:52 | 017,496,864 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Rick Sinclair - Prophetic Ministry 4-8-2011 compressed.mp3
[2011/04/11 22:30:12 | 514,409,448 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - edited.wav
[2011/04/11 22:27:02 | 000,151,498 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - edited aud.aup
[2011/04/11 22:17:22 | 047,856,086 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - Copy.mp3
[2011/04/11 22:14:00 | 000,001,085 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\WavePad Sound Editor.lnk
[2011/04/11 22:02:20 | 000,001,780 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Be Creative on Facebook With Facepaint Layouts.lnk
[2011/04/11 22:02:20 | 000,001,777 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Free Music Downloads.lnk
[2011/04/11 22:02:20 | 000,001,767 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Free Games!!.lnk
[2011/04/11 20:32:50 | 036,679,972 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Presb Prep 4-2011.WMA
[2011/04/11 20:32:50 | 036,679,972 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Presb Prep 4-11-2011.WMA
[2011/04/10 10:05:58 | 022,489,518 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-10-2011.WMA
[2011/04/10 10:05:58 | 022,489,518 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-10-2011 dup maybe.WMA
[2011/04/07 16:22:19 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/07 11:49:18 | 000,257,536 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Colson DVD & support info.dot
[2011/04/06 08:58:34 | 058,689,727 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla - Ravel.wmv
[2011/04/06 08:29:12 | 158,828,572 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla - Beethoven.wmv
[2011/04/06 07:57:16 | 058,804,897 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla's Recital - Bach.wmv
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/04 22:06:22 | 000,023,729 | —- | C] () – C:\Documents and Settings\Richard Sinclair\.recently-used.xbel
[2011/05/03 14:11:28 | 000,000,789 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Shortcut to Town of Madrid - Zoning Issues.lnk
[2011/04/30 16:53:10 | 000,281,144 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\healthrisksSSA.pdf
[2011/04/30 16:34:24 | 000,071,493 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\get.cfm.htm
[2011/04/30 15:16:02 | 000,114,118 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\deathofmarriage.pdf
[2011/04/30 11:54:47 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2011/04/30 11:54:47 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2011/04/26 17:01:27 | 066,741,394 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Personal_Restoration_Part_04.mp3
[2011/04/26 17:01:10 | 081,837,662 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Personal_Restoration_Part_03.mp3
[2011/04/26 17:00:56 | 091,008,522 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Personal_Restoration_Part_02.mp3
[2011/04/26 17:00:49 | 041,477,016 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Personal_Restoration_Part_01.mp3
[2011/04/26 17:00:44 | 041,012,232 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Louie Giglio - Gospel According to Krispy Kreme.flv
[2011/04/26 09:58:49 | 000,000,553 | —- | C] () – C:\WINDOWS\umaxuapi.ini
[2011/04/26 09:57:41 | 000,000,016 | —- | C] () – C:\WINDOWS\Temp.ini
[2011/04/26 09:57:09 | 000,000,026 | —- | C] () – C:\WINDOWS\Debug.ini
[2011/04/26 00:52:59 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/24 21:43:29 | 000,000,695 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa2.lnk
[2011/04/24 21:43:29 | 000,000,677 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Picasa2.lnk
[2011/04/24 09:44:05 | 022,402,972 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\The Death and Resurrection of Jesus Christ - Twitter style [HD].flv
[2011/04/22 08:20:38 | 000,000,300 | —- | C] () – C:\WINDOWS\tasks\switchShakeIcon.job
[2011/04/18 16:47:56 | 022,489,518 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-10-2011.WMA
[2011/04/18 16:47:52 | 036,679,972 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Presb Prep 4-11-2011.WMA
[2011/04/17 08:43:32 | 023,074,908 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-17-2011.WMA
[2011/04/16 12:54:21 | 000,023,321 | —- | C] () – C:\Documents and Settings\Richard Sinclair\My Documents\Facebook pic.jpg
[2011/04/16 12:47:15 | 000,001,085 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\WavePad Sound Editor.lnk
[2011/04/16 12:47:14 | 017,496,864 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Rick Sinclair - Prophetic Ministry 4-8-2011 compressed.mp3
[2011/04/16 12:47:14 | 000,001,777 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Free Music Downloads.lnk
[2011/04/16 12:47:14 | 000,001,767 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Free Games!!.lnk
[2011/04/16 12:46:57 | 514,409,448 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - edited.wav
[2011/04/16 12:46:56 | 000,151,498 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - edited aud.aup
[2011/04/16 12:46:54 | 047,856,086 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - Copy.mp3
[2011/04/16 12:46:54 | 000,257,536 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Colson DVD & support info.dot
[2011/04/16 12:46:54 | 000,019,294 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\command_introduction.htm
[2011/04/16 12:46:54 | 000,004,503 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\commandments.htm
[2011/04/16 12:46:52 | 058,804,897 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla's Recital - Bach.wmv
[2011/04/16 12:46:50 | 058,689,727 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla - Ravel.wmv
[2011/04/16 12:46:45 | 158,828,572 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla - Beethoven.wmv
[2011/04/16 12:46:45 | 000,001,780 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Be Creative on Facebook With Facepaint Layouts.lnk
[2011/04/11 19:17:10 | 036,679,972 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Presb Prep 4-2011.WMA
[2011/04/10 09:19:32 | 022,489,518 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-10-2011 dup maybe.WMA
[2011/04/07 16:27:09 | 000,000,312 | —- | C] () – C:\WINDOWS\tasks\recordpadShakeIcon.job
[2011/02/10 12:27:14 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2011/02/10 12:22:14 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2011/02/10 12:22:14 | 000,000,060 | —- | C] () – C:\WINDOWS\wpd99.drv
[2011/02/04 17:03:54 | 000,102,400 | —- | C] () – C:\WINDOWS\scrub2k.exe
[2011/02/04 17:03:54 | 000,000,423 | —- | C] () – C:\WINDOWS\hpw1200k.ini
[2011/02/04 17:03:16 | 000,017,889 | —- | C] () – C:\WINDOWS\hpbj1200.ini
[2011/02/04 17:03:10 | 000,005,731 | —- | C] () – C:\WINDOWS\mariner.ini
[2011/02/01 00:25:53 | 000,057,344 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/29 18:38:20 | 000,000,604 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\T2
[2011/01/29 18:38:20 | 000,000,604 | -H– | C] () – C:\Program Files\STLL Notifier
[2011/01/29 18:01:47 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2011/01/29 17:59:10 | 000,000,136 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\fusioncache.dat
[2011/01/29 17:51:31 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2011/01/29 17:49:57 | 000,004,528 | R— | C] () – C:\WINDOWS\System32\SETBROWS.EXE
[2006/02/25 03:02:55 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2006/02/25 00:28:54 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\TDispVol.dll
[2006/02/16 11:07:58 | 000,000,012 | —- | C] () – C:\WINDOWS\dirsaver.ini
[2006/02/16 05:55:04 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/02/16 05:50:52 | 000,000,222 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/02/16 05:25:21 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2006/02/16 05:25:21 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2006/02/16 05:25:21 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2006/02/16 05:25:21 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2006/02/16 05:25:21 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2006/02/16 05:25:21 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2006/02/15 12:41:53 | 000,036,736 | —- | C] () – C:\WINDOWS\System32\drivers\CSIIDecoder_kern_i386.sys
[2006/02/15 12:41:53 | 000,029,184 | —- | C] () – C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2006/02/15 12:40:07 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2006/02/15 12:28:50 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2006/02/15 12:28:50 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2006/02/15 12:28:50 | 000,010,165 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2006/02/15 12:28:50 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2006/02/15 12:25:00 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\TCtrlIO.dll
[2006/02/15 12:21:55 | 000,000,176 | —- | C] () – C:\WINDOWS\System32\drivers\RTHDAEQ1.dat
[2006/02/15 12:21:55 | 000,000,176 | —- | C] () – C:\WINDOWS\System32\drivers\RTHDAEQ0.dat
[2006/02/15 12:21:53 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2006/02/15 12:21:53 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2006/02/15 11:44:19 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/02/15 11:41:14 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/02/15 11:35:33 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/02/15 11:34:07 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/02/15 10:09:00 | 000,000,341 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/02/15 10:03:52 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/15 10:03:40 | 000,399,284 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/15 10:03:40 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/15 10:03:40 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/15 10:03:40 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/15 10:03:34 | 000,004,688 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/15 10:03:31 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/15 10:03:27 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/02/15 10:03:06 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/15 10:03:05 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/15 10:02:37 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/15 10:02:16 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/15 03:30:19 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/02/15 03:29:32 | 000,294,864 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/11/29 00:33:56 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/09/02 18:44:08 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2005/08/24 19:20:28 | 000,009,472 | —- | C] () – C:\WINDOWS\System32\drivers\tbiosdrv.sys
[2005/08/05 18:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/07/23 01:30:20 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2004/07/20 21:04:02 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 18:43:28 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\TBTMonUI.dll

========== LOP Check ==========

[2011/03/17 17:16:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/05/01 08:46:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2011/03/20 22:01:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/03/06 20:54:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2006/02/16 05:55:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/04/25 10:59:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{4DC9D39F-E342-4826-8E99-5A0EFA8682D7}
[2011/02/05 23:20:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard Sinclair\Application Data\Flickr
[2011/05/04 09:41:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard Sinclair\Application Data\gtk-2.0
[2011/04/11 11:50:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard Sinclair\Application Data\InterVideo
[2011/03/17 17:16:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard Sinclair\Application Data\NCH Swift Sound
[2011/02/10 12:27:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard Sinclair\Application Data\pdf995
[2011/01/29 17:49:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard Sinclair\Application Data\Protector Suite
[2011/02/25 12:32:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard Sinclair\Application Data\Recordpad
[2011/04/27 00:25:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard Sinclair\Application Data\searchquband
[2011/04/27 00:26:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard Sinclair\Application Data\searchqutoolbar
[2011/03/16 23:31:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard Sinclair\Application Data\TaxCut
[2006/02/16 05:18:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Richard Sinclair\Application Data\toshiba
[2011/05/04 09:59:17 | 000,000,312 | —- | M] () – C:\WINDOWS\Tasks\recordpadShakeIcon.job
[2011/03/11 12:05:27 | 000,000,300 | —- | M] () – C:\WINDOWS\Tasks\switchDowngrade.job
[2011/04/22 08:20:38 | 000,000,300 | —- | M] () – C:\WINDOWS\Tasks\switchShakeIcon.job
[2011/03/22 10:11:41 | 000,000,304 | —- | M] () – C:\WINDOWS\Tasks\wavepadShakeIcon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/02/15 11:38:58 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/01/29 17:57:51 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2006/02/15 11:38:58 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/08/21 17:32:50 | 000,219,780 | —- | M] () – C:\EULA.pdf
[2011/05/04 09:59:07 | 2137,051,136 | -HS- | M] () – C:\hiberfil.sys
[2006/02/15 11:38:58 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/02/16 05:56:48 | 000,001,222 | -H– | M] () – C:\IPH.PH
[2011/04/26 12:21:02 | 011,248,538 | —- | M] () – C:\LM9831Log.txt
[2006/02/15 11:38:58 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/02/01 07:24:26 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/04 09:59:05 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/02/15 11:38:17 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/06/18 21:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2004/12/08 20:04:46 | 000,045,056 | —- | M] (TOSHIBA) – C:\WINDOWS\cfdemo.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/01/29 18:38:20 | 000,000,604 | -H– | M] () – C:\Program Files\STLL Notifier

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/02/15 03:28:58 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/02/15 03:28:58 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/02/15 03:28:57 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/02/01 07:28:25 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2006/02/18 10:17:27 | 000,005,120 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/01/29 17:59:30 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Richard Sinclair\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2002/05/06 14:19:45 | 000,000,079 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-27 22:37:50

< End of report >


OTL Extras logfile created on: 5/4/2011 10:34:30 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Richard Sinclair\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 69.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 124.95 Gb Free Space | 53.65% Space Free | Partition Type: NTFS

Computer Name: TOSHIBA-USER | User Name: Richard Sinclair | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\TOSHIBA\ivp\NetInt\Netint.exe" = C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrade Engine – (TOSHIBA Corporation)
"C:\TOSHIBA\Ivp\ISM\pinger.exe" = C:\TOSHIBA\IVP\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger – (TOSHIBA Corporation)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed
"C:\Program Files\Common Files\AOL\1140083713\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1140083713\EE\AOLServiceHost.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL
"C:\Program Files\Windows Savevid Toolbar\ToolBar\dtUser.exe" = C:\Program Files\Windows Savevid Toolbar\ToolBar\dtUser.exe:*:Enabled:DTX broker – (Visicom Media Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{10964A8F-21C1-45EA-BC2D-F84B505C3848}" = H&R; Block Deluxe + Efile + State 2010
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2BD90AED-0FF2-4A69-B84D-DC0679991FB7}" = Evince 2.30.3
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator 2
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{425A2BC2-AA64-4107-9C29-484245BBEA05}" = TOSHIBA Software Upgrades
"{4497AFF6-98C4-4F49-B073-F48F42BCBF9E}" = TIPCI
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{48CF9A66-5F03-4025-ABD0-B3A3FA095A59}" = TOSHIBA SD Memory Card Format
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{597E70FF-7C46-4EED-8092-91B7C2E0529D}" = Google SketchUp 7
"{5A80C75C-EB3A-4275-A6C4-2E20349DBF4C}" = H&R; Block New York 2010
"{64212898-097F-4F3F-AECA-6D34A7EF82DF}" = TOSHIBA Zooming Utility
"{64DD71BC-3109-4C88-9AD3-D5422644B722}" = TOSHIBA Hotkey Utility
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{69BE47C2-36FE-4397-8199-85D8EAE69982}" = TOSHIBA TouchPad ON/Off Utility
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{78C68CB9-3DF5-44F3-AB9D-FA305C5EB85C}" = TOSHIBA Utilities
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B12BA86-ADAC-4BA6-B441-FFC591087252}" = TOSHIBA Virtual Sound
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for TOSHIBA
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}" = TOSHIBA Controls
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{BE3F89C0-42D5-11D5-A40A-00105AC8331A}" = Metamail (Toshiba Registration Utility)
"{C45F4811-31D5-4786-801D-F79CD06EDD85}" = SD Secure Module
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDBFC424-DD00-497F-9BDC-4E4178332336}" = Protector Suite 5.4
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D0FDE53C-30CE-4432-9809-756E1A6CEF44}" = HP Business Inkjet 1200
"{D22002ED-EE2A-4CB1-A63D-430E62A2E8D8}" = Google SketchUp 8
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Audacity_is1" = Audacity 1.2.6
"BibleCD" = Power BibleCD
"Flickr Uploadr" = Flickr Uploadr 3.2.1
"FLV Player2.0.25" = FLV Player
"Google Desktop" = Google Desktop
"hp business inkjet 1200 series" = HP Business Inkjet 1200
"ie8" = Windows Internet Explorer 8
"InstallShield_{4497AFF6-98C4-4F49-B073-F48F42BCBF9E}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"Native Instruments Sibelius Player" = Native Instruments Sibelius Player
"Neuratron PhotoScore Lite" = Neuratron PhotoScore Lite
"PC Diagnostic Tool" = TOSHIBA PC Diagnostic Tool
"Pdf995" = Pdf995
"Picasa2" = Picasa 2
"Power Saver" = TOSHIBA Power Saver
"ProInst" = Intel® PROSet/Wireless Software
"PROPLUS" = Microsoft Office Professional Plus 2007
"PROSet" = Intel® PRO Network Connections Drivers
"QuickTime" = QuickTime
"RealPlayer 12.0" = RealPlayer
"Recordpad" = RecordPad Sound Recorder
"Searchqu 405 MediaBar" = Windows Savevid Toolbar
"Sibelius 4" = Sibelius 4
"Switch" = Switch Sound File Converter
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"TOSHIBA TV Tuner" = TOSHIBA TV Tuner [removed]
"ViewpointMediaPlayer" = Viewpoint Media Player
"WavePad" = WavePad Sound Editor
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.11

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/1/2011 7:53:45 PM | Computer Name = TOSHIBA-USER | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3989, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 4/28/2011 12:29:51 PM | Computer Name = TOSHIBA-USER | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.10.108
with the system having network hardware address DC:2B:61:68:82:9B. Network operations
on this system may be disrupted as a result.

Error - 4/28/2011 12:29:51 PM | Computer Name = TOSHIBA-USER | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.10.108
with the system having network hardware address DC:2B:61:68:82:9B. Network operations
on this system may be disrupted as a result.

Error - 4/28/2011 4:27:05 PM | Computer Name = TOSHIBA-USER | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.10.108 for the Network Card with network
address 00130272B1B9 has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).

Error - 4/30/2011 10:48:51 AM | Computer Name = TOSHIBA-USER | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.100 for the Network Card with network
address 00130272B1B9 has been denied by the DHCP server 192.168.10.1 (The DHCP Server
sent a DHCPNACK message).

Error - 4/30/2011 10:26:51 PM | Computer Name = TOSHIBA-USER | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.10.122 for the Network Card with network
address 00130272B1B9 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 5/1/2011 6:43:42 AM | Computer Name = TOSHIBA-USER | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.111 for the Network Card with network
address 00130272B1B9 has been denied by the DHCP server 192.168.10.1 (The DHCP Server
sent a DHCPNACK message).

Error - 5/1/2011 8:33:01 AM | Computer Name = TOSHIBA-USER | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.10.122 for the Network Card with network
address 00130272B1B9 has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).

Error - 5/1/2011 8:46:41 AM | Computer Name = TOSHIBA-USER | Source = DCOM | ID = 10010
Description = The server {D5E8041D-920F-45E9-B8FB-B1DEB82C6E5E} did not register
with DCOM within the required timeout.

Error - 5/2/2011 9:07:48 AM | Computer Name = TOSHIBA-USER | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.0.100 on
the Network Card with network address 00130272B1B9.

Error - 5/3/2011 8:52:52 AM | Computer Name = TOSHIBA-USER | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.100 for the Network Card with network
address 00130272B1B9 has been denied by the DHCP server 192.168.10.1 (The DHCP Server
sent a DHCPNACK message).


< End of report >
Hi madrid, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Please go to add/remove programs and uninstall

J2SE Runtime Environment 5.0 Update 4
Windows Savevid Toolbar




Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/405
[2010/12/09 11:17:40 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows Savevid Toolbar\ToolBar\searchqudtx.dll ()
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows Savevid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows Savevid Toolbar\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O20 - AppInit_DLLs: (C:\PROGRA~1\WI0498~1\Datamngr\datamngr.dll) - C:\Program Files\Windows Savevid Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI0498~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows Savevid Toolbar\Datamngr\IEBHO.dll (Discordia, LTD)
[2011/04/25 10:59:31 | 000,000,000 | —D | C] – C:\Program Files\Savevid
[2011/04/24 09:40:57 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{4DC9D39F-E342-4826-8E99-5A0EFA8682D7}
[2011/04/24 09:37:13 | 000,000,000 | —D | C] – C:\Program Files\Windows Savevid Toolbar
[2011/04/24 09:37:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\PackageAware

:Files
C:\Documents and Settings\Richard Sinclair\Application Data\searchquband
C:\Documents and Settings\Richard Sinclair\Application Data\searchqutoolbar
ipconfig /flushdns

:Commands
[createrestorepoint]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Next

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Next

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt(no Extra.txt this time).


Please post back with
  • OTL fix log
  • MBAM log
  • OTL.txt
How's the computer?

Thanks
All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. File C:\Program Files\Windows Savevid Toolbar\ToolBar\searchqudtx.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ not found. File C:\Program Files\Windows Savevid Toolbar\Datamngr\IEBHO.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found. File C:\Program Files\Windows Savevid Toolbar\ToolBar\searchqudtx.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI0498~1\Datamngr\datamngr.dll deleted successfully. C:\Program Files\Windows Savevid Toolbar\Datamngr\datamngr.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI0498~1\Datamngr\IEBHO.dll deleted successfully. File C:\Program Files\Windows Savevid Toolbar\Datamngr\IEBHO.dll not found. C:\Program Files\Savevid\[removed]\chrome\content folder moved successfully. C:\Program Files\Savevid\[removed]\chrome folder moved successfully. C:\Program Files\Savevid\[removed] folder moved successfully. C:\Program Files\Savevid folder moved successfully. C:\Documents and Settings\All Users\Application Data\{4DC9D39F-E342-4826-8E99-5A0EFA8682D7} folder moved successfully. C:\Program Files\Windows Savevid Toolbar\Datamngr folder moved successfully. C:\Program Files\Windows Savevid Toolbar folder moved successfully. C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\PackageAware folder moved successfully. ========== FILES ========== C:\Documents and Settings\Richard Sinclair\Application Data\searchquband folder moved successfully. File\Folder C:\Documents and Settings\Richard Sinclair\Application Data\searchqutoolbar not found. Invalid Switch: flushdns ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32768 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 56502 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32969 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Richard Sinclair ->Temp folder emptied: 88468216 bytes ->Temporary Internet Files folder emptied: 412650205 bytes ->Java cache emptied: 123683 bytes ->FireFox cache emptied: 189565828 bytes ->Flash cache emptied: 31299 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1288168 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 407590296 bytes Total Files Cleaned = 1,049.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 05052011_223916 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6516 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 5/5/2011 10:50:34 PM mbam-log-2011-05-05 (22-50-34).txt Scan type: Quick scan Objects scanned: 154587 Time elapsed: 3 minute(s), 58 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
OTL logfile created on: 5/5/2011 11:29:38 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Richard Sinclair\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 126.78 Gb Free Space | 54.44% Space Free | Partition Type: NTFS

Computer Name: TOSHIBA-USER | User Name: Richard Sinclair | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Richard Sinclair\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
PRC - C:\Program Files\Protector Suite QL\psqltray.exe (UPEK Inc.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\Program Files\Synaptics\SynTP\Toshiba.exe (Synaptics, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\TOSHIBA\Tvs\TvsTray.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe (TOSHIBA Corporation)
PRC - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
PRC - C:\WINDOWS\system32\TPSMain.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\TOSHIBA\IVP\ISM\pinger.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TDispVol.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
PRC - C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
PRC - C:\Program Files\Hewlett-Packard\hp business inkjet 1200 series\Toolbox\HPWNTBX.exe (Hewlett-Packard Company)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Richard Sinclair\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\TDispVol.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (aspnet_state) – File not found
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (TAPPSRV) – C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
SRV - (Swupdtmr) – c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)


========== Driver Services (SafeList) ==========

DRV - (FdRedir) – C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys (UPEK Inc.)
DRV - (FileDisk2) – C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys (UPEK Inc.)
DRV - (smihlp) – C:\Program Files\Protector Suite QL\smihlp.sys (UPEK Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (Tvs) – C:\WINDOWS\system32\drivers\Tvs.sys (TOSHIBA Corporation)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (TVALD) – C:\WINDOWS\system32\drivers\NBSMI.sys (Toshiba Corporation)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (tosrfec) – C:\WINDOWS\system32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (tbiosdrv) – C:\WINDOWS\system32\drivers\tbiosdrv.sys ()
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (KR10N) – C:\WINDOWS\system32\drivers\KR10N.sys (TOSHIBA CORPORATION)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/02/07 12:48:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/29 15:33:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/24 13:28:27 | 000,000,000 | —D | M]

[2011/05/05 22:37:34 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard Sinclair\Application Data\Mozilla\Extensions
[2011/02/05 23:20:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard Sinclair\Application Data\Mozilla\Extensions\[removed]
[2011/04/25 15:26:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard Sinclair\Application Data\Mozilla\Firefox\Profiles\i6ozt9ar.default\extensions
[2011/02/10 11:36:43 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Richard Sinclair\Application Data\Mozilla\Firefox\Profiles\i6ozt9ar.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/03/24 13:28:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Richard Sinclair\Application Data\Mozilla\Firefox\Profiles\i6ozt9ar.default\extensions\nostmp
[2011/05/05 22:37:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/01/31 23:54:49 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/29 15:33:11 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/01/31 23:54:41 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2004/08/10 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CFSServ.exe] File not found
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [HPWNTOOLBOX] C:\Program Files\Hewlett-Packard\hp business inkjet 1200 series\Toolbox\HPWNTBX.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [PadTouch] File not found
O4 - HKLM..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\Protector Suite QL\launcher.exe (UPEK Inc.)
O4 - HKLM..\Run: [Recordpad] C:\Program Files\NCH Swift Sound\Recordpad\recordpad.exe (NCH Software)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TDispVol] C:\WINDOWS\System32\TDispVol.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [THotkey] C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [DW6] File not found
O4 - HKCU..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_22.dll (Sun Microsystems, Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\psfus: DllName - psqlpwd.dll - C:\WINDOWS\System32\psqlpwd.dll (UPEK Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/02/15 11:38:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/05/05 22:39:16 | 000,000,000 | —D | C] – C:\_OTL
[2011/05/05 22:18:29 | 000,000,000 | R-SD | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Safe
[2011/04/30 16:34:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\get.cfm_files
[2011/04/26 09:57:03 | 000,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\um34scan.dll
[2011/04/26 09:57:03 | 000,216,064 | —- | C] (UMAX Data Systems Inc.) – C:\WINDOWS\System32\dllcache\um34scan.dll
[2011/04/24 21:43:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Picasa2
[2011/04/24 21:43:18 | 000,000,000 | —D | C] – C:\Program Files\Picasa2
[2011/04/22 09:41:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\RCF Presbytery 4-2011
[2011/04/22 08:32:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Application Data\Sonic
[2011/04/16 12:54:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\ZGhost
[2011/04/16 12:54:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\ZBackup info
[2011/04/16 12:54:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\ZApplication Downloads
[2011/04/16 12:53:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\When I Return from Sabbatical
[2011/04/16 12:53:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Vision Folder
[2011/04/16 12:53:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Updater5
[2011/04/16 12:51:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\TomTom
[2011/04/16 12:50:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Timothy Center
[2011/04/16 12:50:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\commandments_files
[2011/04/16 12:50:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\command_introduction_files
[2011/04/16 12:47:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - edited aud_data
[2011/04/16 12:47:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\GCC Audio Files
[2011/04/16 12:47:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Desktop\Tom Pahler - April 2011
[2011/04/16 12:46:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 4-14-2009
[2011/04/16 12:46:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 4-1-08
[2011/04/16 12:42:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 3-30-2011
[2011/04/16 12:42:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 1-28-2011
[2011/04/16 12:42:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 1-15-2011
[2011/04/16 12:42:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 1-12-2011
[2011/04/16 12:40:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Temp Desktop 1-4-2010
[2011/04/16 12:11:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Teaching- Training
[2011/04/16 08:35:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\TaxCut
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\SightSpeed Recordings
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Sibelius Files
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\ShareContacts
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Scores
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Recordpad
[2011/04/16 06:42:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Pradis
[2011/04/16 06:30:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\PERSONAL
[2011/04/15 22:58:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\PcSetup
[2011/04/15 22:58:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Nolo Documents Backup
[2011/04/15 22:57:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\New Folder
[2011/04/15 22:57:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Videos
[2011/04/15 22:57:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Practice Files
[2011/04/15 22:57:43 | 000,000,000 | R–D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Pictures
[2011/04/15 22:49:40 | 000,000,000 | R–D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Music
[2011/04/15 22:49:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My Data Sources
[2011/04/15 22:45:50 | 000,000,000 | R–D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\My 2011 Pix
[2011/04/15 22:44:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\GCC Moira
[2011/04/15 22:44:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Ministries, Fellowships, etc
[2011/04/15 22:44:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Master Planning
[2011/04/15 22:39:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Kid's Files
[2011/04/15 22:38:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Individuals
[2011/04/15 22:38:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\HRBlock
[2011/04/15 22:38:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\gegl-0.0
[2011/04/15 22:38:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Forms-Tools
[2011/04/15 22:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Finale-Sibelius Files
[2011/04/15 22:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Fax
[2011/04/15 22:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\DVD X Studios
[2011/04/15 22:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\DSSPlayer
[2011/04/15 22:37:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\DRConfig
[2011/04/15 22:37:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Downloads
[2011/04/15 22:35:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Desktop stuff 9-10-2008
[2011/04/15 22:35:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Darlene's File
[2011/04/15 22:35:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Computer info & Shopping
[2011/04/15 22:31:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\CFC
[2011/04/15 22:31:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\My Documents\Books
[2011/04/13 18:40:10 | 004,284,416 | —- | C] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2011/04/11 11:50:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Richard Sinclair\Application Data\InterVideo
[2006/02/15 12:25:00 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\DLLVGA.dll

========== Files - Modified Within 30 Days ==========

[2011/05/05 23:29:40 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-4281795085-2703001846-136500816-1005.job
[2011/05/05 23:29:39 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-4281795085-2703001846-136500816-1005.job
[2011/05/05 22:42:36 | 000,000,312 | —- | M] () – C:\WINDOWS\tasks\recordpadShakeIcon.job
[2011/05/05 22:41:50 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/05 22:41:49 | 2137,051,136 | -HS- | M] () – C:\hiberfil.sys
[2011/05/05 12:59:52 | 000,060,416 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/04 23:40:32 | 000,023,729 | —- | M] () – C:\Documents and Settings\Richard Sinclair\.recently-used.xbel
[2011/05/03 14:11:28 | 000,000,789 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Shortcut to Town of Madrid - Zoning Issues.lnk
[2011/05/01 08:46:09 | 000,000,060 | —- | M] () – C:\WINDOWS\wpd99.drv
[2011/04/30 16:53:11 | 000,281,144 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\healthrisksSSA.pdf
[2011/04/30 16:34:25 | 000,071,493 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\get.cfm.htm
[2011/04/30 15:16:02 | 000,114,118 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\deathofmarriage.pdf
[2011/04/30 11:54:47 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/04/30 11:54:47 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2011/04/26 12:21:02 | 000,000,026 | —- | M] () – C:\WINDOWS\Debug.ini
[2011/04/26 12:21:02 | 000,000,016 | —- | M] () – C:\WINDOWS\Temp.ini
[2011/04/26 12:20:53 | 000,000,553 | —- | M] () – C:\WINDOWS\umaxuapi.ini
[2011/04/26 00:52:59 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/24 21:43:29 | 000,000,695 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa2.lnk
[2011/04/24 21:43:29 | 000,000,677 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Picasa2.lnk
[2011/04/24 09:48:13 | 022,402,972 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\The Death and Resurrection of Jesus Christ - Twitter style [HD].flv
[2011/04/22 08:20:38 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\switchShakeIcon.job
[2011/04/17 09:31:10 | 023,074,908 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-17-2011.WMA
[2011/04/15 03:23:29 | 000,294,864 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/15 03:06:23 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/15 03:05:30 | 002,005,471 | —- | M] () – C:\WINDOWS\iis6.BAK
[2011/04/13 18:40:10 | 004,284,416 | —- | M] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2011/04/11 22:37:52 | 017,496,864 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Rick Sinclair - Prophetic Ministry 4-8-2011 compressed.mp3
[2011/04/11 22:30:12 | 514,409,448 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - edited.wav
[2011/04/11 22:27:02 | 000,151,498 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - edited aud.aup
[2011/04/11 22:17:22 | 047,856,086 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - Copy.mp3
[2011/04/11 22:14:00 | 000,001,085 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\WavePad Sound Editor.lnk
[2011/04/11 22:02:20 | 000,001,780 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Be Creative on Facebook With Facepaint Layouts.lnk
[2011/04/11 22:02:20 | 000,001,777 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Free Music Downloads.lnk
[2011/04/11 22:02:20 | 000,001,767 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Free Games!!.lnk
[2011/04/11 20:32:50 | 036,679,972 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Presb Prep 4-2011.WMA
[2011/04/11 20:32:50 | 036,679,972 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Presb Prep 4-11-2011.WMA
[2011/04/10 10:05:58 | 022,489,518 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-10-2011.WMA
[2011/04/10 10:05:58 | 022,489,518 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-10-2011 dup maybe.WMA
[2011/04/07 16:22:19 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/07 11:49:18 | 000,257,536 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Colson DVD & support info.dot
[2011/04/06 08:58:34 | 058,689,727 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla - Ravel.wmv
[2011/04/06 08:29:12 | 158,828,572 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla - Beethoven.wmv
[2011/04/06 07:57:16 | 058,804,897 | —- | M] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla's Recital - Bach.wmv

========== Files Created - No Company Name ==========

[2011/05/04 23:40:32 | 000,023,729 | —- | C] () – C:\Documents and Settings\Richard Sinclair\.recently-used.xbel
[2011/05/03 14:11:28 | 000,000,789 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Shortcut to Town of Madrid - Zoning Issues.lnk
[2011/04/30 16:53:10 | 000,281,144 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\healthrisksSSA.pdf
[2011/04/30 16:34:24 | 000,071,493 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\get.cfm.htm
[2011/04/30 15:16:02 | 000,114,118 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\deathofmarriage.pdf
[2011/04/30 11:54:47 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2011/04/30 11:54:47 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2011/04/26 17:01:27 | 066,741,394 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Personal_Restoration_Part_04.mp3
[2011/04/26 17:01:10 | 081,837,662 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Personal_Restoration_Part_03.mp3
[2011/04/26 17:00:56 | 091,008,522 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Personal_Restoration_Part_02.mp3
[2011/04/26 17:00:49 | 041,477,016 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Personal_Restoration_Part_01.mp3
[2011/04/26 17:00:44 | 041,012,232 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Louie Giglio - Gospel According to Krispy Kreme.flv
[2011/04/26 09:58:49 | 000,000,553 | —- | C] () – C:\WINDOWS\umaxuapi.ini
[2011/04/26 09:57:41 | 000,000,016 | —- | C] () – C:\WINDOWS\Temp.ini
[2011/04/26 09:57:09 | 000,000,026 | —- | C] () – C:\WINDOWS\Debug.ini
[2011/04/26 00:52:59 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/24 21:43:29 | 000,000,695 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa2.lnk
[2011/04/24 21:43:29 | 000,000,677 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Picasa2.lnk
[2011/04/24 09:44:05 | 022,402,972 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\The Death and Resurrection of Jesus Christ - Twitter style [HD].flv
[2011/04/22 08:20:38 | 000,000,300 | —- | C] () – C:\WINDOWS\tasks\switchShakeIcon.job
[2011/04/18 16:47:56 | 022,489,518 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-10-2011.WMA
[2011/04/18 16:47:52 | 036,679,972 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Presb Prep 4-11-2011.WMA
[2011/04/17 08:43:32 | 023,074,908 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-17-2011.WMA
[2011/04/16 12:54:21 | 000,023,321 | —- | C] () – C:\Documents and Settings\Richard Sinclair\My Documents\Facebook pic.jpg
[2011/04/16 12:47:15 | 000,001,085 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\WavePad Sound Editor.lnk
[2011/04/16 12:47:14 | 017,496,864 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Rick Sinclair - Prophetic Ministry 4-8-2011 compressed.mp3
[2011/04/16 12:47:14 | 000,001,777 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Free Music Downloads.lnk
[2011/04/16 12:47:14 | 000,001,767 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Free Games!!.lnk
[2011/04/16 12:46:57 | 514,409,448 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - edited.wav
[2011/04/16 12:46:56 | 000,151,498 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - edited aud.aup
[2011/04/16 12:46:54 | 047,856,086 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\DS300005 - Copy.mp3
[2011/04/16 12:46:54 | 000,257,536 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Colson DVD & support info.dot
[2011/04/16 12:46:54 | 000,019,294 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\command_introduction.htm
[2011/04/16 12:46:54 | 000,004,503 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\commandments.htm
[2011/04/16 12:46:52 | 058,804,897 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla's Recital - Bach.wmv
[2011/04/16 12:46:50 | 058,689,727 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla - Ravel.wmv
[2011/04/16 12:46:45 | 158,828,572 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Camilla - Beethoven.wmv
[2011/04/16 12:46:45 | 000,001,780 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Be Creative on Facebook With Facepaint Layouts.lnk
[2011/04/11 19:17:10 | 036,679,972 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Presb Prep 4-2011.WMA
[2011/04/10 09:19:32 | 022,489,518 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Desktop\Pillars 4-10-2011 dup maybe.WMA
[2011/04/07 16:27:09 | 000,000,312 | —- | C] () – C:\WINDOWS\tasks\recordpadShakeIcon.job
[2011/02/10 12:27:14 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2011/02/10 12:22:14 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2011/02/10 12:22:14 | 000,000,060 | —- | C] () – C:\WINDOWS\wpd99.drv
[2011/02/04 17:03:54 | 000,102,400 | —- | C] () – C:\WINDOWS\scrub2k.exe
[2011/02/04 17:03:54 | 000,000,423 | —- | C] () – C:\WINDOWS\hpw1200k.ini
[2011/02/04 17:03:16 | 000,017,889 | —- | C] () – C:\WINDOWS\hpbj1200.ini
[2011/02/04 17:03:10 | 000,005,731 | —- | C] () – C:\WINDOWS\mariner.ini
[2011/02/01 00:25:53 | 000,060,416 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/29 18:38:20 | 000,000,604 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\T2
[2011/01/29 18:38:20 | 000,000,604 | -H– | C] () – C:\Program Files\STLL Notifier
[2011/01/29 18:01:47 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2011/01/29 17:59:10 | 000,000,136 | —- | C] () – C:\Documents and Settings\Richard Sinclair\Local Settings\Application Data\fusioncache.dat
[2011/01/29 17:51:31 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2011/01/29 17:49:57 | 000,004,528 | R— | C] () – C:\WINDOWS\System32\SETBROWS.EXE
[2006/02/25 03:02:55 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2006/02/25 00:28:54 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\TDispVol.dll
[2006/02/16 11:07:58 | 000,000,012 | —- | C] () – C:\WINDOWS\dirsaver.ini
[2006/02/16 05:55:04 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/02/16 05:50:52 | 000,000,222 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/02/16 05:25:21 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2006/02/16 05:25:21 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2006/02/16 05:25:21 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2006/02/16 05:25:21 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2006/02/16 05:25:21 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2006/02/16 05:25:21 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2006/02/15 12:41:53 | 000,036,736 | —- | C] () – C:\WINDOWS\System32\drivers\CSIIDecoder_kern_i386.sys
[2006/02/15 12:41:53 | 000,029,184 | —- | C] () – C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2006/02/15 12:40:07 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2006/02/15 12:28:50 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2006/02/15 12:28:50 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2006/02/15 12:28:50 | 000,010,165 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2006/02/15 12:28:50 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2006/02/15 12:25:00 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\TCtrlIO.dll
[2006/02/15 12:21:55 | 000,000,176 | —- | C] () – C:\WINDOWS\System32\drivers\RTHDAEQ1.dat
[2006/02/15 12:21:55 | 000,000,176 | —- | C] () – C:\WINDOWS\System32\drivers\RTHDAEQ0.dat
[2006/02/15 12:21:53 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2006/02/15 12:21:53 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2006/02/15 11:44:19 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/02/15 11:41:14 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/02/15 11:35:33 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/02/15 11:34:07 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/02/15 10:09:00 | 000,000,341 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/02/15 10:03:52 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/15 10:03:40 | 000,399,284 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/15 10:03:40 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/15 10:03:40 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/15 10:03:40 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/15 10:03:34 | 000,004,688 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/15 10:03:31 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/15 10:03:27 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/02/15 10:03:06 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/15 10:03:05 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/15 10:02:37 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/15 10:02:16 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/15 03:30:19 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/02/15 03:29:32 | 000,294,864 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/11/29 00:33:56 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/09/02 18:44:08 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2005/08/24 19:20:28 | 000,009,472 | —- | C] () – C:\WINDOWS\System32\drivers\tbiosdrv.sys
[2005/08/05 18:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/07/23 01:30:20 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2004/07/20 21:04:02 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 18:43:28 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\TBTMonUI.dll

< End of report >
Hi madrid,

What are you using for an antivirus program?

How is the computer?

Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK
Hi madrid,

Ok we'll clean up the tools.

First, I don't see an antivirus program installed on this computer. If you do not have one installed you can use one of these free ones. Do not install one if you already have one.

Avast
Help and support can be found here Avast Forum
AVG
Help and support can be found here AVG Forum
Antivir PersonalEditionClassic
Help and support can be found here Avira Personal Support Forum
Microsoft Security Essentials
Support


From your desktop, please delete, if present
  • any notepads/logs that we created

Next

* Create a new restore point

You must be logged on to an administrator account
  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create
* Remove old restore points

  • Go to Start - All Programs - Accessories - system tools.
  • Launch the Disk Cleanup tool and let it run.
  • When it finishes a box with tabs will appear, select the more options tab.
  • On this tab you will find a section for System Restore.
  • If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep it updated and use it regularly.

Some Recommendations and prevention tips
Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

I suggest either for a resident antispyware program.

Windows Defender
OR
Winpatrol

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)

A guide to understanding and using Custom hosts file which you have.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis

- Make sure you have reset Automatic Updates to your chosen optionClick your start button > Control Panel > System

- Keep your antivirus program updated, as well as any other security programs you have.

-More tips and programs can be found HERE

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

Please post back if you have any problems.

Take care :adios:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI