This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

searchqu

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

when i open a new window i have searchqu search instead of an
empty window, i would like to get rid of searchqu

.first text doc generated :
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 12:04:30.39 on Mon 06/20/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.269 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: ZoneAlarm Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\WINDOWS\system32\lxdccoms.exe
C:\PROGRA~1\Ontrack\Fix-It\mxserver.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\IObit\Game Booster\gbtray.exe
C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\Program Files\Corel\Corel GuideMenu\GuideMenu.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
C:\Program Files\IObit\IObit Malware Fighter\IMF.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\gary\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.searchqu.com/406
uInternet Settings,ProxyOverride = *.local
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program files\zonealarm\tbZone.dll
BHO: ZoneAlarm Security Engine Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - Searchqu Toolbar
BHO: UrlHelper Class: {a40dc6c5-79d0-4ca8-a185-8ff989af1115} - c:\progra~1\wi371a~1\datamngr\IEBHO.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: ShopAtHomeIEHelper Class: {e8daaa30-6caa-4b58-9603-8e54238219e2} - c:\program files\selectrebates\toolbar\ShopAtHomeToolbar.dll
TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
TB: ZoneAlarm Toolbar: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - c:\program files\zonealarm\tbZone.dll
TB: ShopAtHome Toolbar: {98279c38-de4b-4bcf-93c9-8ec26069d6f4} - c:\program files\selectrebates\toolbar\ShopAtHomeToolbar.dll
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Advanced SystemCare 4] "c:\program files\iobit\advanced systemcare 4\ASCTray.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [lxdcamon] "c:\program files\lexmark 1300 series\lxdcamon.exe"
mRun: [GuideMenu] c:\program files\corel\corel guidemenu\GuideMenu.exe -hide
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [ISW] "c:\program files\checkpoint\zaforcefield\ForceField.exe" /icon="hidden"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [DATAMNGR] c:\progra~1\wi371a~1\datamngr\DATAMN~1.EXE
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [IObit Malware Fighter] "c:\program files\iobit\iobit malware fighter\IMF.exe" /autostart
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…t;ver=10.0.1325
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
uPolicies-explorer: NoRealMode = 0 (0x0)
uPolicies-explorer: NoInstrumentation = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LMIinit - LMIinit.dll
AppInit_DLLs: c:\progra~1\wi371a~1\datamngr\datamngr.dll c:\progra~1\wi371a~1\datamngr\IEBHO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\gary\applic~1\mozilla\firefox\profiles\nc40df2x.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=102&systemid=406&q=
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\checkpoint\zaforcefield\trustchecker\components\TrustCheckerMozillaPlugin.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\gary\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-6-6 13496]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl801c4dd8;MpKsl801c4dd8;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{21bf301f-c2c8-4510-bf98-ecce76295b27}\MpKsl801c4dd8.sys [2011-6-20 28752]
R1 MpKslcb9f1e91;MpKslcb9f1e91;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{843b602e-556e-4293-a96b-fda3d2759c20}\mpkslcb9f1e91.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{843b602e-556e-4293-a96b-fda3d2759c20}\MpKslcb9f1e91.sys [?]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2010-6-9 532224]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-5-13 353168]
R2 ASO3DiskOptimizer;ASO3DiskOptimizer;c:\program files\advanced system optimizer 3\ASO3DefragSrv.exe [2010-8-20 238824]
R2 IMFservice;IMF Service;c:\program files\iobit\iobit malware fighter\IMFsrv.exe [2011-6-20 821080]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2009-10-14 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2009-10-14 493032]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-3-1 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2010-9-17 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-4-5 47640]
R2 lxdc_device;lxdc_device;c:\windows\system32\lxdccoms.exe -service –> c:\windows\system32\lxdccoms.exe -service [?]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R3 ArcCD;ArcCD Filter Driver Service;c:\windows\system32\drivers\ArcCD.sys [2011-2-17 36224]
R3 FileMonitor;FileMonitor;c:\program files\iobit\iobit malware fighter\drivers\wxp_x86\FileMonitor.sys [2011-6-20 239472]
R4 RegFilter;RegFilter;c:\program files\iobit\iobit malware fighter\drivers\wxp_x86\RegFilter.sys [2011-6-20 30368]
R4 UrlFilter;UrlFilter;c:\program files\iobit\iobit malware fighter\drivers\wxp_x86\UrlFilter.sys [2011-6-20 16080]
S1 MpKsl2a7a7eeb;MpKsl2a7a7eeb;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{18613ebb-e983-4e35-a8db-af5fd60b8e5b}\mpksl2a7a7eeb.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{18613ebb-e983-4e35-a8db-af5fd60b8e5b}\MpKsl2a7a7eeb.sys [?]
S1 MpKslf28403ba;MpKslf28403ba;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1b4e1252-7f25-4758-984d-17f0f4c67420}\mpkslf28403ba.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1b4e1252-7f25-4758-984d-17f0f4c67420}\MpKslf28403ba.sys [?]
S2 lxdcCATSCustConnectService;lxdcCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdcserv.exe [2010-3-11 99248]
S3 POSKILLDRIVERm;POSKILLDRIVERm;c:\windows\system32\drivers\POSKILLDRIVERm [2011-2-17 6656]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-3 14336]
S4 ArcUdfs;ArcUdfs FileSystem Driver Service;c:\windows\system32\drivers\ArcUdfs.sys [2011-2-17 134912]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
=============== Created Last 30 ================
.
2011-06-20 17:45:17 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{21bf301f-c2c8-4510-bf98-ecce76295b27}\MpKsl801c4dd8.sys
2011-06-20 17:43:01 6962000 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{21bf301f-c2c8-4510-bf98-ecce76295b27}\mpengine.dll
2011-06-16 04:05:49 ——– d—–w- c:\windows\SxsCaPendDel
2011-06-16 04:02:01 551936 -c—-w- c:\windows\system32\dllcache\oleaut32.dll
2011-06-16 03:59:06 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-06-16 03:53:52 ——– d—–w- c:\windows\system32\winrm
2011-06-16 03:53:38 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
2011-06-15 14:02:20 ——– d—–w- c:\documents and settings\all users\Uniblue
2011-06-08 03:16:53 ——– d—–w- c:\docume~1\gary\locals~1\applic~1\Yahoo!
2011-06-07 14:40:58 ——– d—–w- c:\docume~1\gary\applic~1\FreeFileSync
2011-06-07 14:39:16 ——– d—–w- c:\program files\FreeFileSync
2011-06-06 19:55:30 183696 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2011-06-06 19:55:30 183696 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2011-06-06 17:45:07 29520 —-a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-06-06 17:45:06 13496 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-06-06 15:00:59 ——– d—–w- c:\docume~1\alluse~1\applic~1\boost_interprocess
2011-06-06 04:09:38 ——– d—–w- c:\docume~1\gary\locals~1\applic~1\Ilivid Player
2011-06-06 04:04:23 ——– d—–w- c:\program files\Windows iLivid Toolbar
2011-06-06 04:03:21 ——– d—–w- c:\docume~1\gary\locals~1\applic~1\PackageAware
2011-06-06 03:52:47 11776 —-a-w- c:\program files\mozilla firefox\plugins\nprjplug.dll
2011-06-06 03:52:00 ——– d—–w- c:\program files\common files\xing shared
2011-06-06 03:51:35 150712 —-a-w- c:\program files\mozilla firefox\plugins\nppl3260.dll
2011-06-06 03:51:28 105472 —-a-w- c:\program files\mozilla firefox\plugins\nprpjplug.dll
2011-06-06 03:37:39 ——– d—–w- c:\program files\WhiteSmoke
2011-06-02 22:43:40 6962000 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-06-02 18:10:12 ——– d—–w- c:\program files\Siber Systems
2011-06-01 16:11:24 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-06-01 16:01:12 ——– d—–w- c:\program files\Microsoft Security Client
2011-05-28 01:13:00 ——– d—–w- c:\documents and settings\gary\usrusmt2.tmp
2011-05-28 01:04:47 ——– d—–w- c:\program files\EasyFix Tools
2011-05-27 17:18:33 ——– d–h–w- c:\windows\PIF
2011-05-24 20:44:31 ——– d—–w- c:\docume~1\alluse~1\applic~1\Bomgar-SCC-4DDC18AF
2011-05-24 19:40:00 ——– d—–w- c:\docume~1\gary\locals~1\applic~1\Citrix
2011-05-24 19:39:41 103720 —-a-w- c:\documents and settings\gary\GoToAssistDownloadHelper.exe
2011-05-22 16:42:10 ——– d—–w- c:\docume~1\gary\locals~1\applic~1\Temp
.
==================== Find3M ====================
.
2011-06-16 14:46:40 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-16 00:13:51 72080 —-a-w- c:\documents and settings\gary\g2mdlhlpx.exe
2011-06-06 03:51:16 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-06-06 03:51:16 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-05-04 11:52:22 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-05-04 09:25:49 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-02 15:31:52 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-25 16:11:12 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11:11 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11:11 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01:22 385024 —-a-w- c:\windows\system32\html.iec
2011-04-06 23:20:16 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 23:20:16 75040 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 23:20:16 197920 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 23:20:16 107808 —-a-w- c:\windows\system32\dns-sd.exe
2011-03-31 18:18:18 23376 —-a-w- c:\windows\system32\dopdfmn7.dll
2011-03-31 18:18:16 20304 —-a-w- c:\windows\system32\dopdfmi7.dll
.
============= FINISH: 12:07:34.28 ===============

Attachments:

Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post












  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.










  • Download aswMBR.exe ( 511KB ) to your desktop.
  • Double click the aswMBR.exe to run it
  • Click the Scan button to start scan
  • On completion of the scan click Save Log, save it to your Desktop and post in your next reply
OTL logfile created on: 6/23/2011 10:43:04 AM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\gary\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.10 Mb Total Physical Memory | 146.91 Mb Available Physical Memory | 16.43% Memory free
2.11 Gb Paging File | 1.09 Gb Available in Paging File | 51.48% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 55.80 Gb Free Space | 49.92% Space Free | Partition Type: NTFS
Drive E: | 1.87 Gb Total Space | 1.15 Gb Free Space | 61.75% Space Free | Partition Type: FAT

Computer Name: HOME-E03FACF8C2 | User Name: gary | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\gary\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
PRC - C:\Program Files\IObit\IObit Malware Fighter\IMF.exe (IObit)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\IObit\Game Booster\gbtray.exe (IObit)
PRC - C:\Program Files\Kodak\MediaImpression\ArcMonitor.exe (ArcSoft, Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Ontrack\Fix-It\mxserver.exe (Ontrack Data International)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe (Systweak Inc., (www.systweak.com))
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Corel\Corel GuideMenu\GuideMenu.exe (Corel Copyright © 2007)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\WINDOWS\system32\lxdccoms.exe ( )
PRC - C:\Program Files\Lexmark 1300 Series\lxdcamon.exe ()
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe ()
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\gary\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchrome10browserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)


========== Win32 Services (SafeList) ==========

SRV - (IMFservice) – C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (mxserver) – C:\Program Files\Ontrack\Fix-It\mxserver.exe (Ontrack Data International)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (ASO3DiskOptimizer) – C:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe (Systweak Inc., (www.systweak.com))
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (lxdcCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdcserv.exe ()
SRV - (lxdc_device) – C:\WINDOWS\System32\lxdccoms.exe ( )
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (ProtexisLicensing) – C:\Program Files\Common Files\Protexis\License Service\PSIService.exe ()
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (MpKsl8bc62b14) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BCC9E123-4620-4000-9603-1C62808647D9}\MpKsl8bc62b14.sys (Microsoft Corporation)
DRV - (MpKsl5f0cc74c) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BCC9E123-4620-4000-9603-1C62808647D9}\MpKsl5f0cc74c.sys (Microsoft Corporation)
DRV - (FileMonitor) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys ()
DRV - (UrlFilter) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys (IObit.com)
DRV - (RegFilter) – C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys (IObit.com)
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (SmartDefragDriver) – C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys ()
DRV - (POSKILLDRIVERm) – C:\WINDOWS\system32\drivers\POSKILLDRIVERm ()
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (ArcCD) – C:\WINDOWS\System32\drivers\ArcCD.sys (ArcSoft Inc.)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (ArcUdfs) – C:\WINDOWS\System32\drivers\ArcUdfs.sys (ArcSoft Inc.)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (Cam5603D) – C:\WINDOWS\system32\drivers\BisonCam.sys (Bison Electronics. Inc. )
DRV - (ESDCR) – C:\WINDOWS\system32\drivers\ESD7SK.sys (ENE Technology Inc.)
DRV - (ESMCR) – C:\WINDOWS\system32\drivers\ESM7SK.sys (ENE Technology Inc.)
DRV - (EMSCR) – C:\WINDOWS\system32\drivers\EMS7SK.sys (ENE Technology Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTSERIAL) – C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B8 01 AA CE 54 C9 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.006.004
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.5.227.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.2
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=102&systemid;=406&q;="

FF - HKLM\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/02/07 08:35:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/05/11 09:01:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/06/05 20:51:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/05 20:51:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/20 06:45:29 | 000,000,000 | —D | M]

[2011/06/05 21:04:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\gary\Application Data\Mozilla\Extensions
[2011/06/19 17:07:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\gary\Application Data\Mozilla\Firefox\Profiles\nc40df2x.default\extensions
[2011/02/04 09:06:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\gary\Application Data\Mozilla\Firefox\Profiles\nc40df2x.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/23 10:38:41 | 000,000,000 | —D | M] (Window Shopper - Powered by Superfish) – C:\Documents and Settings\gary\Application Data\Mozilla\Firefox\Profiles\nc40df2x.default\extensions\[removed]
[2011/06/05 21:04:24 | 000,002,501 | —- | M] () – C:\Documents and Settings\gary\Application Data\Mozilla\Firefox\Profiles\nc40df2x.default\searchplugins\SearchResults.xml
[2011/06/15 06:53:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/09 13:35:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/03/08 09:33:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/15 06:53:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) –
[2011/06/05 20:51:53 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
() (No name found) – C:\DOCUMENTS AND SETTINGS\GARY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\NC40DF2X.DEFAULT\EXTENSIONS\{CE6E6E3B-84DD-4CAC-9F63-8D2AE4F30A4B}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\GARY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\NC40DF2X.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\GARY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\NC40DF2X.DEFAULT\EXTENSIONS\[removed]
[2011/05/11 09:01:35 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2010/06/09 13:34:42 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/06/05 21:04:52 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES\WINDOWS ILIVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2011/04/29 15:44:59 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 01:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/06/05 21:04:24 | 000,002,501 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchResults.xml

O1 HOSTS File: ([2004/08/03 18:07:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - Reg Error: Value error. File not found
O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ShopAtHome Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [ArcSoft MediaImpression Monitor] C:\Program Files\Kodak\MediaImpression\ArcMonitor.exe (ArcSoft, Inc.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [GuideMenu] C:\Program Files\Corel\Corel GuideMenu\GuideMenu.exe (Corel Copyright © 2007)
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [lxdcamon] C:\Program Files\Lexmark 1300 Series\lxdcamon.exe ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRealMode = 0
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Value error. File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\gary\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\gary\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/09 19:09:10 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/06/23 08:52:12 | 000,000,090 | —- | M] () - E:\AUTORUN.INF – [ FAT ]
O33 - MountPoints2\{a627b898-3abb-11e0-bde3-0016d415960f}\Shell - "" = AutoRun
O33 - MountPoints2\{a627b898-3abb-11e0-bde3-0016d415960f}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.mpegacm - C:\Program Files\Common Files\Ulead Systems\MPEG\MPEGACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.ulmp3acm - C:\Program Files\Common Files\Ulead Systems\MPEG\ulmp3acm.acm (Ulead systems)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - xvidvfw.dll File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (65034330371522560)

========== Files/Folders - Created Within 30 Days ==========

[2011/06/23 10:39:35 | 000,579,072 | —- | C] (OldTimer Tools) – C:\Documents and Settings\gary\Desktop\OTL.exe
[2011/06/23 08:43:09 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Desktop\PR_emailList
[2011/06/22 12:35:47 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\My Documents\MIT(stephine)
[2011/06/22 10:03:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ArcSoft Connect
[2011/06/21 20:16:29 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Application Data\ZoomBrowser EX
[2011/06/21 16:02:42 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Local Settings\Application Data\WMTools Downloaded Files
[2011/06/21 15:01:31 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\My Documents\InterVideo
[2011/06/21 14:58:54 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Application Data\InterVideo
[2011/06/21 14:33:04 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Application Data\Ulead Systems
[2011/06/21 14:30:07 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Application Data\Corel
[2011/06/21 14:30:03 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\My Documents\Ulead DVD MovieFactory
[2011/06/21 08:46:20 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\My Documents\Instant Article Creation Templates 2.0
[2011/06/20 11:37:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\IObit Malware Fighter
[2011/06/17 10:17:27 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\My Documents\FileSync
[2011/06/15 21:05:49 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2011/06/15 21:02:01 | 000,551,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oleaut32.dll
[2011/06/15 20:59:06 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2011/06/15 20:53:53 | 000,000,000 | —D | C] – C:\WINDOWS\System32\WindowsPowerShell
[2011/06/15 20:53:52 | 000,000,000 | —D | C] – C:\WINDOWS\System32\winrm
[2011/06/15 20:53:38 | 000,000,000 | -H-D | C] – C:\WINDOWS\$968930Uinstall_KB968930$
[2011/06/15 07:02:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Uniblue
[2011/06/15 06:53:47 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/06/15 06:53:47 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/06/15 06:53:47 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/06/12 11:37:28 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\My Documents\Articles made from book
[2011/06/07 20:18:25 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Start Menu\Programs\BrowserPlus
[2011/06/07 20:16:53 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Local Settings\Application Data\Yahoo!
[2011/06/07 07:40:58 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Application Data\FreeFileSync
[2011/06/07 07:39:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\FreeFileSync
[2011/06/07 07:39:16 | 000,000,000 | —D | C] – C:\Program Files\FreeFileSync
[2011/06/06 10:45:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Smart Defrag 2
[2011/06/06 10:44:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Game Booster
[2011/06/06 08:00:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/06/05 21:09:38 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Local Settings\Application Data\Ilivid Player
[2011/06/05 21:04:23 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/06/05 21:03:21 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Local Settings\Application Data\PackageAware
[2011/06/05 20:52:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2011/06/05 20:51:35 | 000,198,848 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/06/05 20:51:23 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/06/05 20:51:23 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/06/05 20:51:22 | 000,272,896 | —- | C] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/06/05 20:51:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Real
[2011/06/05 20:51:03 | 000,000,000 | —D | C] – C:\Program Files\Real
[2011/06/05 20:51:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Real
[2011/06/05 20:51:00 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Application Data\Real
[2011/06/05 20:37:39 | 000,000,000 | —D | C] – C:\Program Files\WhiteSmoke
[2011/06/05 11:58:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Softland
[2011/06/05 09:39:26 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Application Data\Leadertech
[2011/06/02 11:10:12 | 000,000,000 | —D | C] – C:\Program Files\Siber Systems
[2011/06/01 09:11:24 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/06/01 09:01:12 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/05/30 09:31:06 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Desktop\SSI
[2011/05/30 08:53:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/05/27 18:04:47 | 000,000,000 | —D | C] – C:\Program Files\EasyFix Tools
[2011/05/27 17:58:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\C_
[2011/05/27 10:18:33 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2011/05/26 16:24:07 | 000,000,000 | R–D | C] – C:\Documents and Settings\gary\Start Menu\Programs\Administrative Tools
[2011/05/24 13:44:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-4DDC18AF
[2011/05/24 12:40:00 | 000,000,000 | —D | C] – C:\Documents and Settings\gary\Local Settings\Application Data\Citrix
[2010/03/11 13:44:17 | 001,232,896 | —- | C] ( ) – C:\WINDOWS\System32\lxdcserv.dll
[2010/03/11 13:44:17 | 000,999,424 | —- | C] ( ) – C:\WINDOWS\System32\lxdcusb1.dll
[2010/03/11 13:44:17 | 000,413,696 | —- | C] ( ) – C:\WINDOWS\System32\lxdcinpa.dll
[2010/03/11 13:44:17 | 000,397,312 | —- | C] ( ) – C:\WINDOWS\System32\lxdciesc.dll
[2010/03/11 13:44:17 | 000,323,584 | —- | C] ( ) – C:\WINDOWS\System32\LXDChcp.dll
[2010/03/11 13:44:17 | 000,163,840 | —- | C] ( ) – C:\WINDOWS\System32\lxdcprox.dll
[2010/03/11 13:44:16 | 000,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxdcpmui.dll
[2010/03/11 13:44:16 | 000,585,728 | —- | C] ( ) – C:\WINDOWS\System32\lxdclmpm.dll
[2010/03/11 13:44:16 | 000,385,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdcih.exe
[2010/03/11 13:44:16 | 000,094,208 | —- | C] ( ) – C:\WINDOWS\System32\lxdcpplc.dll
[2010/03/11 13:44:15 | 000,700,416 | —- | C] ( ) – C:\WINDOWS\System32\lxdchbn3.dll
[2010/03/11 13:44:15 | 000,684,032 | —- | C] ( ) – C:\WINDOWS\System32\lxdccomc.dll
[2010/03/11 13:44:15 | 000,537,520 | —- | C] ( ) – C:\WINDOWS\System32\lxdccoms.exe
[2010/03/11 13:44:15 | 000,425,984 | —- | C] ( ) – C:\WINDOWS\System32\lxdccomm.dll
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[11 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\Documents and Settings\gary\*.tmp files -> C:\Documents and Settings\gary\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/23 10:39:46 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Documents and Settings\gary\Desktop\OTL.exe
[2011/06/23 07:00:11 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/06/23 06:55:59 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/06/23 06:55:49 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-343818398-861567501-1801674531-1005.job
[2011/06/23 06:55:36 | 000,000,268 | —- | M] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/06/23 06:55:36 | 000,000,246 | —- | M] () – C:\WINDOWS\tasks\Game_Booster_Startup.job
[2011/06/23 06:54:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/06/22 21:07:28 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-343818398-861567501-1801674531-1005.job
[2011/06/22 07:09:33 | 000,000,112 | —- | M] () – C:\Documents and Settings\gary\default.pls
[2011/06/22 07:08:58 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/06/21 20:27:36 | 000,008,704 | —- | M] () – C:\Documents and Settings\gary\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/21 19:34:30 | 000,001,730 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/06/20 19:14:54 | 000,433,014 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/06/20 19:14:54 | 000,067,930 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/06/20 06:45:32 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/06/16 07:46:40 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/15 17:13:51 | 000,072,080 | —- | M] () – C:\Documents and Settings\gary\g2mdlhlpx.exe
[2011/06/08 15:41:14 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/06/08 08:13:07 | 000,000,000 | —- | M] () – C:\Documents and Settings\gary\Local Settings\Application Data\prvlcl.dat
[2011/06/07 12:15:29 | 000,000,338 | —- | M] () – C:\Documents and Settings\gary\Desktop\Shortcut to My Documents.lnk
[2011/06/07 07:39:34 | 000,000,730 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FreeFileSync.lnk
[2011/06/06 15:35:34 | 000,000,145 | —- | M] () – C:\Shortcut to CD Drive.lnk
[2011/06/05 20:51:36 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/06/05 20:51:23 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/06/05 20:51:23 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/06/05 20:51:22 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/06/05 19:35:12 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2011/06/01 09:02:14 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/05/30 15:19:48 | 005,964,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2011/05/30 08:53:30 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/27 21:26:22 | 000,016,784 | —- | M] () – C:\Documents and Settings\gary\Local Settings\Application Data\FASTWiz.html
[2011/05/27 14:12:26 | 000,000,520 | R— | M] () – C:\WINDOWS\System32\drivers\RTEQEX1.dat
[2011/05/27 14:12:26 | 000,000,520 | R— | M] () – C:\WINDOWS\System32\drivers\RTEQEX0.dat
[2011/05/27 14:12:26 | 000,000,008 | R— | M] () – C:\WINDOWS\System32\drivers\rtkhdaud.dat
[2011/05/27 14:12:25 | 000,127,619 | R— | M] () – C:\WINDOWS\System32\atiicdxx.dat
[2011/05/26 11:48:37 | 000,000,109 | —- | M] () – C:\Documents and Settings\gary\default(1).pls
[2011/05/24 12:39:43 | 000,103,720 | —- | M] () – C:\Documents and Settings\gary\GoToAssistDownloadHelper.exe
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[11 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\Documents and Settings\gary\*.tmp files -> C:\Documents and Settings\gary\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/21 16:19:44 | 000,000,276 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-343818398-861567501-1801674531-1005.job
[2011/06/20 06:45:31 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/06/20 06:45:29 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/06/15 20:56:55 | 000,225,262 | —- | C] () – C:\WINDOWS\System32\dllcache\msimain.sdb
[2011/06/07 12:15:23 | 000,000,338 | —- | C] () – C:\Documents and Settings\gary\Desktop\Shortcut to My Documents.lnk
[2011/06/07 07:39:33 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Desktop\FreeFileSync.lnk
[2011/06/06 15:35:34 | 000,000,145 | —- | C] () – C:\Shortcut to CD Drive.lnk
[2011/06/06 11:30:18 | 000,000,246 | —- | C] () – C:\WINDOWS\tasks\Game_Booster_Startup.job
[2011/06/06 10:45:07 | 000,029,520 | —- | C] () – C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/06/06 10:45:06 | 000,013,496 | —- | C] () – C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/06/05 20:53:20 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-343818398-861567501-1801674531-1005.job
[2011/06/01 16:08:45 | 000,000,000 | —- | C] () – C:\Documents and Settings\gary\Local Settings\Application Data\prvlcl.dat
[2011/06/01 09:06:49 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/06/01 09:02:14 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/06/01 09:01:30 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/05/30 08:53:30 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/27 13:27:44 | 000,016,784 | —- | C] () – C:\Documents and Settings\gary\Local Settings\Application Data\FASTWiz.html
[2011/05/24 12:39:41 | 000,103,720 | —- | C] () – C:\Documents and Settings\gary\GoToAssistDownloadHelper.exe
[2011/03/16 18:14:46 | 000,026,064 | —- | C] () – C:\WINDOWS\System32\IDriveEXceedCryReg.exe
[2011/03/16 18:13:58 | 000,055,808 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2011/02/23 10:49:05 | 000,008,704 | —- | C] () – C:\Documents and Settings\gary\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/14 16:02:43 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/12/19 11:40:02 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2010/12/19 11:39:14 | 000,000,520 | R— | C] () – C:\WINDOWS\System32\drivers\RTEQEX1.dat
[2010/12/19 11:39:14 | 000,000,520 | R— | C] () – C:\WINDOWS\System32\drivers\RTEQEX0.dat
[2010/12/19 11:39:14 | 000,000,008 | R— | C] () – C:\WINDOWS\System32\drivers\rtkhdaud.dat
[2010/08/20 11:08:33 | 000,017,136 | —- | C] () – C:\WINDOWS\System32\sasnative32.exe
[2010/07/07 13:04:14 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\9B43B50AEB.sys
[2010/07/06 13:25:17 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/14 19:01:14 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/06/14 19:01:14 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/06/14 19:01:14 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/06/14 19:01:14 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/06/14 19:01:13 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/06/14 19:01:13 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2010/06/09 15:58:24 | 000,044,416 | —- | C] () – C:\WINDOWS\System32\mxntboot.exe
[2010/06/09 15:58:24 | 000,020,736 | —- | C] () – C:\WINDOWS\System32\mxntdfg.exe
[2010/06/09 15:42:31 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2010/06/09 09:34:55 | 000,001,730 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2010/06/09 09:34:55 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\B9FBABCA69.sys
[2010/06/09 07:36:29 | 000,001,237 | —- | C] () – C:\Program Files\WinDVDSetup.iss
[2010/06/09 07:36:09 | 000,000,328 | —- | C] () – C:\Program Files\GuideMenuSetup.iss
[2010/03/17 18:16:14 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/03/11 21:05:16 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2010/03/11 13:45:36 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdcvs.dll
[2010/03/11 13:45:29 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\lxdccoin.dll
[2010/03/11 13:44:55 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\lxdcrwrd.ini
[2010/03/11 13:44:17 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\LXDCinst.dll
[2010/03/11 13:44:15 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdcgrd.dll
[2010/03/10 13:12:18 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/03/10 08:47:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/03/09 19:29:03 | 000,127,619 | R— | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/03/09 19:27:45 | 000,015,190 | —- | C] () – C:\WINDOWS\M2000Twn.ini
[2010/03/09 19:12:20 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/03/09 19:05:25 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/03/09 10:51:58 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/03/09 10:50:09 | 000,236,760 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/01/17 11:31:30 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2004/08/03 18:07:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/03 18:07:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/03 18:07:00 | 000,433,014 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/03 18:07:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/03 18:07:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/03 18:07:00 | 000,067,930 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/03 18:07:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/03 18:07:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/03 18:07:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/03 18:07:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/03 18:07:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/03 18:07:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2001/11/14 13:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2011/04/24 10:17:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/05/24 14:00:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-4DDC18AF
[2011/06/06 08:00:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2010/07/11 09:58:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2011/03/14 10:03:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/02/17 16:26:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Encryptomatic, LLC
[2011/06/06 10:44:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/03/10 09:04:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/06/23 06:55:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/06/06 08:32:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/05/13 15:28:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/14 18:46:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/01/14 16:04:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivitar
[2011/01/14 16:04:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivitar Experience Image Manager
[2011/02/07 18:59:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/05/27 18:20:25 | 000,000,000 | —D | M] – C:\Documents and Settings\gary\Application Data\BitZipper
[2011/02/02 14:25:07 | 000,000,000 | —D | M] – C:\Documents and Settings\gary\Application Data\CheckPoint
[2011/02/17 16:27:05 | 000,000,000 | —D | M] – C:\Documents and Settings\gary\Application Data\Encryptomatic, LLC
[2011/06/07 07:45:38 | 000,000,000 | —D | M] – C:\Documents and Settings\gary\Application Data\FreeFileSync
[2011/06/21 14:58:54 | 000,000,000 | —D | M] – C:\Documents and Settings\gary\Application Data\InterVideo
[2011/06/16 15:50:09 | 000,000,000 | —D | M] – C:\Documents and Settings\gary\Application Data\IObit
[2011/06/05 09:39:26 | 000,000,000 | —D | M] – C:\Documents and Settings\gary\Application Data\Leadertech
[2011/05/27 18:20:48 | 000,000,000 | —D | M] – C:\Documents and Settings\gary\Application Data\PSTViewer
[2011/05/13 15:26:13 | 000,000,000 | —D | M] – C:\Documents and Settings\gary\Application Data\Sammsoft
[2011/04/06 16:41:01 | 000,000,000 | —D | M] – C:\Documents and Settings\gary\Application Data\Softland
[2011/06/21 18:42:46 | 000,000,000 | —D | M] – C:\Documents and Settings\gary\Application Data\Ulead Systems
[2011/06/23 06:55:36 | 000,000,268 | —- | M] () – C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2011/06/23 06:55:36 | 000,000,246 | —- | M] () – C:\WINDOWS\Tasks\Game_Booster_Startup.job
[2011/06/23 07:00:11 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/04/05 20:36:55 | 000,001,024 | —- | M] () – C:\.rnd
[2010/03/09 19:09:10 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/03/09 19:02:11 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/05/27 10:21:11 | 000,000,010 | —- | M] () – C:\BRDNO.TXT
[2010/03/10 11:35:36 | 000,007,448 | R— | M] () – C:\CLDMA.LOG
[2011/03/16 18:19:43 | 000,608,448 | —- | M] (Microsoft Corporation) – C:\COMCTL32.OCX
[2010/03/09 19:09:10 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/03/09 19:09:10 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/03/09 19:09:10 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/03 18:07:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/03/09 19:40:58 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/06/23 06:54:50 | 1409,286,144 | -HS- | M] () – C:\pagefile.sys
[2011/06/06 15:35:34 | 000,000,145 | —- | M] () – C:\Shortcut to CD Drive.lnk
[2011/04/08 16:22:19 | 000,000,058 | —- | M] () – C:\Trace.txt
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/03/09 19:08:39 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2011/03/01 12:12:16 | 000,053,632 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/01/18 07:18:54 | 000,103,936 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdcdrpp.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2011/06/23 08:52:09 | 000,001,746 | -H– | M] () – C:\Documents and Settings\gary\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2007/04/25 01:49:51 | 000,000,328 | —- | M] () – C:\Program Files\GuideMenuSetup.iss
[2007/04/05 20:28:08 | 000,001,237 | —- | M] () – C:\Program Files\WinDVDSetup.iss

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/03/09 10:48:17 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/03/09 10:48:17 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/03/09 10:48:16 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/03/09 19:46:17 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/02/02 14:25:47 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\gary\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/02/02 14:25:47 | 000,000,079 | —- | M] () – C:\Documents and Settings\gary\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/06/23 10:39:46 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Documents and Settings\gary\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2003/09/22 14:36:46 | 000,013,448 | —- | M] () – C:\WINDOWS\M2000Twn.src
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >
[2011/06/15 17:13:51 | 000,072,080 | —- | M] () – C:\Documents and Settings\gary\g2mdlhlpx.exe
[2011/05/24 12:39:43 | 000,103,720 | —- | M] () – C:\Documents and Settings\gary\GoToAssistDownloadHelper.exe
[1 C:\Documents and Settings\gary\*.tmp files -> C:\Documents and Settings\gary\*.tmp -> ]

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2011/02/02 14:25:47 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\gary\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2011/03/22 18:37:40 | 000,014,086 | —- | M] () – C:\Documents and Settings\All Users\lxdc
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/06/23 07:46:11 | 000,049,152 | —- | M] () – C:\Documents and Settings\gary\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-21 02:15:27

========== Alternate Data Streams ==========

@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >

OTL Extras logfile created on: 6/23/2011 10:43:04 AM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\gary\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.10 Mb Total Physical Memory | 146.91 Mb Available Physical Memory | 16.43% Memory free
2.11 Gb Paging File | 1.09 Gb Available in Paging File | 51.48% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 55.80 Gb Free Space | 49.92% Space Free | Partition Type: NTFS
Drive E: | 1.87 Gb Total Space | 1.15 Gb Free Space | 61.75% Space Free | Partition Type: FAT

Computer Name: HOME-E03FACF8C2 | User Name: gary | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Lexmark 1300 Series\app4r.exe" = C:\Program Files\Lexmark 1300 Series\App4R.exe:*:Enabled:Lexmark Imaging Studio – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\lxdccoms.exe" = C:\WINDOWS\system32\lxdccoms.exe:*:Enabled:1300 Series Server – ( )
"C:\Program Files\Lexmark 1300 Series\App4R.exe" = C:\Program Files\Lexmark 1300 Series\App4R.exe:*:Disabled:Printing Application – ()
"C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" = C:\Program Files\Lexmark 1300 Series\lxdcamon.exe:*:Disabled:Device Monitor Application – ()
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon – (Check Point Software Technologies LTD)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcpswx.exe:*:Enabled: – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdcjswx.exe:*:Enabled: – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdctime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdctime.exe:*:Enabled: – (Lexmark International, Inc.)
"C:\WINDOWS\system32\usmt\migwiz.exe" = C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{1A6A6531-08FC-47AD-BAC4-C41497E71033}" = Nero 7 Essentials
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A57592C-FF92-4083-97A9-92783BD5AFB4}" = Acer OrbiCam
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{65179FD8-04C0-40A7-87FC-007F2CD5BF1E}" = LogMeIn
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{79B05AF4-8894-49A1-9FF4-53F0142D85E1}" = ATI Catalyst Control Center
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}" = ATI Parental Control & Encoder
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{973A3E5C-36E8-43AC-8EE4-E1CF3DF721A2}" = PSTViewer Pro
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1E21995-127E-4B7F-8C4D-CB04AA8A58EF}_is1" = Advanced System Optimizer
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C975D391-7BF6-44A0-A4FF-EDF3CFD88F68}" = ArcSoft MediaImpression for Kodak
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DFF56DFF-F703-467C-AF1D-B8FAA99C7416}" = Ulead DVD MovieFactory SE
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2BFA&SUBSYS;_1025009F" = Soft Data Fax Modem with SmartCP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CSCLIB" = Canon Camera Support Core Library
"doPDF 7 printer_is1" = doPDF 7.2 printer
"EOS Utility" = Canon Utilities EOS Utility
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"Fix-It1.0" = Fix-It Utilities 2000
"FreeFileSync" = FreeFileSync v3.16
"Game Booster_is1" = Game Booster
"ie8" = Windows Internet Explorer 8
"InstallShield_{6D299DC3-31E2-45C6-8E36-263A2AB1CE8C}" = InterVideo WinDVD SE
"InstallShield_{83104339-BF03-4ECA-910F-7B5344717EB5}" = Corel GuideMenu
"IObit Malware Fighter_is1" = IObit Malware Fighter
"jZip" = jZip
"Lexmark 1300 Series" = Lexmark 1300 Series
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 12.0" = RealPlayer
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"SelectRebatesUninstall" = ShopAtHome SelectRebates
"Smart Defrag 2_is1" = Smart Defrag 2
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"ZoneAlarm" = ZoneAlarm
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.8.0.723
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/21/2011 11:03:13 AM | Computer Name = HOME-E03FACF8C2 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Failed to compile: c:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.IO.Log.dll
. Error code = 0x80070020

Error - 6/21/2011 11:03:18 AM | Computer Name = HOME-E03FACF8C2 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Failed to compile: c:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
. Error code = 0x80070020

Error - 6/21/2011 11:04:49 AM | Computer Name = HOME-E03FACF8C2 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Failed to compile: Microsoft.PowerShell.Commands.Management,Version=1.0.0.0,Culture=neutral,PublicK
eyToken=31bf3856ad364e35,ProcessorArchitecture=msil
. Error code = 0x80070020

Error - 6/21/2011 3:13:17 PM | Computer Name = HOME-E03FACF8C2 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070020, P2 patchapplication, P3 am bde,
P4 10.3.1781.0, P5 mpsigstub.exe, P6 3.0.8107.0, P7 microsoft security essentials,
P8 NIL, P9 NIL, P10 NIL.

Error - 6/22/2011 10:01:45 AM | Computer Name = HOME-E03FACF8C2 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 80070422 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 6/22/2011 10:01:45 AM | Computer Name = HOME-E03FACF8C2 | Source = VSS | ID = 8193
Description = Volume Shadow Copy Service error: Unexpected error calling routine
CoCreateInstance. hr = 0x80040206.

Error - 6/22/2011 10:03:06 AM | Computer Name = HOME-E03FACF8C2 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 80070422 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 6/23/2011 9:55:28 AM | Computer Name = HOME-E03FACF8C2 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 80070422 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 6/23/2011 9:55:28 AM | Computer Name = HOME-E03FACF8C2 | Source = VSS | ID = 8193
Description = Volume Shadow Copy Service error: Unexpected error calling routine
CoCreateInstance. hr = 0x80040206.

Error - 6/23/2011 9:56:58 AM | Computer Name = HOME-E03FACF8C2 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 80070422 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

[ System Events ]
Error - 6/22/2011 10:10:58 AM | Computer Name = HOME-E03FACF8C2 | Source = ati2mtag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 6/22/2011 10:10:59 AM | Computer Name = HOME-E03FACF8C2 | Source = ati2mtag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 6/22/2011 10:11:01 AM | Computer Name = HOME-E03FACF8C2 | Source = ati2mtag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 6/23/2011 12:11:06 AM | Computer Name = HOME-E03FACF8C2 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 6/23/2011 9:55:28 AM | Computer Name = HOME-E03FACF8C2 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 6/23/2011 9:55:58 AM | Computer Name = HOME-E03FACF8C2 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 6/23/2011 9:55:59 AM | Computer Name = HOME-E03FACF8C2 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdcCATSCustConnectService
service to connect.

Error - 6/23/2011 9:55:59 AM | Computer Name = HOME-E03FACF8C2 | Source = Service Control Manager | ID = 7000
Description = The lxdcCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 6/23/2011 9:55:59 AM | Computer Name = HOME-E03FACF8C2 | Source = Service Control Manager | ID = 7001
Description = The System Event Notification service depends on the COM+ Event System
service which failed to start because of the following error: %%1058

Error - 6/23/2011 9:56:58 AM | Computer Name = HOME-E03FACF8C2 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}


< End of report >
aswMBR version 0.9.7.675 Copyright© 2011 AVAST Software Run date: 2011-06-23 10:55:55 —————————– 10:55:55.515 OS Version: Windows 5.1.2600 Service Pack 3 10:55:55.515 Number of processors: 2 586 0x4802 10:55:55.515 ComputerName: HOME-E03FACF8C2 UserName: gary 10:55:59.171 Initialize success 10:56:25.234 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 10:56:25.234 Disk 0 Vendor: HTS421212H9AT00 HA4OA70S Size: 114473MB BusType: 3 10:56:27.250 Disk 0 MBR read successfully 10:56:27.250 Disk 0 MBR scan 10:56:27.250 Disk 0 Windows XP default MBR code 10:56:29.250 Disk 0 scanning sectors +234420480 10:56:29.328 Disk 0 scanning C:\WINDOWS\system32\drivers 10:56:36.953 Service scanning 10:56:38.218 Disk 0 trace - called modules: 10:56:38.265 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys 10:56:38.265 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85558ab8] 10:56:38.265 3 CLASSPNP.SYS[f7692fd7] -> nt!IofCallDriver -> \Device\00000080[0x8557b9e8] 10:56:38.265 5 ACPI.sys[f7529620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x8557bd98] 10:56:38.265 Scan finished successfully 10:57:13.468 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\gary\Desktop\MBR.dat" 10:57:13.500 The log file has been saved successfully to "C:\Documents and Settings\gary\Desktop\aswMBR.txt"
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/406
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - Reg Error: Value error. File not found
    O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
    O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - Reg Error: Value error. File not found
    O3 - HKLM\..\Toolbar: (ShopAtHome Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - Reg Error: Value error. File not found
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Value error. File not found
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
    O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) - C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
    
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )









Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please














Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
:notworthy: :clap: :thumbup: :wub: :yeah: :woot: :D as you can see i can't thankyou enough ITS GONE Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Database version: 6939 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 6/24/2011 10:41:42 AM mbam-log-2011-06-24 (10-41-42).txt Scan type: Quick scan Objects scanned: 163670 Time elapsed: 5 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 3 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\POSKILLDRIVERm (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\.pox (Rogue.FixTool) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\pofile (Rogue.FixTool) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\bak_XMLLookup (Hijacker.XMLLookup) -> Value: bak_XMLLookup -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\bak_Application (Hijacker.Application) -> Value: bak_Application -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\bak_intl (Hijacker.intl) -> Value: bak_intl -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\XMLLookup (Hijacker.XMLLookup) -> Bad: (http://www.helpmeopen.com/?n=app&l=%04x&ext=%s) Good: (http://shell.windows.com/fileassoc/fileassoc.asp?LangID=%04x&Ext=%s) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\Application (Hijacker.Application) -> Bad: (http://www.helpmeopen.com/?n=app&l=%04x&ext=%s) Good: (http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\intl (Hijacker.intl) -> Bad: (http://www.helpmeopen.com/?n=app&l=%04x&ext=%s) Good: (http://shell.windows.com/fileassoc/fileassoc.asp?LangID=%04x&Ext=%s) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\system32\drivers\poskilldriverm (Trojan.Agent) -> Quarantined and deleted successfully. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully. C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E8DAAA30-6CAA-4b58-9603-8E54238219E2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E8DAAA30-6CAA-4b58-9603-8E54238219E2}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98279C38-DE4B-4bcf-93C9-8EC26069D6F4} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98279C38-DE4B-4bcf-93C9-8EC26069D6F4}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\avgsecuritytoolbar\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F2DDE6B2-9684-4A55-86D4-E255E237B77C}\ deleted successfully. File {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Value error. File not found not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll deleted successfully. C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll deleted successfully. File C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: gary ->Temp folder emptied: 98879809 bytes ->Temporary Internet Files folder emptied: 1185276 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 145277357 bytes ->Flash cache emptied: 1636 bytes User: Joan ->Temp folder emptied: 82985778 bytes ->Temporary Internet Files folder emptied: 9225465 bytes ->Java cache emptied: 238235 bytes ->FireFox cache emptied: 35687262 bytes ->Flash cache emptied: 7079 bytes User: LocalService ->Temp folder emptied: 2045864 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 2123028 bytes ->Temporary Internet Files folder emptied: 49621 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 4383733 bytes %systemroot%\System32 .tmp files removed: 25422353 bytes %systemroot%\System32\dllcache .tmp files removed: 1210880 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2138505 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 67780052 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 3159142959 bytes Total Files Cleaned = 3,469.00 mb OTL by OldTimer - Version 3.2.24.1 log created on 06242011_065754 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\gary\Local Settings\Temp\etilqs_pQGbUSVcWBwflhV not found! C:\Documents and Settings\gary\Local Settings\Temp\~DF15B3.tmp moved successfully. C:\Documents and Settings\gary\Local Settings\Application Data\Mozilla\Firefox\Profiles\nc40df2x.default\startupCache\startupCache.4.little moved successfully. C:\Documents and Settings\gary\Local Settings\Application Data\Mozilla\Firefox\Profiles\nc40df2x.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\gary\Local Settings\Application Data\Mozilla\Firefox\Profiles\nc40df2x.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\gary\Local Settings\Application Data\Mozilla\Firefox\Profiles\nc40df2x.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\gary\Local Settings\Application Data\Mozilla\Firefox\Profiles\nc40df2x.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\gary\Local Settings\Application Data\Mozilla\Firefox\Profiles\nc40df2x.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\gary\Local Settings\Application Data\Mozilla\Firefox\Profiles\nc40df2x.default\XUL.mfl moved successfully. File\Folder C:\WINDOWS\temp\ZLT00b3b.TMP not found! Registry entries deleted on Reboot… thanks AGAIN
You appear clean of infections,please do the following.




Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.









Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI