This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows Recovery and Hard Drive Failure

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Didn't understand that it was a virus at first and ran a checkdisk. When it came back up there were no desktop icons and warning messages where I figured out it was an infection.

Ran Malwarebytes, SuperAntiSpyware and Vipre (was outdated when the virus came, but updated it)

The main parts of the infection are gone, but it looked like that it had removed all desktop icons, all items under "All Programs", all files in My Documents. Realized that the attributes for them were set to Hidden and Read Only. Was able to reset them back. Unfortunately many of the submenus are empty.

Still a problem: The programs that were pinned to the Start button and redirects in Firefox. Haven't test IE. Also Microsoft Office icons haven't shown up. I can run them from Program Files.

Posted the results for them and just ran otl with it's results.

Thanks for your help.

SuperAntiSpyware
==============================================================
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/30/2011 at 12:52 PM

Application Version : 4.41.1000

Core Rules Database Version : 7164
Trace Rules Database Version: 4976

Scan type : Complete Scan
Total Scan Time : 00:39:21

Memory items scanned : 474
Memory threats detected : 0
Registry items scanned : 6292
Registry threats detected : 0
File items scanned : 21156
File threats detected : 79

Adware.Tracking Cookie
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@atdmt[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@burstbeacon[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@imrworldwide[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@insightexpressai[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@pointroll[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@revsci[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@apmebf[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][3].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@burstnet[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@invitemedia[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@interclick[3].txt
C:\Documents and Settings\Barbie\Cookies\[removed][3].txt
C:\Documents and Settings\Barbie\Cookies\barbie@mediabrandsww[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@collective-media[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@zedo[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@mediaplex[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@serving-sys[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@adbrite[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@doubleclick[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
ec.atdmt.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
media.mtvnservices.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
media1.break.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
msnbcmedia.msn.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
secure-us.imrworldwide.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
spe.atdmt.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
C:\Documents and Settings\Barbie\Cookies\barbie@yieldmanager[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@msnportal.112.2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@interclick[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@dmtracker[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@leeenterprises.112.2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@112.2o7[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@adbrite[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@burstbeacon[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@specificmedia[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@adxpose[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@invitemedia[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@eyewonder[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@insightexpressai[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@martiniadnetwork[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@legolas-media[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@specificclick[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@msnbc.112.2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@mediabrandsww[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@advertising[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt

Trojan.Agent/Gen-Nullo[Short]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{CE1C12AC-59BB-4220-B895-862AF2DD144F}\RP919\A0144276.EXE


MalWareBytes
================================================================================
======
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6705

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

5/28/2011 4:53:52 PM
mbam-log-2011-05-28 (16-53-52).txt

Scan type: Full scan (C:\|)
Objects scanned: 40950
Time elapsed: 14 minute(s), 47 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
c:\documents and settings\all users\application data\lobouyvvyw.exe (Trojan.FakeMS) -> 1024 -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\LoBoUYvVYw (Trojan.FakeMS) -> Value: LoBoUYvVYw -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\all users\application data\lobouyvvyw.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.



Second scan
============================================================================
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6705

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

5/28/2011 8:07:58 PM
mbam-log-2011-05-28 (20-07-58).txt

Scan type: Full scan (C:\|)
Objects scanned: 206389
Time elapsed: 1 hour(s), 8 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallPaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop (PUM.Hidden.Desktop) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

===============================================================================

OTL logfile created on: 5/30/2011 4:55:00 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Barbie\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.67 Mb Total Physical Memory | 590.51 Mb Available Physical Memory | 57.74% Memory free
2.40 Gb Paging File | 1.93 Gb Available in Paging File | 80.20% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 25.16 Gb Free Space | 67.52% Space Free | Partition Type: NTFS

Computer Name: BARBIE-PC | User Name: Barbie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Barbie\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_user_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_system_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_service.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_host.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_comm_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Verizon\McciTrayApp.exe (Motive Communications, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Iomega\REV System Software\ImIconXp.exe (Iomega Corporation)
PRC - C:\Program Files\Iomega\REV System Software\RevUDF.exe (Iomega Corp)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Barbie\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Motive\McciContextHook_DSR.dll (Alcatel-Lucent)


========== Win32 Services (SafeList) ==========

SRV - (GoToAssist Express Customer) – C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_service.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (SBAMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
SRV - (SBPIMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
SRV - (afcdpsrv) – C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (RevUDFService) – C:\Program Files\Iomega\REV System Software\RevUDF.exe (Iomega Corp)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Driver Services (SafeList) ==========

DRV - (sbapifs) – C:\WINDOWS\system32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (sbaphd) – C:\WINDOWS\system32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (SbFw) – C:\WINDOWS\system32\drivers\SbFw.sys (Sunbelt Software, Inc.)
DRV - (SbTis) – C:\WINDOWS\system32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (SbHips) – C:\WINDOWS\system32\drivers\sbhips.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCL) – C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (SBRE) – C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (afcdp) – C:\WINDOWS\system32\drivers\afcdp.sys (Acronis)
DRV - (tdrpman258) Acronis Try&Decide; and Restore Points filter (build 258) – C:\WINDOWS\system32\DRIVERS\tdrpm258.sys (Acronis)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (usbsermpt) – C:\WINDOWS\system32\drivers\usbsermpt.sys (Microsoft Corporation)
DRV - (imdrvfsf) – C:\WINDOWS\system32\DRIVERS\imdrvfsf.sys (Iomega Corporation)
DRV - (IABFilt) – C:\WINDOWS\system32\DRIVERS\IABFilt.sys (Iomega)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (SMBios) Intel ® – C:\WINDOWS\system32\drivers\SMBios.sys (Intel Corporation)
DRV - (sf) – C:\WINDOWS\system32\drivers\sf.sys (Sonic Focus, Inc)
DRV - (MidiSyn) – C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (QV2KUX) – C:\WINDOWS\system32\drivers\qv2kux.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/default.aspx?mypg=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 31 F6 58 51 2A 17 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.startup.homepage: "http://my.msn.com/default.aspx?mypg=1"
FF - prefs.js..keyword.URL: "http://www.google.com/search?sourceid=navclient&hl;=en&q;="
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/23 13:13:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/05/23 13:13:46 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Barbie\Application Data\Mozilla\Extensions
[2011/05/23 14:13:05 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Barbie\Application Data\Mozilla\Firefox\Profiles\46esaizr.default\extensions
[2011/05/23 14:13:05 | 000,000,000 | -H-D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Barbie\Application Data\Mozilla\Firefox\Profiles\46esaizr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/05/23 13:13:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2010/08/05 10:15:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/04/14 09:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 01:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2001/08/23 09:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Coupons.com Toolbar) - {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
O2 - BHO: (PCTools Site Guard) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Coupons.com Toolbar) - {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Coupons.com Toolbar) - {37153479-1976-43C3-A1EE-557513977B64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [Iomega ImIconXP] C:\Program Files\Iomega\REV System Software\ImIconXp.exe (Iomega Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [yrsgtjkbutlqmc] File not found
O4 - HKLM..\RunOnceEx: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1143505706468 (WUWebControl Class)
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} file://C:\TempEI4\EI40_\msxml4.cab (XML DOM Document 4.0)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist Express Customer: DllName - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_winlogon.dll - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_winlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\System32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/27 17:10:39 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/30 13:18:44 | 000,000,000 | —D | C] – C:\VIPRERESCUE
[2011/05/30 12:10:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\Application Data\SUPERAntiSpyware.com
[2011/05/28 16:52:27 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Recent
[2011/05/28 16:31:48 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Malwarebytes
[2011/05/28 16:19:06 | 000,074,968 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbapifs.sys
[2011/05/28 16:16:22 | 000,021,592 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbaphd.sys
[2011/05/28 16:16:21 | 000,212,568 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\sbtis.sys
[2011/05/28 16:16:21 | 000,094,040 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\sbhips.sys
[2011/05/28 16:16:17 | 000,332,248 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\SbFw.sys
[2011/05/28 16:16:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Sunbelt Software
[2011/05/28 16:05:57 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Windows XP Recovery
[2011/05/28 15:55:10 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Adobe
[2011/05/24 10:53:11 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/24 10:52:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\My Documents\Downloads
[2011/05/23 13:13:30 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Mozilla
[2011/05/23 13:13:30 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Mozilla
[2011/05/23 13:13:21 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/05/22 09:05:17 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Conduit
[2011/05/22 09:05:17 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2011/05/22 09:05:16 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Coupons.com
[2011/05/22 09:05:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Temp
[2011/05/22 09:05:14 | 000,000,000 | —D | C] – C:\Program Files\Coupons.com
[2011/05/22 09:04:47 | 000,398,760 | R— | C] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2011/05/22 09:04:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Coupons
[2011/05/22 09:04:44 | 000,000,000 | —D | C] – C:\Program Files\Coupons
[2011/05/20 17:40:45 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\GamesForOne
[2011/05/20 17:40:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\GamesForOne
[2011/05/20 17:40:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Solitaire Plus!
[2011/05/20 17:40:40 | 000,000,000 | —D | C] – C:\Program Files\Solitaire Plus
[2011/05/20 17:08:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Mega Mahjongg
[2011/05/20 17:08:02 | 000,000,000 | —D | C] – C:\Program Files\Mega Mahjongg
[2011/05/20 17:04:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Encore
[2011/05/20 17:02:48 | 000,000,000 | —D | C] – C:\Program Files\Encore
[2011/05/20 16:59:25 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_10.dll
[2011/05/20 16:59:24 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_36.dll
[2011/05/20 16:59:24 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_36.dll
[2011/05/20 16:59:23 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_36.dll
[2011/05/20 16:59:23 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_9.dll
[2011/05/20 16:59:22 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_35.dll
[2011/05/20 16:59:22 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_35.dll
[2011/05/20 16:59:22 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_35.dll
[2011/05/20 16:59:21 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_8.dll
[2011/05/20 16:59:21 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_2.dll
[2011/05/20 16:59:20 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_34.dll
[2011/05/20 16:59:20 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_34.dll
[2011/05/20 16:59:20 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_34.dll
[2011/05/20 16:59:19 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_3.dll
[2011/05/20 16:59:15 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_7.dll
[2011/05/20 16:59:11 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_33.dll
[2011/05/20 16:59:11 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_33.dll
[2011/05/20 16:59:03 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_33.dll
[2011/05/20 16:59:02 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_6.dll
[2011/05/20 16:59:02 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_5.dll
[2011/05/20 16:59:01 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2011/05/20 16:59:01 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_4.dll
[2011/05/20 16:59:01 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_1.dll
[2011/05/20 16:59:00 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_31.dll
[2011/05/20 16:59:00 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_3.dll
[2011/05/20 16:59:00 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_2.dll
[2011/05/20 16:58:59 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_2.dll
[2011/05/20 16:58:59 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_1.dll
[2011/05/20 16:58:59 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_1.dll
[2011/05/20 16:58:49 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_30.dll
[2011/05/20 16:58:49 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_0.dll
[2011/05/20 16:58:49 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_0.dll
[2011/05/20 16:58:48 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_29.dll
[2011/05/20 16:58:48 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2011/05/20 16:58:47 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_27.dll
[2011/05/20 16:58:47 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_26.dll
[2011/05/20 16:58:47 | 000,061,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput9_1_0.dll
[2011/05/20 16:58:46 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_25.dll
[2011/05/20 16:58:44 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_24.dll
[2011/05/20 16:57:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Best Buy Games
[2011/05/20 16:57:01 | 000,000,000 | —D | C] – C:\Program Files\Best Buy Games
[2011/05/20 15:22:10 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Motive
[2011/05/20 13:26:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\My Documents\Webshots Data
[2011/05/20 13:15:32 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2011/05/20 13:15:06 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2011/05/20 13:14:36 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/05/20 13:13:55 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\IECompatCache
[2011/05/20 13:13:07 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Macromedia
[2011/05/20 13:13:05 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Adobe
[2011/05/20 13:13:01 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\PrivacIE
[2011/05/20 13:12:58 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Google
[2011/05/20 13:12:58 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Google
[2011/05/20 13:11:08 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\KodakGallery
[2011/05/20 13:10:30 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2011/05/20 13:10:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Citrix
[2011/05/20 13:08:23 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Citrix
[2011/05/20 13:07:57 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Sunbelt
[2011/05/20 13:07:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Identities
[2011/05/20 13:07:45 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\My Documents\My Music
[2011/05/20 13:07:44 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\My Documents\My Pictures
[2011/05/20 13:07:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\IETldCache
[2011/05/20 13:07:38 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Microsoft
[2011/05/20 13:07:37 | 000,000,000 | –SD | C] – C:\Documents and Settings\Barbie\Application Data\Microsoft
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Start Menu
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\SendTo
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\My Documents
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Favorites
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Application Data
[2011/05/20 13:07:36 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Startup
[2011/05/20 13:07:36 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Accessories
[2011/05/20 13:07:36 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\Cookies
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Templates
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\PrintHood
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\NetHood
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Desktop
[2011/05/20 13:01:16 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Citrix
[2011/05/11 16:55:16 | 000,027,984 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\sbbd.exe
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/30 16:37:25 | 000,444,394 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/05/30 16:37:25 | 000,072,270 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/05/30 16:33:40 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/30 16:33:29 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/05/30 16:33:12 | 000,050,257 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/05/30 16:33:07 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/30 14:28:11 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{A2C07E96-00DE-4350-BB1D-BA91A01F7E29}.job
[2011/05/28 18:54:27 | 000,000,742 | —- | M] () – C:\Documents and Settings\Barbie\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to firefox.lnk
[2011/05/28 16:07:43 | 000,000,136 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~19914532r
[2011/05/28 16:07:43 | 000,000,104 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~19914532
[2011/05/28 16:05:51 | 000,000,344 | —- | M] () – C:\Documents and Settings\All Users\Application Data\19914532
[2011/05/28 13:50:55 | 000,020,767 | —- | M] () – C:\logfile
[2011/05/24 10:53:11 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/23 13:13:32 | 000,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2011/05/22 09:04:48 | 000,398,760 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2011/05/20 17:40:45 | 000,000,685 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Solitaire Plus!.lnk
[2011/05/20 17:08:37 | 000,001,584 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Mega Mahjongg.lnk
[2011/05/20 17:07:20 | 000,000,083 | —- | M] () – C:\WINDOWS\encore_launcher.ini
[2011/05/20 17:04:43 | 000,002,053 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Hoyle Puzzle and Board Games Classic.lnk
[2011/05/20 17:00:01 | 000,001,128 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Game Center.lnk
[2011/05/20 15:01:16 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2011/05/20 14:18:13 | 000,248,696 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/20 14:01:22 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/05/20 13:25:40 | 000,003,584 | -H– | M] () – C:\Documents and Settings\Barbie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/20 13:10:12 | 000,001,184 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\GoToAssist Customer.lnk
[2011/05/11 16:26:04 | 000,074,968 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbapifs.sys
[2011/05/11 16:26:04 | 000,021,592 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbaphd.sys
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/28 18:54:27 | 000,000,742 | —- | C] () – C:\Documents and Settings\Barbie\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to firefox.lnk
[2011/05/28 16:07:43 | 000,000,136 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~19914532r
[2011/05/28 16:07:42 | 000,000,104 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~19914532
[2011/05/28 16:05:51 | 000,000,344 | —- | C] () – C:\Documents and Settings\All Users\Application Data\19914532
[2011/05/23 13:13:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/05/20 17:40:45 | 000,000,685 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Solitaire Plus!.lnk
[2011/05/20 17:08:37 | 000,001,584 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Mega Mahjongg.lnk
[2011/05/20 17:07:20 | 000,000,083 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2011/05/20 17:04:43 | 000,002,053 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Hoyle Puzzle and Board Games Classic.lnk
[2011/05/20 17:00:01 | 000,001,128 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Game Center.lnk
[2011/05/20 13:25:40 | 000,003,584 | -H– | C] () – C:\Documents and Settings\Barbie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/20 13:13:53 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{A2C07E96-00DE-4350-BB1D-BA91A01F7E29}.job
[2011/05/20 13:10:11 | 000,001,184 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\GoToAssist Customer.lnk
[2011/05/20 13:08:19 | 000,000,803 | —- | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Internet Explorer.lnk
[2011/05/20 13:07:51 | 000,000,738 | -H– | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Outlook Express.lnk
[2011/05/20 13:07:37 | 000,001,599 | —- | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Remote Assistance.lnk
[2011/05/20 13:07:37 | 000,000,792 | —- | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Windows Media Player.lnk
[2010/01/06 17:49:29 | 000,000,135 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\fusioncache.dat
[2007/08/31 13:14:07 | 000,000,086 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2006/07/21 09:41:59 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/03/27 19:22:09 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2006/03/27 19:10:01 | 000,032,200 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2006/03/27 19:10:01 | 000,020,910 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2006/03/27 19:10:01 | 000,020,869 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2006/03/27 19:10:01 | 000,000,022 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/03/27 19:06:27 | 000,000,058 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2006/03/27 19:06:12 | 000,000,044 | —- | C] () – C:\WINDOWS\EPSPR320.ini
[2006/03/27 18:39:00 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2006/03/27 17:22:24 | 000,012,288 | R— | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/03/27 17:16:44 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/03/27 17:12:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/03/27 17:08:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/03/27 09:02:51 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/03/27 09:01:54 | 000,248,696 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/03/09 16:29:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/03/09 16:29:00 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2006/03/09 16:29:00 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/03/09 16:29:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2006/03/09 16:29:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/03/09 16:29:00 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/03/09 16:29:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/03/09 16:29:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2006/03/09 16:29:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2006/03/09 16:29:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/03/09 16:29:00 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2004/08/02 15:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 00:57:58 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/10/29 14:51:02 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\NavLogon.dll
[2001/08/23 09:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 09:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 09:00:00 | 000,444,394 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 09:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 09:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 09:00:00 | 000,072,270 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 09:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 09:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 09:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 09:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2010/07/29 17:55:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/05/20 17:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GamesForOne
[2010/07/29 11:33:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/05/20 17:40:45 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Barbie\Application Data\GamesForOne
[2011/05/30 14:28:11 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{A2C07E96-00DE-4350-BB1D-BA91A01F7E29}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/03/27 17:10:39 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/03/27 17:52:20 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2006/03/27 17:10:39 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/04/03 14:29:41 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2009/10/07 12:19:22 | 000,000,238 | —- | M] () – C:\INSTALL.LOG
[2006/03/27 17:10:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/05/28 13:50:55 | 000,020,767 | —- | M] () – C:\logfile
[2010/07/28 12:57:49 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\mbam-setup-1.46.exe
[2006/03/27 17:10:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/03/27 17:43:14 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/10/08 13:38:42 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/30 16:33:05 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2010/07/28 12:56:02 | 009,157,960 | —- | M] (SUPERAntiSpyware.com) – C:\SUPERAntiSpyware.exe
[2010/07/28 14:05:57 | 000,009,647 | -H– | M] () – C:\_NavCClt.Log
[2006/05/23 12:02:03 | 000,000,256 | -HS- | M] () – C:\__IOM_DEVLIB__.__ATTRIBUTES__

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/03/27 17:10:17 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/06/18 18:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/03/27 09:01:09 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/03/27 09:01:09 | 000,626,688 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/03/27 09:01:09 | 000,417,792 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >
[2009/11/23 15:51:40 | 000,103,720 | —- | M] () – C:\WINDOWS\java\GoToAssistDownloadHelper.exe

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-20 21:01:49

========== Alternate Data Streams ==========

@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >


================================================================================
==================
OTL Extras logfile created on: 5/30/2011 4:55:00 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Barbie\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.67 Mb Total Physical Memory | 590.51 Mb Available Physical Memory | 57.74% Memory free
2.40 Gb Paging File | 1.93 Gb Available in Paging File | 80.20% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 25.16 Gb Free Space | 67.52% Space Free | Partition Type: NTFS

Computer Name: BARBIE-PC | User Name: Barbie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"ANTIVIRUSDISABLENOTIFY" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{109D28C7-FB38-483A-9C91-001CB59E2699}" = EPSON CardMonitor
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{141F2872-D2F9-4A89-95D3-E222D1CBCC56}" = Vz In Home Agent
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D97E163-946B-468B-97F3-CF0C3CC3DC1B}" = Norton Ghost Boot Disk Creator for REV
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{411C5D92-2AE4-436F-A027-1E441EDC05CE}" = VIPRE Antivirus Premium
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{56AB063D-1450-4BDE-9F0D-E9C693429C51}" = netbrdg
"{5983C895-DDA4-45D9-A8D1-877D5DE7693E}" = EPSON PhotoStarter3.0
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{65D85050-5610-4A91-A3B1-D5C744291AD4}" = PCDADDIN
"{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis True Image Home
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{8EEA1427-5C0D-469F-9FC6-A622A99D98EB}" = Trixie
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90FF23FE-0E1B-40DF-A22E-B4C0372E5936}" = Iomega Product Registration
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B351E5AF-E6E2-46E4-8155-DAB130731F70}" = Iomega REV System Software
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D1FC57-3EB9-4B21-BCA3-F1C927508200}" = VIPRE Antivirus Premium
"{C9618743-1A5C-461E-91C4-E013A3D70F3C}" = Adobe® Photoshop® Album Starter Edition 3.0.1
"{C99DCDA4-7407-4F72-A77E-C81C551D0C4E}" = PCDHELP
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"Bookworm Deluxe_is1" = Bookworm Deluxe
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"Coupons.com Toolbar" = Coupons.com Toolbar
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Status Monitor 2" = EPSON Status Monitor 2
"Google Updater" = Google Updater
"GoToAssist Express Customer" = GoToAssist Customer 1.6.0.290
"Hoyle Puzzle and Board Games Classic" = Hoyle Puzzle and Board Games Classic
"ie8" = Windows Internet Explorer 8
"LiveUpdate1.6" = LiveUpdate 1.6 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mega Mahjongg" = Hoyle Mahjongg (remove only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Network Adapters and Drivers
"Silent Package Run-Time Sample" = ESPR320 Reference Guide
"Solitaire Plus!_is1" = Solitaire Plus! version 3.0
"Verizon Help and Support" = Verizon Help and Support Tool
"Webshots Desktop" = Webshots Desktop
"WGA" = Windows Genuine Advantage Validation Tool
"Windows XP Service Pack" = Windows XP Service Pack 3
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/21/2010 6:17:55 PM | Computer Name = FRENCH-MAIN | Source = ESENT | ID = 439
Description = Catalog Database (1268) Unable to write a shadowed header for file
C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb. Error
-1032.

Error - 7/21/2010 6:17:55 PM | Computer Name = FRENCH-MAIN | Source = ESENT | ID = 473
Description = Catalog Database (1268) Database C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
was partially detached. Error -1032 encountered updating database headers.

Error - 7/22/2010 6:49:57 PM | Computer Name = FRENCH-MAIN | Source = Acronis True Image Home | ID = 33
Description =

Error - 7/23/2010 1:34:03 PM | Computer Name = FRENCH-MAIN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/23/2010 7:46:24 PM | Computer Name = FRENCH-MAIN | Source = Acronis True Image Home | ID = 33
Description =

Error - 7/26/2010 3:20:02 PM | Computer Name = FRENCH-MAIN | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/28/2010 4:08:04 PM | Computer Name = FRENCH-MAIN | Source = Norton AntiVirus | ID = 16711685
Description =

Error - 7/28/2010 5:07:05 PM | Computer Name = FRENCH-MAIN | Source = pctsSvc.exe | ID = 0
Description =

Error - 8/10/2010 4:32:28 PM | Computer Name = FRENCH-MAIN | Source = MsiInstaller | ID = 11904
Description = Product: PCDADDIN – Error 1904.Module C:\Program Files\Kodak\Kodak
EasyShare software\AddIn\VistaPCD.cyx failed to register. HRESULT . Contact your
support personnel.

Error - 5/30/2011 11:20:38 AM | Computer Name = BARBIE-PC | Source = Application Error | ID = 1000
Description = Faulting application services.exe, version 5.1.2600.5755, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00001de6.

[ System Events ]
Error - 5/30/2011 6:59:59 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon

Error - 5/30/2011 7:02:22 PM | Computer Name = BARBIE-PC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{D38BC63C-B887-4224-A6F3-A6F4DF8EFB6F}. The
backup browser is stopping.

Error - 5/30/2011 7:14:51 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect.

Error - 5/30/2011 7:14:51 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7000
Description = The HTTP SSL service failed to start due to the following error: %%1053

Error - 5/30/2011 7:25:50 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7034
Description = The McciCMService service terminated unexpectedly. It has done this
1 time(s).

Error - 5/30/2011 7:26:45 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 5/30/2011 7:26:51 PM | Computer Name = BARBIE-PC | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 5/30/2011 7:27:24 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7034
Description = The Acronis Scheduler2 Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 5/30/2011 7:33:36 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon

Error - 5/30/2011 7:35:52 PM | Computer Name = BARBIE-PC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{D38BC63C-B887-4224-A6F3-A6F4DF8EFB6F}. The
backup browser is stopping.


< End of report >
Hi Jack P, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Download RogueKiller to your desktop

  • Quit all running programs
  • When prompted, type 6 and validate
Your icons back?


Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O4 - HKLM..\Run: [yrsgtjkbutlqmc] File not found
[2011/05/28 16:07:43 | 000,000,136 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~19914532r
[2011/05/28 16:07:43 | 000,000,104 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~19914532
[2011/05/28 16:05:51 | 000,000,344 | —- | M] () – C:\Documents and Settings\All Users\Application Data\19914532

:Commands
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Next

Please open OTL if it is not still open.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following



    %Temp%\smtmp\*.* /s

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. Please post this log.

Please post back with
  • OTL fix log
  • OTL.txt
Thanks
Thank you so much for your help! The RogueKiller restored the desktop icons and the Start Menu icons. The only ones it didn't fix were many submenu icons. For instance, When I click Start -> All Programs -> Games, there are no games listed. The first OTL scan produced this report: ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\yrsgtjkbutlqmc deleted successfully. C:\Documents and Settings\All Users\Application Data\~19914532r moved successfully. C:\Documents and Settings\All Users\Application Data\~19914532 moved successfully. C:\Documents and Settings\All Users\Application Data\19914532 moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) OTL by OldTimer - Version 3.2.23.0 log created on 05312011_002741 =========================================== =========================================== The second scan produced this report: Error: Unable to interpret <%Temp%\smtmp\*.* /s > in the current context! OTL by OldTimer - Version 3.2.23.0 log created on 05312011_003443 ============================================= ============================================= But, it did not produce the other 2 logs that you listed.
Hi Jack P,

Th first log you posted was the fix log. When you ran OTL the second time did you click the Run Scan button?
Sorry, I misspoke. What I posted WAS the fix.log What didn't show up was the otl.txt log I'll post the fix.log again here. Error: Unable to interpret <%Temp%\smtmp\*.* /s > in the current context! OTL by OldTimer - Version 3.2.23.0 log created on 05312011_003443
Hi Jack P,

What I posted WAS the fix.log

Correct.

Error: Unable to interpret <%Temp%\smtmp\*.* /s > in the current context!

That looks like the error message you would recieve if you used that script in a fix.

When you pasted %Temp%\smtmp\*.* /s in the Custom Scans/Fixes box did you click the Run Scan button?
I'm not sure what you mean about "if you used that script in a fix." I opened OTL Clicked on "None" to make it "Standard" Pasted %Temp%\smtmp\*.* /s into the "Custom Scan/Fixes" Window Clicked on the "Run Fix" button at the top of the screen. It quickly yielded a window that said "Fix Complete! Click Ok to open the fix log." In the file that opens after clicking OK it says: Error: Unable to interpret <%Temp%\smtmp\*.* /s > in the current context! OTL by OldTimer - Version 3.2.23.0 log created on 05312011_003443 Is that right? I think I followed the steps correctly. Or do I need to do another to follow another procedure?
Hi Jack P,

I'm not sure what you mean about "if you used that script in a fix."

I mean that you will recieve that error if you paste %Temp%\smtmp\*.* /s into the "Custom Scan/Fixes" Window and click "Run Fix" as it is not a proper fix script.


Clicked on the "Run Fix" button at the top of the screen.

That's the problem, you need to click the Run Scan button.
I finally figured out how to READ!!!!

I am soooo sorry.

OK, here it is.

OTL logfile created on: 5/31/2011 10:20:29 PM - Run 2
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Barbie\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.67 Mb Total Physical Memory | 499.55 Mb Available Physical Memory | 48.85% Memory free
2.40 Gb Paging File | 1.98 Gb Available in Paging File | 82.21% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 24.98 Gb Free Space | 67.05% Space Free | Partition Type: NTFS

Computer Name: BARBIE-PC | User Name: Barbie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========


< %Temp%\smtmp\*.* /s >
[2008/10/08 13:51:59 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\Barbie\Local Settings\Temp\smtmp\1\desktop.ini
[2006/03/27 18:32:48 | 000,001,992 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\New Office Document.lnk
[2006/03/27 18:32:49 | 000,002,002 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Open Office Document.lnk
[2008/10/08 13:51:59 | 000,001,563 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Set Program Access and Defaults.lnk
[2006/03/27 17:10:43 | 000,000,398 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Windows Catalog.lnk
[2006/03/27 17:28:20 | 000,001,507 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Windows Update.lnk
[2006/03/29 16:04:22 | 000,002,073 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Adobe Photoshop Album Starter Edition 3.0.lnk
[2009/01/05 15:38:16 | 000,001,804 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Adobe Reader 8.lnk
[2006/03/27 09:02:28 | 000,000,062 | -HS- | M] () – C:\Documents and Settings\Barbie\Local Settings\Temp\smtmp\1\Programs\desktop.ini
[2011/05/23 13:13:26 | 000,000,730 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Mozilla Firefox.lnk
[2006/03/27 17:07:48 | 000,001,846 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\MSN Explorer.lnk
[2006/03/27 18:48:37 | 000,000,636 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Webshots Desktop.lnk
[2006/03/27 17:08:09 | 000,000,829 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Windows Messenger.lnk
[2006/03/27 17:08:09 | 000,001,498 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Calculator.lnk
[2010/08/10 13:31:43 | 000,000,320 | -HS- | M] () – C:\Documents and Settings\Barbie\Local Settings\Temp\smtmp\1\Programs\Accessories\desktop.ini
[2006/03/27 17:08:09 | 000,001,515 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Paint.lnk
[2008/10/08 13:51:45 | 000,001,585 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Remote Desktop Connection.lnk
[2010/08/10 13:31:43 | 000,000,710 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Scanner and Camera Wizard.lnk
[2006/03/27 17:09:33 | 000,000,790 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Windows Movie Maker.lnk
[2006/03/27 17:08:09 | 000,000,879 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\WordPad.lnk
[2006/03/27 17:08:09 | 000,001,520 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Accessibility\Accessibility Wizard.lnk
[2006/03/27 17:08:09 | 000,000,090 | -HS- | M] () – C:\Documents and Settings\Barbie\Local Settings\Temp\smtmp\1\Programs\Accessories\Accessibility\desktop.ini
[2008/10/08 13:55:07 | 000,000,516 | -HS- | M] () – C:\Documents and Settings\Barbie\Local Settings\Temp\smtmp\1\Programs\Accessories\Communications\desktop.ini
[2006/03/27 17:08:09 | 000,000,786 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications\HyperTerminal.lnk
[2006/03/27 17:06:46 | 000,001,757 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications\Network Connections.lnk
[2006/03/27 17:09:27 | 000,001,640 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications\Network Setup Wizard.lnk
[2006/03/27 17:06:46 | 000,001,646 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications\New Connection Wizard.lnk
[2008/10/08 13:55:07 | 000,001,656 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications\Wireless Network Setup Wizard.lnk
[2006/03/27 17:08:09 | 000,000,146 | -HS- | M] () – C:\Documents and Settings\Barbie\Local Settings\Temp\smtmp\1\Programs\Accessories\Entertainment\desktop.ini
[2006/03/27 17:08:09 | 000,001,528 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Entertainment\Sound Recorder.lnk
[2006/03/27 17:08:09 | 000,001,528 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Entertainment\Volume Control.lnk
[2006/03/27 17:10:43 | 000,001,532 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Backup.lnk
[2006/03/27 17:08:09 | 000,001,521 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Character Map.lnk
[2006/03/27 17:54:41 | 000,000,757 | -HS- | M] () – C:\Documents and Settings\Barbie\Local Settings\Temp\smtmp\1\Programs\Accessories\System Tools\desktop.ini
[2006/03/27 17:09:31 | 000,001,532 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Disk Cleanup.lnk
[2006/03/27 17:09:30 | 000,001,572 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Disk Defragmenter.lnk
[2006/03/27 17:10:43 | 000,001,591 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Files and Settings Transfer Wizard.lnk
[2006/03/27 17:09:31 | 000,001,753 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Scheduled Tasks.lnk
[2006/03/27 17:09:30 | 000,001,070 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\System Information.lnk
[2006/03/27 17:09:31 | 000,001,616 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\System Restore.lnk
[2010/07/29 16:52:04 | 000,001,956 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Acronis\Acronis True Image Home\Acronis One-Click Backup.lnk
[2010/07/29 16:52:05 | 000,000,048 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Acronis\Acronis True Image Home\Acronis Web Site.url
[2010/07/29 16:52:04 | 000,000,984 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Acronis\Acronis True Image Home\Acronis True Image Home.lnk
[2010/07/29 16:52:04 | 000,001,157 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Acronis\Acronis True Image Home\Bootable Rescue Media Builder.lnk
[2006/03/27 17:07:54 | 000,001,582 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Component Services.lnk
[2006/03/27 17:10:43 | 000,001,602 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Computer Management.lnk
[2006/03/27 17:10:43 | 000,001,596 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Data Sources (ODBC).lnk
[2006/03/27 17:10:43 | 000,000,545 | -HS- | M] () – C:\Documents and Settings\Barbie\Local Settings\Temp\smtmp\1\Programs\Administrative Tools\desktop.ini
[2010/07/28 14:23:08 | 000,001,592 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Event Viewer.lnk
[2006/05/23 11:52:19 | 000,001,874 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Iomega REV Administrative Tools.lnk
[2006/03/27 17:10:43 | 000,001,590 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Local Security Policy.lnk
[2006/03/27 17:32:14 | 000,001,107 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Microsoft .NET Framework 1.1 Configuration.lnk
[2006/03/27 17:32:14 | 000,001,158 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Microsoft .NET Framework 1.1 Wizards.lnk
[2006/03/27 17:10:43 | 000,001,591 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Performance.lnk
[2006/03/27 17:10:43 | 000,001,602 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Services.lnk
[2006/03/27 18:54:37 | 000,000,855 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\Nero Cover Designer.lnk
[2006/03/27 18:54:37 | 000,000,756 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\Nero Express.lnk
[2006/03/27 18:54:37 | 000,000,835 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\Nero Toolkit\Nero CD Speed.lnk
[2006/03/27 18:54:37 | 000,000,856 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\Nero Toolkit\Nero DriveSpeed.lnk
[2006/03/27 18:54:37 | 000,000,892 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\Nero Toolkit\Nero InfoTool.lnk
[2006/03/27 18:54:37 | 000,000,960 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\User's Guides\Nero Cover Designer [English manual].lnk
[2006/03/27 18:54:37 | 000,000,849 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\User's Guides\Nero Express [English manual].lnk
[2011/05/20 16:57:09 | 000,001,805 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Best Buy Games\Bookworm Deluxe\Bookworm Deluxe Readme.lnk
[2011/05/20 16:57:09 | 000,001,810 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Best Buy Games\Bookworm Deluxe\Bookworm Deluxe.lnk
[2011/05/20 17:00:01 | 000,001,128 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Best Buy Games\Bookworm Deluxe\Game Center.lnk
[2011/05/20 16:57:09 | 000,001,710 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Best Buy Games\Bookworm Deluxe\Uninstall Bookworm Deluxe.lnk
[2011/05/22 09:04:46 | 000,001,572 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Coupons\Coupons.com - Print Coupons.lnk
[2011/05/22 09:04:46 | 000,001,724 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Coupons\Uninstall Coupon Printer for Windows.lnk
[2006/03/27 18:56:06 | 000,001,696 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\CyberLink PowerDVD\PowerDVD Help.lnk
[2006/03/27 18:56:06 | 000,001,696 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\CyberLink PowerDVD\PowerDVD.lnk
[2006/03/27 18:56:06 | 000,001,452 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\CyberLink PowerDVD\Readme.lnk
[2006/03/27 18:56:06 | 000,001,671 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\CyberLink PowerDVD\System Diagnostic.lnk
[2006/03/27 18:56:06 | 000,001,717 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\CyberLink PowerDVD\Uninstall PowerDVD.lnk
[2011/05/20 17:04:41 | 000,001,958 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Encore Web Site.lnk
[2011/05/20 17:04:43 | 000,002,071 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Hoyle Puzzle and Board Games Classic.lnk
[2011/05/20 17:04:43 | 000,001,064 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Hoyle Puzzle and Board Games Help.lnk
[2011/05/20 17:04:43 | 000,001,958 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Register Online.lnk
[2011/05/20 17:04:43 | 000,002,043 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Try and Buy other Hoyle Products.lnk
[2011/05/20 17:04:41 | 000,000,989 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Uninstall Hoyle Puzzle and Board Games Classic.lnk
[2006/03/27 19:08:30 | 000,000,665 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON Print CD\EPSON Print CD Help.lnk
[2006/03/27 19:08:30 | 000,001,541 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON Print CD\EPSON Print CD.lnk
[2006/03/27 19:08:30 | 000,000,485 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON Print CD\Read Me.lnk
[2006/03/27 19:08:51 | 000,001,715 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON Print CD\Uninstall EPSON Print CD.lnk
[2006/03/27 19:08:02 | 000,001,731 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON\EPSON Printer Software Uninstall.lnk
[2006/03/27 19:12:15 | 000,000,490 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON\EPSON Status Monitor 2 Readme.lnk
[2006/03/27 19:12:15 | 000,000,495 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON\EPSON Status Monitor 2.lnk
[2006/03/27 19:09:15 | 000,000,805 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON\ESPR320 Reference Guide\Reference Guide.lnk
[2006/03/27 19:09:15 | 000,000,849 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON\ESPR320 Reference Guide\Uninstall Reference Guide.lnk
[2006/03/27 19:09:24 | 000,001,866 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Film Factory\EPSON PhotoStarter3.0.lnk
[2006/03/27 17:59:17 | 000,000,798 | -HS- | M] () – C:\Documents and Settings\Barbie\Local Settings\Temp\smtmp\1\Programs\Games\desktop.ini
[2006/03/28 14:16:33 | 000,001,522 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Freecell.lnk
[2006/03/27 17:08:09 | 000,001,520 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Hearts.lnk
[2006/03/27 17:59:17 | 000,000,913 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Internet Backgammon.lnk
[2006/03/27 17:59:16 | 000,000,913 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Internet Checkers.lnk
[2006/03/27 17:59:16 | 000,000,913 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Internet Hearts.lnk
[2006/03/27 17:59:17 | 000,000,913 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Internet Reversi.lnk
[2006/03/27 17:59:16 | 000,000,913 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Internet Spades.lnk
[2006/03/27 17:08:09 | 000,001,515 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Minesweeper.lnk
[2006/03/27 17:08:09 | 000,000,885 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Pinball.lnk
[2006/03/28 14:34:09 | 000,001,491 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Solitaire.lnk
[2011/05/24 10:53:23 | 000,001,502 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Spider Solitaire.lnk
[2009/06/04 12:55:46 | 000,000,902 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Google Updater\Google Updater.lnk
[2009/06/04 12:55:46 | 000,000,926 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Google Updater\Uninstall Google Updater.lnk
[2006/03/27 18:58:21 | 000,000,893 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Iomega\Norton Ghost for REV.lnk
[2006/05/23 11:52:18 | 000,001,920 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Iomega\REV Information Center.lnk
[2010/08/10 13:29:37 | 000,001,827 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Kodak\Kodak EasyShare\Kodak EasyShare software.lnk
[2010/08/10 13:30:47 | 000,000,788 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Kodak\Kodak EasyShare\ReadMe.lnk
[2010/08/10 13:32:19 | 000,001,914 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Kodak\Kodak software updater\Kodak software updater setup.lnk
[2010/07/28 13:03:08 | 000,000,708 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware Help.lnk
[2010/07/28 13:03:08 | 000,000,708 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware.lnk
[2010/07/28 13:03:08 | 000,000,732 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Malwarebytes' Anti-Malware\Uninstall Malwarebytes' Anti-Malware.lnk
[2006/03/27 18:32:48 | 000,002,004 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Access 2003.lnk
[2006/03/27 18:32:48 | 000,002,044 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Excel 2003.lnk
[2006/03/27 18:32:49 | 000,002,062 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office InfoPath 2003.lnk
[2006/03/27 18:32:49 | 000,002,060 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Outlook 2003.lnk
[2006/03/27 18:32:49 | 000,002,016 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office PowerPoint 2003.lnk
[2006/03/27 18:32:49 | 000,001,992 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Publisher 2003.lnk
[2006/05/25 11:31:38 | 000,002,509 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Word 2003.lnk
[2006/03/27 18:32:49 | 000,002,022 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Digital Certificate for VBA Projects.lnk
[2006/03/27 18:32:48 | 000,001,988 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Clip Organizer.lnk
[2006/03/27 18:32:48 | 000,001,902 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Language Settings.lnk
[2006/03/27 18:32:49 | 000,001,908 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Save My Settings Wizard.lnk
[2006/03/27 18:32:49 | 000,002,020 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Access Snapshot Viewer.lnk
[2006/03/27 18:32:48 | 000,001,876 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Application Recovery.lnk
[2006/03/27 18:32:48 | 000,002,140 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Document Imaging.lnk
[2006/03/27 18:32:48 | 000,002,142 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Document Scanning.lnk
[2006/03/27 18:32:48 | 000,001,964 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Picture Manager.lnk
[2010/01/08 14:46:10 | 000,001,802 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\QuickTime\About QuickTime.lnk
[2010/01/08 14:46:10 | 000,001,812 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\QuickTime\PictureViewer.lnk
[2010/01/08 14:46:10 | 000,001,802 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\QuickTime\QuickTime Player.lnk
[2010/01/08 14:46:11 | 000,001,639 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\QuickTime\Uninstall QuickTime.lnk
[2011/05/20 17:40:45 | 000,001,535 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Solitaire Plus!\Solitaire Plus HTML Help.lnk
[2011/05/20 17:40:45 | 000,000,697 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Solitaire Plus!\Solitaire Plus!.lnk
[2011/05/20 17:40:45 | 000,001,552 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Solitaire Plus!\Uninstall Solitaire Plus!.lnk
[2006/03/27 17:21:17 | 000,001,473 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SoundMAX\AudioWizard.lnk
[2006/03/27 17:21:08 | 000,001,459 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SoundMAX\DLS Loader.lnk
[2006/03/27 17:21:10 | 000,001,451 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SoundMAX\SoundMAX Control Panel.lnk
[2006/03/27 17:21:16 | 000,000,619 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SoundMAX\SoundMAX Help.lnk
[2006/03/27 17:10:43 | 000,000,084 | -HS- | M] () – C:\Documents and Settings\Barbie\Local Settings\Temp\smtmp\1\Programs\Startup\desktop.ini
[2006/03/27 19:12:15 | 000,000,478 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Startup\EPSON Background Monitor.lnk
[2010/08/10 13:29:37 | 000,001,837 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Startup\Kodak EasyShare software.lnk
[2011/05/28 16:16:16 | 000,001,756 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Sunbelt Software\VIPRE Antivirus Premium\VIPRE Antivirus Premium.lnk
[2010/07/29 10:55:09 | 000,001,756 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Sunbelt Software\VIPRE Antivirus Premium\VIPRE.lnk
[2010/07/28 12:57:08 | 000,001,634 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SUPERAntiSpyware\BootSafe.lnk
[2010/07/28 12:57:08 | 000,001,618 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SUPERAntiSpyware\SUPERAntiSpyware Alternate Start.lnk
[2010/07/28 12:57:08 | 000,001,690 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SUPERAntiSpyware\SUPERAntiSpyware Free Edition.lnk
[2010/07/28 12:57:08 | 000,000,792 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SUPERAntiSpyware\SUPERAntiSpyware Help.lnk
[2010/07/28 12:57:08 | 000,001,712 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SUPERAntiSpyware\SUPERAntiSpyware Registration-Activation.lnk
[2009/10/13 13:35:29 | 000,001,034 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Verizon\Verizon Help and Support.lnk
[2011/05/20 13:08:11 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Barbie\Local Settings\Temp\smtmp\2\desktop.ini
[2011/05/20 13:08:19 | 000,000,815 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\2\Launch Internet Explorer Browser.lnk
[2011/05/20 15:06:46 | 000,000,792 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\2\Launch Microsoft Office Outlook.lnk
[2011/05/23 13:13:26 | 000,000,742 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\2\Mozilla Firefox.lnk
[2011/05/20 13:08:11 | 000,000,079 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\2\Show Desktop.scf
[2010/07/29 16:52:04 | 000,000,864 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Acronis True Image Home 2010.lnk
[2006/03/29 16:04:22 | 000,002,067 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Adobe Photoshop Album Starter Edition 3.0.lnk
[2011/05/20 16:57:09 | 000,001,792 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Bookworm Deluxe.lnk
[2006/03/27 19:08:30 | 000,001,529 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\EPSON Print CD.lnk
[2006/03/27 19:09:15 | 000,000,803 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\ESPR320 Reference Guide.lnk
[2010/08/10 13:29:37 | 000,001,817 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Kodak EasyShare.lnk
[2010/07/28 13:03:09 | 000,000,696 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Malwarebytes' Anti-Malware.lnk
[2011/05/23 13:13:26 | 000,000,724 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Mozilla Firefox.lnk
[2006/03/27 18:56:06 | 000,001,684 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\PowerDVD.lnk
[2010/01/08 14:46:11 | 000,001,604 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\QuickTime Player.lnk
[2010/07/28 12:57:08 | 000,001,678 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\SUPERAntiSpyware Free Edition.lnk
[2011/05/28 16:16:15 | 000,001,740 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\VIPRE Antivirus Premium.lnk
[2010/07/29 10:55:09 | 000,001,740 | -H– | M] () – C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\VIPRE.lnk

< End of report >
Hi Jack P,

No problem, sometimes I put the wrong glasses on.

Let me if all icons, programs etc return after this fix.


Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:files
xcopy %Temp%\smtmp\1 "%AllUsersProfile%\Start Menu" /H /I /S /Y /C
xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C
xcopy %Temp%\smtmp\4 "%AllUsersProfile%\Desktop" /H /I /S /Y /C


:Commands
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Thanks
OK. I think I followed the instructions correctly this time. Here's the results:

========== SERVICES/DRIVERS ==========
========== FILES ==========
< xcopy %Temp%\smtmp\1 "%AllUsersProfile%\Start Menu" /H /I /S /Y /C >
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\desktop.ini
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\New Office Document.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Open Office Document.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Set Program Access and Defaults.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Windows Catalog.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Windows Update.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Adobe Photoshop Album Starter Edition 3.0.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Adobe Reader 8.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\desktop.ini
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Mozilla Firefox.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\MSN Explorer.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Webshots Desktop.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Windows Messenger.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Calculator.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\desktop.ini
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Paint.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Remote Desktop Connection.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Scanner and Camera Wizard.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Windows Movie Maker.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\WordPad.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Accessibility\Accessibility Wizard.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Accessibility\desktop.ini
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications\desktop.ini
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications\HyperTerminal.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications\Network Connections.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications\Network Setup Wizard.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications\New Connection Wizard.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications\Wireless Network Setup Wizard.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Entertainment\desktop.ini
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Entertainment\Sound Recorder.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Entertainment\Volume Control.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Backup.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Character Map.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\desktop.ini
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Disk Cleanup.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Disk Defragmenter.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Files and Settings Transfer Wizard.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\Scheduled Tasks.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\System Information.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools\System Restore.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Acronis\AcronisÿTrueÿImageÿHome\Acronis One-Click Backup.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Acronis\AcronisÿTrueÿImageÿHome\Acronis Web Site.url
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Acronis\AcronisÿTrueÿImageÿHome\AcronisÿTrueÿImageÿHome.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Acronis\AcronisÿTrueÿImageÿHome\Bootable RescueÿMedia Builder.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Component Services.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Computer Management.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Data Sources (ODBC).lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\desktop.ini
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Event Viewer.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Iomega REV Administrative Tools.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Local Security Policy.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Microsoft .NET Framework 1.1 Configuration.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Microsoft .NET Framework 1.1 Wizards.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Performance.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools\Services.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\Nero Cover Designer.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\Nero Express.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\Nero Toolkit\Nero CD Speed.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\Nero Toolkit\Nero DriveSpeed.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\Nero Toolkit\Nero InfoTool.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\User's Guides\Nero Cover Designer [English manual].lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Ahead Nero\User's Guides\Nero Express [English manual].lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Best Buy Games\Bookworm Deluxe\Bookworm Deluxe Readme.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Best Buy Games\Bookworm Deluxe\Bookworm Deluxe.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Best Buy Games\Bookworm Deluxe\Game Center.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Best Buy Games\Bookworm Deluxe\Uninstall Bookworm Deluxe.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Coupons\Coupons.com - Print Coupons.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Coupons\Uninstall Coupon Printer for Windows.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\CyberLink PowerDVD\PowerDVD Help.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\CyberLink PowerDVD\PowerDVD.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\CyberLink PowerDVD\Readme.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\CyberLink PowerDVD\System Diagnostic.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\CyberLink PowerDVD\Uninstall PowerDVD.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Encore Web Site.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Hoyle Puzzle and Board Games Classic.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Hoyle Puzzle and Board Games Help.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Register Online.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Try and Buy other Hoyle Products.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Encore\Hoyle Puzzle and Board Games Classic\Uninstall Hoyle Puzzle and Board Games Classic.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON\EPSON Printer Software Uninstall.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON\EPSON Status Monitor 2 Readme.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON\EPSON Status Monitor 2.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON\ESPR320 Reference Guide\Reference Guide.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON\ESPR320 Reference Guide\Uninstall Reference Guide.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON Print CD\EPSON Print CD Help.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON Print CD\EPSON Print CD.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON Print CD\Read Me.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\EPSON Print CD\Uninstall EPSON Print CD.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Film Factory\EPSON PhotoStarter3.0.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\desktop.ini
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Freecell.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Hearts.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Internet Backgammon.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Internet Checkers.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Internet Hearts.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Internet Reversi.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Internet Spades.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Minesweeper.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Pinball.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Solitaire.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Games\Spider Solitaire.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Google Updater\Google Updater.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Google Updater\Uninstall Google Updater.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Iomega\Norton Ghost for REV.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Iomega\REV Information Center.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Kodak\Kodak EasyShare\Kodak EasyShare software.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Kodak\Kodak EasyShare\ReadMe.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Kodak\Kodak software updater\Kodak software updater setup.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware Help.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Malwarebytes' Anti-Malware\Uninstall Malwarebytes' Anti-Malware.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Access 2003.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Excel 2003.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office InfoPath 2003.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Outlook 2003.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office PowerPoint 2003.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Publisher 2003.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Word 2003.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Digital Certificate for VBA Projects.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Clip Organizer.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Language Settings.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2003 Save My Settings Wizard.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Access Snapshot Viewer.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Application Recovery.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Document Imaging.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Document Scanning.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Picture Manager.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\QuickTime\About QuickTime.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\QuickTime\PictureViewer.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\QuickTime\QuickTime Player.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\QuickTime\Uninstall QuickTime.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Solitaire Plus!\Solitaire Plus HTML Help.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Solitaire Plus!\Solitaire Plus!.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Solitaire Plus!\Uninstall Solitaire Plus!.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SoundMAX\AudioWizard.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SoundMAX\DLS Loader.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SoundMAX\SoundMAX Control Panel.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SoundMAX\SoundMAX Help.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Startup\desktop.ini
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Startup\EPSON Background Monitor.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Startup\Kodak EasyShare software.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Sunbelt Software\VIPRE Antivirus Premium\VIPRE Antivirus Premium.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Sunbelt Software\VIPRE Antivirus Premium\VIPRE.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SUPERAntiSpyware\BootSafe.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SUPERAntiSpyware\SUPERAntiSpyware Alternate Start.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SUPERAntiSpyware\SUPERAntiSpyware Free Edition.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SUPERAntiSpyware\SUPERAntiSpyware Help.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\SUPERAntiSpyware\SUPERAntiSpyware Registration-Activation.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\1\Programs\Verizon\Verizon Help and Support.lnk
149 File(s) copied
C:\Documents and Settings\Barbie\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Barbie\Desktop\cmd.txt deleted successfully.
< xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C >
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\2\desktop.ini
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\2\Launch Internet Explorer Browser.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\2\Launch Microsoft Office Outlook.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\2\Mozilla Firefox.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\2\Show Desktop.scf
5 File(s) copied
C:\Documents and Settings\Barbie\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Barbie\Desktop\cmd.txt deleted successfully.
< xcopy %Temp%\smtmp\4 "%AllUsersProfile%\Desktop" /H /I /S /Y /C >
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Acronis True Image Home 2010.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Adobe Photoshop Album Starter Edition 3.0.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Bookworm Deluxe.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\EPSON Print CD.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\ESPR320 Reference Guide.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Kodak EasyShare.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Malwarebytes' Anti-Malware.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\Mozilla Firefox.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\PowerDVD.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\QuickTime Player.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\SUPERAntiSpyware Free Edition.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\VIPRE Antivirus Premium.lnk
C:\DOCUME~1\Barbie\LOCALS~1\Temp\smtmp\4\VIPRE.lnk
13 File(s) copied
C:\Documents and Settings\Barbie\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Barbie\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point (0)

OTL by OldTimer - Version 3.2.23.0 log created on 05312011_230237
Hi Jack P,


Go to Start > Run > type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between ..g /f.. it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.


Next,

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.


Next

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it

  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Safe Mode


Please post back with
  • aswMBR log
  • MBR.dat (zipped)
  • GMER log
Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI