This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Multiple Problems

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've had these error messges come up everytime I boot up my computer saying Cannot run or cannot find Csrss.exe, My computer randomly restarts, I'm not sure if those are related. I also get the Blue Screen of Death sometimes, which is very irratating. I've googled to try and fix these before, but I've had no luck with it. I have a Windows Xp.

OTL Scan Results

OTL.Txt File

OTL logfile created on: 6/26/2011 10:34:35 AM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Ron Lambdin\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.12 Gb Available Physical Memory | 55.98% Memory free
3.85 Gb Paging File | 2.88 Gb Available in Paging File | 74.88% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 117.97 Gb Free Space | 63.32% Space Free | Partition Type: NTFS

Computer Name: 4SIGHT | User Name: Ron Lambdin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Ron Lambdin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Java\jre6\bin\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\ArcEmu Blizzlike\Server\mysql\bin\mysqld-nt.exe ()
PRC - C:\Program Files\MouseWare\system\EM_EXEC.EXE (Logitech Inc.)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Ron Lambdin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
MOD - C:\Program Files\Common Files\Logitech\Scrolling\LGMSGHK.DLL (Logitech Inc.)
MOD - C:\Program Files\MouseWare\system\LgWndHk.dll (Logitech Inc.)


========== Win32 Services (SafeList) ==========

SRV - (TuneUp360Mon) – File not found
SRV - (hasplms) – File not found
SRV - (AppMgmt) – File not found
SRV - (CLPSLS) – C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe (COMODO)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (mysql) – C:\ArcEmu Blizzlike\Server\mysql\bin\mysqld-nt.exe ()


========== Driver Services (SafeList) ==========

DRV - (Inspect) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (cmderd) – C:\WINDOWS\system32\drivers\cmderd.sys (COMODO)
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (aksfridge) – C:\WINDOWS\system32\drivers\aksfridge.sys (Aladdin Knowledge Systems Ltd.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (AC2003) – C:\WINDOWS\system32\drivers\AC2003.sys (ABIT Computer Corp.)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (LHidUsb) – C:\WINDOWS\system32\drivers\LHidUsb.sys (Logitech, Inc.)
DRV - (LHidFlt2) – C:\WINDOWS\system32\drivers\LHidFlt2.Sys (Logitech, Inc.)
DRV - (cmpci) C-Media PCI Audio Driver (WDM) – C:\WINDOWS\system32\drivers\cmaudio.sys (C-Media Inc)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\PfModNT.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.youcansearch.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=ZUGO&form;=ZGAPHP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:61717

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:1.20.00
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.4
FF - prefs.js..keyword.URL: "http://www.startnow.com/s/?src=addrbar&provider;=Bing&provider;_code=Z059&partner;_id=308&product;_id=435&affiliate;_id=&channel;=rjacs&toolbar;_id=200&toolbar;_version=2.0&install;_country=US&install;_date=20110609&user;_guid=037B9461475748468AC505B1A1ADC95C&machine;_id=03635ec99fd02b4eb43fe447401925e9&browser;=FF&os;=win&os;_version=5.1-x86-SP3&q;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 61717
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/23 21:26:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/09 18:44:36 | 000,000,000 | —D | M]

[2011/01/04 18:20:16 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ron Lambdin\Application Data\Mozilla\Extensions
[2011/06/23 21:27:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ron Lambdin\Application Data\Mozilla\Firefox\Profiles\6ohojrpq.default\extensions
[2011/01/06 16:57:31 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Ron Lambdin\Application Data\Mozilla\Firefox\Profiles\6ohojrpq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/23 21:27:00 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Documents and Settings\Ron Lambdin\Application Data\Mozilla\Firefox\Profiles\6ohojrpq.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/06/04 19:21:53 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\Ron Lambdin\Application Data\Mozilla\Firefox\Profiles\6ohojrpq.default\extensions\[removed]
[2011/06/08 21:21:32 | 000,002,264 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Mozilla\Firefox\Profiles\6ohojrpq.default\searchplugins\bing-zugo.xml
[2011/06/09 15:45:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/01 20:38:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/09 15:45:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2008/11/07 01:35:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\App\Photoshop\Plug-ins\Extensions
File not found (No name found) –
[2011/06/09 15:44:48 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/06/23 21:26:07 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/06/09 15:44:47 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/06/23 21:26:01 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/06/26 00:54:57 | 000,006,514 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.virustotal.com
O1 - Hosts: 127.0.0.1 www.bitdefender.com
O1 - Hosts: 127.0.0.1 www.virusscan.jotti.org
O1 - Hosts: 127.0.0.1 www.vscan.novirusthanks.org
O1 - Hosts: 127.0.0.1 www.virustotal.com
O1 - Hosts: 127.0.0.1 www.bitdefender.com
O1 - Hosts: 127.0.0.1 www.virusscan.jotti.org
O1 - Hosts: 127.0.0.1 www.vscan.novirusthanks.org
O1 - Hosts: 127.0.0.1 http://rsbots.net/
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: 127.0.0.1 www.virustotal.com
O1 - Hosts: 127.0.0.1 www.bitdefender.com
O1 - Hosts: 127.0.0.1 www.virusscan.jotti.org
O1 - Hosts: 127.0.0.1 www.vscan.novirusthanks.org
O1 - Hosts: 127.0.0.1 http://rsbots.net/
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: 127.0.0.1 www.virustotal.com
O1 - Hosts: 127.0.0.1 www.bitdefender.com
O1 - Hosts: 127.0.0.1 www.virusscan.jotti.org
O1 - Hosts: 127.0.0.1 www.vscan.novirusthanks.org
O1 - Hosts: 249 more lines…
O2 - BHO: (Browser Enhancer) - {86ef8bd1-47f3-4322-923f-f29cdf477eb0} - C:\Program Files\CAJ Media\Browser Enhancer\adxloader.dll ()
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers\YontooIEClient.dll (Yontoo Technology, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Logitech Utility] C:\WINDOWS\LOGI_MWX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.exe (Creative Technology Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} http://www.instantaction.com/download/iaplayer.cab (InstantAction Game Launcher)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (EXPLORER.EXE) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Ron Lambdin\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ron Lambdin\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/25 13:53:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/26 00:53:24 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Ron Lambdin\Desktop\HiJackThis.exe
[2011/06/26 00:37:00 | 000,579,072 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Ron Lambdin\Desktop\OTL.exe
[2011/06/21 20:24:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spotmau
[2011/06/21 20:24:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\spotmau
[2011/06/21 20:24:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\pc health check
[2011/06/21 20:23:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TuneUp360
[2011/06/21 20:22:35 | 000,000,000 | —D | C] – C:\Program Files\TuneUp360
[2011/06/21 20:19:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\RegistryKeys
[2011/06/18 16:01:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\MouseWare
[2011/06/18 15:05:53 | 000,104,960 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\COMNCTR.DLL
[2011/06/18 15:05:53 | 000,098,304 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\LGUICOM.DLL
[2011/06/18 15:05:53 | 000,016,896 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\LMOUSE32.DLL
[2011/06/18 15:05:53 | 000,003,568 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\LMOUSE16.DLL
[2011/06/18 15:05:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Logitech
[2011/06/18 15:05:52 | 000,019,968 | —- | C] (Logitech Inc.) – C:\WINDOWS\LOGI_MWX.EXE
[2011/06/18 15:05:52 | 000,000,000 | —D | C] – C:\Program Files\MouseWare
[2011/06/18 15:05:51 | 000,152,064 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\lmoufrc.dll
[2011/06/18 15:05:51 | 000,073,134 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LMouFlt2.Sys
[2011/06/18 15:05:51 | 000,053,870 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\L8042PR2.SYS
[2011/06/18 15:05:51 | 000,037,804 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LHidUsb.sys
[2011/06/18 15:05:51 | 000,025,214 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LHidFlt2.Sys
[2011/06/18 15:05:51 | 000,023,372 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\LCOINST.DLL
[2011/06/18 15:05:51 | 000,014,348 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LCCFLTR.SYS
[2011/06/18 15:05:27 | 000,000,000 | —D | C] – C:\SWSetup
[2011/06/18 15:02:59 | 000,090,112 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\Updreg.exe
[2011/06/18 14:58:51 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mfcans32.dll
[2011/06/18 14:58:51 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mfcuia32.dll
[2011/06/18 14:58:51 | 000,084,992 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\sfcvrt32.dll
[2011/06/18 14:58:51 | 000,082,432 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\ctwflt32.dll
[2011/06/18 14:58:51 | 000,026,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ctl3d.dll
[2011/06/18 14:58:50 | 000,053,552 | —- | C] (Creative® Technology Ltd.) – C:\WINDOWS\ctccw.dll
[2011/06/18 14:58:50 | 000,034,816 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\CTRes32.dll
[2011/06/18 14:58:50 | 000,024,976 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\ctres.dll
[2011/06/18 14:55:32 | 000,000,000 | —D | C] – C:\NVIDIA
[2011/06/18 14:54:30 | 000,018,432 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\Audiohq.cpl
[2011/06/18 14:54:30 | 000,003,584 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\Ahqcpres.dll
[2011/06/18 14:54:07 | 000,000,000 | —D | C] – C:\Media
[2011/06/18 14:54:04 | 000,055,808 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CtMp3.Crl
[2011/06/18 14:54:04 | 000,025,088 | —- | C] (Creative Technology Ltd) – C:\WINDOWS\System32\CTSVCCTL.EXE
[2011/06/18 14:53:20 | 000,307,200 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CtMp3Lib.dll
[2011/06/18 14:53:20 | 000,012,288 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTNMSP.crl
[2011/06/18 14:53:19 | 000,105,984 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\ctmp3io2.dll
[2011/06/18 14:53:19 | 000,006,656 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTMP3io2.crl
[2011/06/18 14:53:17 | 000,106,496 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\Video.skn
[2011/06/18 14:53:16 | 000,278,528 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTMedEng.dll
[2011/06/18 14:53:16 | 000,228,352 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTDetect.cpl
[2011/06/18 14:53:16 | 000,057,856 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTDetres.dll
[2011/06/18 14:53:16 | 000,028,672 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTIntRes.dll
[2011/06/18 14:53:16 | 000,024,576 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTMERes.DLL
[2011/06/18 14:53:15 | 000,098,304 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTDrmUI.dll
[2011/06/18 14:53:15 | 000,054,784 | —- | C] (Blue Sky Software Corporation.) – C:\WINDOWS\System32\Inetwh32.dll
[2011/06/18 14:53:15 | 000,012,288 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTDrmRes.dll
[2011/06/18 14:52:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Creative
[2011/06/18 14:52:38 | 000,006,752 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\PfModNT.sys
[2011/06/18 14:52:38 | 000,000,000 | —D | C] – C:\Program Files\Creative
[2011/06/18 14:52:37 | 000,306,688 | —- | C] (InstallShield Software Corporation) – C:\WINDOWS\IsUninst.exe
[2011/06/18 14:50:25 | 000,000,000 | —D | C] – C:\Compaq
[2011/06/18 14:42:35 | 000,000,000 | —D | C] – C:\Downloads
[2011/06/18 14:41:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Device Doctor
[2011/06/18 14:41:20 | 000,000,000 | —D | C] – C:\Program Files\Device Doctor
[2011/06/18 14:41:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\Device Doctor
[2011/06/18 14:38:04 | 000,000,000 | —D | C] – C:\Program Files\Downloaded Installers
[2011/06/18 14:33:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Local Settings\Application Data\SlimWare Utilities Inc
[2011/06/18 14:32:32 | 000,000,000 | —D | C] – C:\Program Files\DriverUpdate
[2011/06/18 14:23:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\FixCleaner
[2011/06/18 14:23:11 | 000,000,000 | —D | C] – C:\Program Files\FixCleaner
[2011/06/16 16:01:09 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/15 22:32:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\My Documents\sqljdbc_3.0
[2011/06/15 22:15:55 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2011/06/09 15:46:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/06/09 15:45:03 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/06/09 15:45:02 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/06/09 15:45:02 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/06/09 15:45:02 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/06/08 21:21:37 | 000,000,000 | —D | C] – C:\Program Files\FrostWire
[2011/06/08 21:21:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Start Menu\Programs\FrostWire
[2011/06/08 20:50:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\IObit
[2011/06/08 19:03:01 | 000,000,000 | —D | C] – C:\WINDOWS\System32\WindowsPowerShell
[2011/06/08 19:03:00 | 000,000,000 | —D | C] – C:\WINDOWS\System32\winrm
[2011/06/08 19:03:00 | 000,000,000 | —D | C] – C:\WINDOWS\System32\GroupPolicy
[2011/06/08 19:02:45 | 000,000,000 | -H-D | C] – C:\WINDOWS\$968930Uinstall_KB968930$
[2011/06/08 18:29:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\IObit
[2011/06/08 18:29:32 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/06/08 17:53:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\DriverCure
[2011/06/08 17:53:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\ParetoLogic
[2011/06/08 17:53:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/06/04 22:44:37 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Ron Lambdin\Recent
[2011/06/04 19:31:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\SUPERAntiSpyware.com
[2011/06/04 19:31:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/06/04 19:31:19 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/06/04 19:21:55 | 000,000,000 | —D | C] – C:\Program Files\uTorrentBar
[2011/06/04 19:21:46 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2011/06/04 19:21:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\uTorrent
[2011/06/04 01:04:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\My Documents\Add-in Express
[2011/06/03 18:31:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/05/30 21:00:23 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/26 10:36:01 | 000,000,129 | —- | M] () – C:\Documents and Settings\Ron Lambdin\jagex_runescape_preferences2.dat
[2011/06/26 10:28:32 | 001,474,832 | —- | M] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/06/26 10:19:30 | 000,000,034 | —- | M] () – C:\Documents and Settings\Ron Lambdin\jagex_runescape_preferences.dat
[2011/06/26 10:08:51 | 000,131,129 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/06/26 10:08:43 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/06/26 10:08:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/06/26 00:58:28 | 000,001,002 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-1425521274-725345543-1004UA.job
[2011/06/26 00:54:57 | 000,006,514 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/06/26 00:53:26 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Ron Lambdin\Desktop\HiJackThis.exe
[2011/06/26 00:37:04 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Ron Lambdin\Desktop\OTL.exe
[2011/06/25 20:22:00 | 000,000,290 | —- | M] () – C:\WINDOWS\tasks\TuneUp360 Reminder.job
[2011/06/25 20:18:25 | 000,002,283 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2011/06/25 14:35:19 | 000,013,736 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/06/21 20:30:59 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/06/21 18:42:00 | 000,000,268 | —- | M] () – C:\WINDOWS\tasks\defrag.job
[2011/06/21 09:58:00 | 000,000,950 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-1425521274-725345543-1004Core.job
[2011/06/20 18:40:00 | 000,000,272 | —- | M] () – C:\WINDOWS\tasks\Disk Cleanup.job
[2011/06/18 15:03:48 | 000,000,130 | —- | M] () – C:\WINDOWS\SBWIN.INI
[2011/06/18 14:54:07 | 000,000,924 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\Creative PlayCenter 2.lnk
[2011/06/18 14:53:45 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/06/16 16:01:09 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/15 22:34:56 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/06/15 21:41:49 | 000,493,738 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/06/15 21:41:49 | 000,084,282 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/06/14 23:59:26 | 000,002,350 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Desktop\Google Chrome.lnk
[2011/06/09 15:44:47 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/06/09 15:44:47 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/06/09 15:44:47 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/06/09 15:44:47 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/06/09 15:44:47 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/06/09 12:52:13 | 005,767,168 | -H– | M] () – C:\Documents and Settings\Ron Lambdin\NTUSER.bak
[2011/06/09 03:22:13 | 000,102,232 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/06/08 21:21:37 | 000,000,533 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire.lnk
[2011/06/08 21:13:11 | 000,002,171 | —- | M] () – C:\Documents and Settings\Ron Lambdin\.recently-used.xbel
[2011/06/04 19:21:47 | 000,000,656 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/05/31 16:36:47 | 000,001,550 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/05/30 20:52:24 | 000,005,632 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/30 18:19:48 | 005,964,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/21 20:23:47 | 000,000,290 | —- | C] () – C:\WINDOWS\tasks\TuneUp360 Reminder.job
[2011/06/18 14:58:51 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\sfman.dat
[2011/06/18 14:58:50 | 000,000,231 | —- | C] () – C:\WINDOWS\ac3api.ini
[2011/06/18 14:57:08 | 002,259,067 | —- | C] () – C:\WINDOWS\System32\DEFAULT.ECW
[2011/06/18 14:55:06 | 000,000,130 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2011/06/18 14:54:07 | 000,000,924 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\Creative PlayCenter 2.lnk
[2011/06/18 14:52:40 | 000,000,227 | —- | C] () – C:\WINDOWS\SYSTEM.I~I
[2011/06/18 09:52:39 | 000,002,350 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Desktop\Google Chrome.lnk
[2011/06/15 23:42:57 | 000,000,268 | —- | C] () – C:\WINDOWS\tasks\defrag.job
[2011/06/15 23:41:25 | 000,000,272 | —- | C] () – C:\WINDOWS\tasks\Disk Cleanup.job
[2011/06/15 21:52:18 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/06/08 21:21:37 | 000,000,533 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire.lnk
[2011/06/08 21:13:11 | 000,002,171 | —- | C] () – C:\Documents and Settings\Ron Lambdin\.recently-used.xbel
[2011/06/08 19:07:19 | 000,225,262 | —- | C] () – C:\WINDOWS\System32\dllcache\msimain.sdb
[2011/06/08 18:32:09 | 000,000,282 | —- | C] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/06/04 19:21:47 | 000,000,656 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/05/31 17:06:08 | 000,002,283 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2011/05/31 16:36:47 | 000,001,550 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/05/22 12:33:37 | 000,616,960 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\unenhetah.exe
[2011/05/14 14:17:25 | 000,000,053 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\RSBot_Accounts.ini
[2011/02/27 11:03:33 | 000,708,858 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\data.dat
[2011/02/23 17:17:13 | 001,474,832 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/02/11 17:41:28 | 000,022,558 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\F446.28D
[2011/01/04 20:06:58 | 000,015,752 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/01/04 18:20:02 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/11/15 20:39:18 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2010/10/01 23:09:29 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/09/04 19:43:51 | 000,137,688 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/09/04 19:43:45 | 000,202,040 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/09/04 19:43:11 | 000,066,872 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2009/07/04 00:05:00 | 000,000,155 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/07/03 23:51:08 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2009/05/06 17:25:17 | 000,005,632 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/25 23:53:41 | 000,000,888 | —- | C] () – C:\WINDOWS\my.ini
[2009/04/25 23:35:24 | 000,000,025 | —- | C] () – C:\WINDOWS\mixerdef.ini
[2009/04/25 17:50:24 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2009/04/25 15:29:23 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2009/04/25 14:20:09 | 001,657,376 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2009/04/25 14:20:08 | 001,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/04/25 14:20:07 | 001,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2009/04/25 14:20:02 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2009/04/25 14:19:56 | 001,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2009/04/25 14:19:55 | 001,346,080 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2009/04/25 14:19:47 | 000,449,056 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2009/04/25 14:19:43 | 000,436,768 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2009/04/25 14:00:41 | 000,155,648 | R— | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2009/04/25 14:00:34 | 000,001,136 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2009/04/25 13:55:30 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/04/25 13:51:23 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/04/25 08:46:31 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/04/25 08:45:28 | 000,102,232 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2006/02/28 08:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/28 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/28 08:00:00 | 000,493,738 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/28 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/28 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/28 08:00:00 | 000,084,282 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/28 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/28 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/28 08:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/28 08:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/28 08:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/28 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/12/29 03:18:03 | 000,040,103 | -H– | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\Ron Lambdinlog.dat
[2002/11/19 16:46:20 | 000,039,104 | —- | C] () – C:\WINDOWS\cmijack.dat
[2002/11/19 16:43:38 | 000,022,178 | —- | C] () – C:\WINDOWS\cmaudio.dat

========== LOP Check ==========

[2010/09/21 01:44:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\.minecraft
[2010/09/20 02:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\.minecraft server
[2009/09/04 21:15:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Blue Orb
[2011/06/08 20:50:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2011/06/08 18:28:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/06/21 20:37:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pc health check
[2011/06/21 20:24:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spotmau
[2011/05/24 16:45:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SwiftKit
[2011/04/16 20:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2011/05/26 16:00:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/06/21 20:37:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp360
[2011/04/30 22:06:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2011/04/15 23:14:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WindSolutions
[2010/12/09 17:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/04/21 17:03:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\.minecraft
[2010/09/20 02:22:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\.minecraft server
[2011/02/15 17:25:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\BitZipper
[2011/06/18 17:33:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\CoreInternetUtility
[2011/06/19 18:48:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\Device Doctor
[2011/06/08 17:53:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\DriverCure
[2011/06/18 14:30:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\FixCleaner
[2011/06/08 21:13:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\FrostWire
[2009/09/04 21:13:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\GarageGames
[2011/05/16 18:46:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\gtk-2.0
[2011/06/08 18:30:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\IObit
[2010/09/18 04:44:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\LolClient
[2011/06/08 17:53:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\ParetoLogic
[2011/06/21 20:19:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\RegistryKeys
[2011/06/21 20:24:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\spotmau
[2011/05/17 19:19:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\TeamViewer
[2011/06/04 18:58:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\Uniblue
[2011/06/23 16:25:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\uTorrent
[2011/05/22 18:31:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\WinDir
[2011/04/15 23:14:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Ron Lambdin\Application Data\WindSolutions
[2011/06/26 10:08:43 | 000,000,282 | —- | M] () – C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2011/06/21 18:42:00 | 000,000,268 | —- | M] () – C:\WINDOWS\Tasks\defrag.job
[2011/06/20 18:40:00 | 000,000,272 | —- | M] () – C:\WINDOWS\Tasks\Disk Cleanup.job
[2011/06/25 20:22:00 | 000,000,290 | —- | M] () – C:\WINDOWS\Tasks\TuneUp360 Reminder.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/04/25 13:53:40 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/06/21 20:30:59 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/04/25 13:53:40 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/04/25 13:53:40 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/04/25 13:53:40 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/11/23 19:36:20 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/06/26 10:08:35 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/04/25 13:53:18 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/06/03 20:12:01 | 000,001,538 | -H– | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/04/25 08:44:36 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/04/25 08:44:36 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/04/25 08:44:36 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/11/23 19:40:50 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/04/25 13:57:30 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/06/26 00:53:26 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Ron Lambdin\Desktop\HiJackThis.exe
[2011/05/23 19:39:27 | 000,270,142 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Desktop\Minecraft.exe
[2011/06/26 00:37:04 | 000,579,072 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Ron Lambdin\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-20 03:48:57

========== Alternate Data Streams ==========

@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:42DC4246

< End of report >

Extras.Txt File

OTL Extras logfile created on: 6/26/2011 10:34:35 AM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Ron Lambdin\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.12 Gb Available Physical Memory | 55.98% Memory free
3.85 Gb Paging File | 2.88 Gb Available in Paging File | 74.88% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 117.97 Gb Free Space | 63.32% Space Free | Partition Type: NTFS

Computer Name: 4SIGHT | User Name: Ron Lambdin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1947:TCP" = 1947:TCP:*:Enabled:HASP SRM
"1947:UDP" = 1947:UDP:*:Enabled:HASP SRM
"8380:TCP" = 8380:TCP:*:Enabled:League of Legends Launcher
"8380:UDP" = 8380:UDP:*:Enabled:League of Legends Launcher
"6968:TCP" = 6968:TCP:*:Enabled:League of Legends Launcher
"6968:UDP" = 6968:UDP:*:Enabled:League of Legends Launcher
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\ArcEmu Blizzlike\ArcEmu\arcemu-logonserver.exe" = C:\ArcEmu Blizzlike\ArcEmu\arcemu-logonserver.exe:*:Enabled:arcemu-logonserver – ()
"C:\ArcEmu Blizzlike\ArcEmu\arcemu-world.exe" = C:\ArcEmu Blizzlike\ArcEmu\arcemu-world.exe:*:Enabled:arcemu-world – ()
"C:\Program Files\Call of Duty 4 - Modern Warfare\iw3mp.exe" = C:\Program Files\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:iw3mp – ()
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire – (PortableApps.com)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\TeamViewer\Version6\TeamViewer.exe" = C:\Program Files\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application – (TeamViewer GmbH)
"C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe" = C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service – (TeamViewer GmbH)
"C:\Documents and Settings\Ron Lambdin\Application Data\unenhetah.exe" = C:\Documents and Settings\Ron Lambdin\Application Data\unenhetah.exe:*:Enabled:Windows Messanger – ()
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{23E4A9D2-3C02-4BFC-B9BA-6CA6180568EF}" = Browser Enhancer
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 26
"{28999392-5871-4A39-863A-D2A6EA3260AF}" = League of Legends
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = MouseWare 9.76
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers 1.10.01
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FD8E178D-8B4E-42DA-B434-EFF270329B1C}" = COMODO Internet Security
"7-Zip" = 7-Zip 9.20
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"CCleaner" = CCleaner
"COMODO GeekBuddy" = COMODO GeekBuddy
"Device Doctor_is1" = Device Doctor v1.0
"EPSON Printer and Utilities" = EPSON Logiciel imprimante
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NeroVision!UninstallKey" = NeroVision Express 2
"NMPUninstallKey" = Nero Media Player
"NVIDIA Drivers" = NVIDIA Drivers
"PCI Audio Driver" = PCI Audio Driver
"Plants vs. Zombies" = Plants vs. Zombies
"Sound Blaster Live!" = Sound Blaster Live!
"Steam App 105600" = Terraria
"Steam App 220" = Half-Life 2
"Steam App 340" = Half-Life 2: Lost Coast
"Steam App 4000" = Garry's Mod
"TeamViewer 6" = TeamViewer 6
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"WinGimp-2.0_is1" = GIMP 2.6.11
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"SwiftKit" = SwiftKit

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/16/2011 10:20:04 PM | Computer Name = 4SIGHT | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 1.9.2.3989, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.

Error - 1/16/2011 11:08:20 PM | Computer Name = 4SIGHT | Source = Application Hang | ID = 1002
Description = Hanging application gimp-2.6.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/17/2011 4:57:14 PM | Computer Name = 4SIGHT | Source = Application Hang | ID = 1002
Description = Hanging application gimp-2.6.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/17/2011 8:40:07 PM | Computer Name = 4SIGHT | Source = Application Hang | ID = 1002
Description = Hanging application gimp-2.6.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/18/2011 9:01:14 PM | Computer Name = 4SIGHT | Source = Application Hang | ID = 1002
Description = Hanging application gimp-2.6.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/22/2011 9:55:20 PM | Computer Name = 4SIGHT | Source = Application Hang | ID = 1002
Description = Hanging application gimp-2.6.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/22/2011 9:55:22 PM | Computer Name = 4SIGHT | Source = Application Hang | ID = 1002
Description = Hanging application gimp-2.6.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/28/2011 5:18:36 PM | Computer Name = 4SIGHT | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3989, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/28/2011 5:18:38 PM | Computer Name = 4SIGHT | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3989, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 3/6/2011 6:16:19 PM | Computer Name = 4SIGHT | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 6/22/2011 1:06:35 PM | Computer Name = 4SIGHT | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service iPod Service
with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}

Error - 6/22/2011 3:54:26 PM | Computer Name = 4SIGHT | Source = Service Control Manager | ID = 7000
Description = The HASP License Manager service failed to start due to the following
error: %%3

Error - 6/22/2011 5:43:42 PM | Computer Name = 4SIGHT | Source = Service Control Manager | ID = 7000
Description = The HASP License Manager service failed to start due to the following
error: %%3

Error - 6/23/2011 2:43:38 PM | Computer Name = 4SIGHT | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.4 for the Network Card with network
address 00508DCAD2F3 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 6/23/2011 2:43:43 PM | Computer Name = 4SIGHT | Source = Service Control Manager | ID = 7000
Description = The HASP License Manager service failed to start due to the following
error: %%3

Error - 6/23/2011 11:31:02 PM | Computer Name = 4SIGHT | Source = Service Control Manager | ID = 7000
Description = The HASP License Manager service failed to start due to the following
error: %%3

Error - 6/24/2011 2:24:24 PM | Computer Name = 4SIGHT | Source = Service Control Manager | ID = 7000
Description = The HASP License Manager service failed to start due to the following
error: %%3

Error - 6/25/2011 2:35:24 PM | Computer Name = 4SIGHT | Source = Service Control Manager | ID = 7000
Description = The HASP License Manager service failed to start due to the following
error: %%3

Error - 6/26/2011 10:08:41 AM | Computer Name = 4SIGHT | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.5 for the Network Card with network
address 00508DCAD2F3 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 6/26/2011 10:08:46 AM | Computer Name = 4SIGHT | Source = Service Control Manager | ID = 7000
Description = The HASP License Manager service failed to start due to the following
error: %%3


< End of report >

Hijackthis Scan Results

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:39:38 AM, on 6/26/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\ArcEmu Blizzlike\Server\mysql\bin\mysqld-nt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MouseWare\system\em_exec.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Ron Lambdin\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=ZUGO&form;=ZGAPHP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youcansearch.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:61717
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: # Copyright © 1993-1999 Microsoft Corp.
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O1 - Hosts: http://www.rsbots.net/
O1 - Hosts: rsbots.net
O1 - Hosts: www.rsbots.net
O2 - BHO: Browser Enhancer - {86ef8bd1-47f3-4322-923f-f29cdf477eb0} - C:\Program Files\CAJ Media\Browser Enhancer\adxloader.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers\YontooIEClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Ron Lambdin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} (InstantAction Game Launcher) - http://www.instantaction.com/download/iaplayer.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: HASP License Manager (hasplms) - Unknown owner - (no file)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: mysql - Unknown owner - C:\ArcEmu.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: TuneUp360Mon - Unknown owner - C:\Program Files\TuneUp360\TuneUp360Mon.exe (file missing)

–
End of file - 7982 bytes

DDS Scan Results


DDS.Txt File
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 10:40:50.34 on Sun 06/26/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bing.com/?pc=ZUGO&form;=ZGAPHP
mStart Page = hxxp://www.youcansearch.com
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:61717
BHO: Browser Enhancer: {86ef8bd1-47f3-4322-923f-f29cdf477eb0} - c:\program files\caj media\browser enhancer\adxloader.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers\YontooIEClient.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Google Update] "c:\documents and settings\ron lambdin\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [UpdReg] c:\windows\Updreg.exe
mRun: [AHQInit] c:\program files\creative\sblive\program\AHQInit.exe
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
uPolicies-explorer: =
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} - hxxp://www.instantaction.com/download/iaplayer.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
AppInit_DLLs: c:\windows\system32\guard32.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\ronlam~1\applic~1\mozilla\firefox\profiles\6ohojrpq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.startnow.com/s/?src=addrbar&provider;=Bing&provider;_code=Z059&partner;_id=308&product;_id=435&affiliate;_id=&channel;=rjacs&toolbar;_id=200&toolbar;_version=2.0&install;_country=US&install;_date=20110609&user;_guid=037B9461475748468AC505B1A1ADC95C&machine;_id=03635ec99fd02b4eb43fe447401925e9&browser;=FF&os;=win&os;_version=5.1-x86-SP3&q;=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 61717
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\ron lambdin\local settings\application data\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2011-06-24 01:26:07 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2011-06-24 01:26:06 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll
2011-06-22 00:24:30 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spotmau
2011-06-22 00:24:10 ——– d—–w- c:\docume~1\ronlam~1\applic~1\spotmau
2011-06-22 00:24:08 ——– d—–w- c:\docume~1\alluse~1\applic~1\pc health check
2011-06-22 00:23:45 ——– d—–w- c:\docume~1\alluse~1\applic~1\TuneUp360
2011-06-22 00:22:35 ——– d—–w- c:\program files\TuneUp360
2011-06-22 00:19:12 ——– d—–w- c:\docume~1\ronlam~1\applic~1\RegistryKeys
2011-06-18 19:02:59 90112 —-a-w- c:\windows\Updreg.exe
2011-06-18 18:58:51 84992 —-a-w- c:\windows\system32\sfcvrt32.dll
2011-06-18 18:58:51 82432 —-a-w- c:\windows\system32\ctwflt32.dll
2011-06-18 18:58:51 26768 —-a-w- c:\windows\system32\ctl3d.dll
2011-06-18 18:58:51 149504 —-a-w- c:\windows\system32\mfcans32.dll
2011-06-18 18:58:51 108032 —-a-w- c:\windows\system32\mfcuia32.dll
2011-06-18 18:58:50 53552 —-a-w- c:\windows\ctccw.dll
2011-06-18 18:58:50 34816 —-a-w- c:\windows\CTRes32.dll
2011-06-18 18:58:50 24976 —-a-w- c:\windows\ctres.dll
2011-06-18 18:57:53 ——– d—–w- c:\windows\NV24481612.TMP
2011-06-18 18:55:32 ——– d—–w- C:\NVIDIA
2011-06-18 18:54:30 3584 —-a-w- c:\windows\system32\Ahqcpres.dll
2011-06-18 18:54:30 18432 —-a-w- c:\windows\system32\Audiohq.cpl
2011-06-18 18:54:07 ——– d—–w- C:\Media
2011-06-18 18:54:04 55808 —-a-w- c:\windows\system32\CtMp3.Crl
2011-06-18 18:54:04 44032 —-a-w- c:\windows\system32\CTSVCCDA.EXE
2011-06-18 18:54:04 25088 —-a-w- c:\windows\system32\CTSVCCTL.EXE
2011-06-18 18:52:38 6752 —-a-w- c:\windows\system32\PfModNT.sys
2011-06-18 18:52:38 ——– d—–w- c:\program files\Creative
2011-06-18 18:52:37 306688 —-a-w- c:\windows\IsUninst.exe
2011-06-18 18:50:25 ——– d—–w- C:\Compaq
2011-06-18 18:42:35 ——– d—–w- C:\Downloads
2011-06-18 18:41:20 ——– d—–w- c:\program files\Device Doctor
2011-06-18 18:41:20 ——– d—–w- c:\docume~1\ronlam~1\applic~1\Device Doctor
2011-06-18 18:38:04 ——– d—–w- c:\program files\Downloaded Installers
2011-06-18 18:33:03 ——– d—–w- c:\docume~1\ronlam~1\locals~1\applic~1\SlimWare Utilities Inc
2011-06-18 18:32:32 ——– d—–w- c:\program files\DriverUpdate
2011-06-18 18:23:23 ——– d—–w- c:\docume~1\ronlam~1\applic~1\FixCleaner
2011-06-18 18:23:11 ——– d—–w- c:\program files\FixCleaner
2011-06-16 20:01:09 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-16 02:15:55 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-06-09 19:45:03 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-06-09 01:21:37 ——– d—–w- c:\program files\FrostWire
2011-06-09 00:50:08 ——– d—–w- c:\docume~1\alluse~1\applic~1\IObit
2011-06-08 23:03:00 ——– d—–w- c:\windows\system32\winrm
2011-06-08 23:03:00 ——– d—–w- c:\windows\system32\GroupPolicy
2011-06-08 23:02:45 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
2011-06-08 22:29:52 ——– d—–w- c:\docume~1\ronlam~1\applic~1\IObit
2011-06-08 22:29:32 ——– d—–w- c:\program files\IObit
2011-06-08 21:53:49 ——– d—–w- c:\docume~1\ronlam~1\applic~1\DriverCure
2011-06-08 21:53:45 ——– d—–w- c:\docume~1\ronlam~1\applic~1\ParetoLogic
2011-06-08 21:53:11 ——– d—–w- c:\docume~1\alluse~1\applic~1\ParetoLogic
2011-06-04 23:31:25 ——– d—–w- c:\docume~1\ronlam~1\applic~1\SUPERAntiSpyware.com
2011-06-04 23:31:19 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-06-04 23:21:55 ——– d—–w- c:\program files\uTorrentBar
2011-06-04 23:21:46 ——– d—–w- c:\program files\uTorrent
2011-06-04 23:21:19 ——– d—–w- c:\docume~1\ronlam~1\applic~1\uTorrent
2011-06-03 22:31:36 ——– d—–w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2011-05-31 01:00:23 ——– d—–w- c:\program files\VideoLAN
.
==================== Find3M ====================
.
2011-06-09 19:44:47 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-05-22 16:33:40 616960 —-a-w- c:\docume~1\ronlam~1\applic~1\unenhetah.exe
2011-05-13 00:30:54 284744 —-a-w- c:\windows\system32\guard32.dll
2011-05-02 15:31:52 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-25 16:11:12 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11:11 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11:11 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01:22 385024 —-a-w- c:\windows\system32\html.iec
.
============= FINISH: 10:41:29.21 ===============

Attach.Txt File

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
.
==== Disk Partitions =========================
.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Hosts File Hijack ======================
.
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
Hosts: 127.0.0.1 www.virustotal.com
Hosts: 127.0.0.1 www.bitdefender.com
.
==== Installed Programs ======================
.
µTorrent
7-Zip 9.20
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Apple Application Support
Apple Software Update
Bonjour
Browser Enhancer
CCleaner
COMODO GeekBuddy
COMODO Internet Security
Device Doctor v1.0
EPSON Logiciel imprimante
Garry's Mod
GIMP 2.6.11
Google Chrome
Half-Life 2
Half-Life 2: Lost Coast
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
iTunes
Java Auto Updater
Java™ 6 Update 26
League of Legends
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft XNA Framework Redistributable 4.0
MouseWare 9.76
Mozilla Firefox 4.0.1 (x86 en-US)
MSXML 6 Service Pack 2 (KB973686)
Nero Media Player
Nero OEM
NeroVision Express 2
NVIDIA Drivers
NVIDIA PhysX
PCI Audio Driver
Plants vs. Zombies
QuickTime
Realtek AC'97 Audio
REALTEK GbE & FE Ethernet PCI-E NIC Driver
REALTEK GbE & FE Ethernet PCI NIC Driver
REALTEK Gigabit and Fast Ethernet NIC Driver
Safari
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB923789)
Skype™ 5.3
Sound Blaster Live!
Steam
SUPERAntiSpyware
SwiftKit
TeamViewer 6
Terraria
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB982632)
uTorrentBar Toolbar
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Management Framework Core
XML Paper Specification Shared Components Pack 1.0
Yontoo Layers 1.10.01
.
==== End Of File ===========================


Those are the scan results from the three programs suggested to be used on this site.
I hope you can get back to me within today, And help fix my computer. Thanks!
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post






Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:61717
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.youcansearch.com
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    
    
    :Commands
    [emptytemp]
    [RESETHOSTS]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )











Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
OTL File

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 204952 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 15364773 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Ron Lambdin
->Temp folder emptied: 99603327 bytes
->Temporary Internet Files folder emptied: 25643634 bytes
->Java cache emptied: 8179674 bytes
->FireFox cache emptied: 88379623 bytes
->Google Chrome cache emptied: 109163338 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 6471 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 90709 bytes
%systemroot%\System32 .tmp files removed: 6172032 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 29094288 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 113265204 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 23610853 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 495.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.24.1 log created on 06282011_142424

Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot.

Registry entries deleted on Reboot…


With the Combofix, it didn't work as it should. I disabled all Firewalls/AntiVirus Programs, and while downloading the File it would stop at Output Folder: C:\32788R22FWJFW. Not exactly sure what folder that is in my Hardrive either. So I need help with this, any suggestions on how to fix this please.
Leave Combofix for now,run these two scans.




Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please










Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Malware Scan Results

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6705

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

6/29/2011 11:03:51 PM
mbam-log-2011-06-29 (23-03-51).txt

Scan type: Quick scan
Objects scanned: 151829
Time elapsed: 6 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 3
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D1EC4CA-4B92-4324-B8F8-C9A6ED06A8AE} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Windows Firewall (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\bak_XMLLookup (Hijacker.XMLLookup) -> Value: bak_XMLLookup -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\bak_Application (Hijacker.Application) -> Value: bak_Application -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\bak_intl (Hijacker.intl) -> Value: bak_intl -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\XMLLookup (Hijacker.XMLLookup) -> Bad: (http://www.helpmeopen.com/?n=app&l=%04x&ext=%s) Good: (http://shell.windows.com/fileassoc/fileassoc.asp?LangID=%04x&Ext=%s) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\Application (Hijacker.Application) -> Bad: (http://www.helpmeopen.com/?n=app&l=%04x&ext=%s) Good: (http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\intl (Hijacker.intl) -> Bad: (http://www.helpmeopen.com/?n=app&l=%04x&ext=%s) Good: (http://shell.windows.com/fileassoc/fileassoc.asp?LangID=%04x&Ext=%s) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\ron lambdin\application data\data.dat (Stolen.Data) -> Quarantined and deleted successfully.


As for the Eset Online Scanner, it wouldn't let me download it again. It would say can't configure proxy setting when downloading the program, and I tried various ways to fix it, but couldn't find a way to run it properly.
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    FF - prefs.js..network.proxy.http: "127.0.0.1"
    FF - prefs.js..network.proxy.http_port: 61717
    FF - prefs.js..network.proxy.type: 0
    
    :files
    ipconfig /flushdns /c
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )







After this please rescan with OTL and post the new log.Also update malwarebytes as the database you have is outdated and rescan,then try ESET again.
OTL Scan

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Prefs.js: "127.0.0.1" removed from network.proxy.http
Prefs.js: 61717 removed from network.proxy.http_port
Prefs.js: 0 removed from network.proxy.type
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Ron Lambdin\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Ron Lambdin\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Ron Lambdin
->Temp folder emptied: 39393887 bytes
->Temporary Internet Files folder emptied: 2127169 bytes
->Java cache emptied: 175682 bytes
->FireFox cache emptied: 75383138 bytes
->Google Chrome cache emptied: 312824853 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 1188 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 410.00 mb


OTL by OldTimer - Version 3.2.24.1 log created on 06302011_164751

Files\Folders moved on Reboot…
C:\WINDOWS\temp\hlktmp moved successfully.

Registry entries deleted on Reboot…


I tried updating MalwareBytes, and it went unresponsive everytime I tried. And ESET didn't work, again, it said the same thing as the previous time.
OTL Scan

OTL logfile created on: 7/1/2011 5:12:55 PM - Run 2
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Ron Lambdin\Desktop\Virus Protection St00f
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 70.18% Memory free
3.85 Gb Paging File | 3.38 Gb Available in Paging File | 87.90% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 117.00 Gb Free Space | 62.80% Space Free | Partition Type: NTFS

Computer Name: 4SIGHT | User Name: Ron Lambdin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Ron Lambdin\Desktop\Virus Protection St00f\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\ArcEmu Blizzlike\Server\mysql\bin\mysqld-nt.exe ()
PRC - C:\Program Files\MouseWare\system\EM_EXEC.EXE (Logitech Inc.)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Ron Lambdin\Desktop\Virus Protection St00f\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\guard32.dll (COMODO)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Logitech\Scrolling\LGMSGHK.DLL (Logitech Inc.)
MOD - C:\Program Files\MouseWare\system\LgWndHk.dll (Logitech Inc.)


========== Win32 Services (SafeList) ==========

SRV - (TuneUp360Mon) – File not found
SRV - (hasplms) – File not found
SRV - (AppMgmt) – File not found
SRV - (CLPSLS) – C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe (COMODO)
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (mysql) – C:\ArcEmu Blizzlike\Server\mysql\bin\mysqld-nt.exe ()


========== Driver Services (SafeList) ==========

DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (Inspect) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (cmderd) – C:\WINDOWS\system32\drivers\cmderd.sys (COMODO)
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (aksfridge) – C:\WINDOWS\system32\drivers\aksfridge.sys (Aladdin Knowledge Systems Ltd.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (AC2003) – C:\WINDOWS\system32\drivers\AC2003.sys (ABIT Computer Corp.)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (LHidUsb) – C:\WINDOWS\system32\drivers\LHidUsb.sys (Logitech, Inc.)
DRV - (LHidFlt2) – C:\WINDOWS\system32\drivers\LHidFlt2.Sys (Logitech, Inc.)
DRV - (cmpci) C-Media PCI Audio Driver (WDM) – C:\WINDOWS\system32\drivers\cmaudio.sys (C-Media Inc)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\PfModNT.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=ZUGO&form=ZGAPHP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search (eToolKit)"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:1.20.00
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.4
FF - prefs.js..keyword.URL: "http://www.startnow.com/s/?src=addrbar&provider=Bing&provider_code=Z059&partner_id=308&product_id=435&affiliate_id=&channel=rjacs&toolbar_id=200&toolbar_version=2.0&install_country=US&install_date=20110609&user_guid=037B9461475748468AC505B1A1ADC95C&machine_id=03635ec99fd02b4eb43fe447401925e9&browser=FF&os=win&os_version=5.1-x86-SP3&q="

FF - user.js..browser.search.defaultenginename: "Web Search (eToolKit)"
FF - user.js..browser.search.selectedEngine: "Web Search (eToolKit)"

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/23 21:26:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/09 18:44:36 | 000,000,000 | —D | M]

[2011/01/04 18:20:16 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ron Lambdin\Application Data\Mozilla\Extensions
[2011/06/27 22:43:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ron Lambdin\Application Data\Mozilla\Firefox\Profiles\6ohojrpq.default\extensions
[2011/01/06 16:57:31 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Ron Lambdin\Application Data\Mozilla\Firefox\Profiles\6ohojrpq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/08 21:21:32 | 000,002,264 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Mozilla\Firefox\Profiles\6ohojrpq.default\searchplugins\bing-zugo.xml
[2011/06/09 15:45:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/01 20:38:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/09 15:45:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2008/11/07 01:35:20 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\App\Photoshop\Plug-ins\Extensions
File not found (No name found) –
[2011/06/09 15:44:48 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/06/27 22:33:38 | 000,000,000 | —D | M] (eToolKit Toolbar) – C:\PROGRAM FILES\TOOLKITSERVICE\FFEXT
[2011/06/23 21:26:07 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/06/09 15:44:47 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/06/23 21:26:01 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/06/27 22:33:38 | 000,002,129 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\toolkitsearch.xml

O1 HOSTS File: ([2011/06/28 14:26:11 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Browser Enhancer) - {86ef8bd1-47f3-4322-923f-f29cdf477eb0} - C:\Program Files\CAJ Media\Browser Enhancer\adxloader.dll ()
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers\YontooIEClient.dll (Yontoo Technology, Inc.)
O4 - HKLM..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Logitech Utility] C:\WINDOWS\LOGI_MWX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [tktray] C:\Program Files\ToolKitService\tktray.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} http://www.instantaction.com/download/iaplayer.cab (InstantAction Game Launcher)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (EXPLORER.EXE) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Ron Lambdin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Ron Lambdin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/25 13:53:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/29 23:08:35 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/06/29 22:53:36 | 000,000,000 | —D | C] – C:\0ec5f40f4da7ec12ad0951849c9281
[2011/06/29 22:49:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\Malwarebytes
[2011/06/29 22:49:12 | 000,039,984 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/06/29 22:49:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/29 22:49:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/06/29 22:49:06 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/06/29 22:49:05 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/06/28 14:30:36 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2011/06/28 14:24:24 | 000,000,000 | —D | C] – C:\_OTL
[2011/06/27 22:33:22 | 000,057,152 | —- | C] (Toolkit Development, Ltd.) – C:\WINDOWS\System32\drivers\toolkitdisk.sys
[2011/06/27 22:33:09 | 000,000,000 | —D | C] – C:\Program Files\ToolKitService
[2011/06/21 20:24:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spotmau
[2011/06/21 20:24:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\spotmau
[2011/06/21 20:24:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\pc health check
[2011/06/21 20:23:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TuneUp360
[2011/06/21 20:22:35 | 000,000,000 | —D | C] – C:\Program Files\TuneUp360
[2011/06/21 20:19:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\RegistryKeys
[2011/06/18 16:01:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\MouseWare
[2011/06/18 15:05:53 | 000,104,960 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\COMNCTR.DLL
[2011/06/18 15:05:53 | 000,098,304 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\LGUICOM.DLL
[2011/06/18 15:05:53 | 000,016,896 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\LMOUSE32.DLL
[2011/06/18 15:05:53 | 000,003,568 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\LMOUSE16.DLL
[2011/06/18 15:05:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Logitech
[2011/06/18 15:05:52 | 000,019,968 | —- | C] (Logitech Inc.) – C:\WINDOWS\LOGI_MWX.EXE
[2011/06/18 15:05:52 | 000,000,000 | —D | C] – C:\Program Files\MouseWare
[2011/06/18 15:05:51 | 000,152,064 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\lmoufrc.dll
[2011/06/18 15:05:51 | 000,073,134 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LMouFlt2.Sys
[2011/06/18 15:05:51 | 000,053,870 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\L8042PR2.SYS
[2011/06/18 15:05:51 | 000,037,804 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LHidUsb.sys
[2011/06/18 15:05:51 | 000,025,214 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LHidFlt2.Sys
[2011/06/18 15:05:51 | 000,023,372 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\LCOINST.DLL
[2011/06/18 15:05:51 | 000,014,348 | —- | C] (Logitech, Inc.) – C:\WINDOWS\System32\drivers\LCCFLTR.SYS
[2011/06/18 15:05:27 | 000,000,000 | —D | C] – C:\SWSetup
[2011/06/18 15:02:59 | 000,090,112 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\Updreg.exe
[2011/06/18 14:58:51 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mfcans32.dll
[2011/06/18 14:58:51 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mfcuia32.dll
[2011/06/18 14:58:51 | 000,084,992 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\sfcvrt32.dll
[2011/06/18 14:58:51 | 000,082,432 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\ctwflt32.dll
[2011/06/18 14:58:51 | 000,026,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ctl3d.dll
[2011/06/18 14:58:50 | 000,053,552 | —- | C] (Creative® Technology Ltd.) – C:\WINDOWS\ctccw.dll
[2011/06/18 14:58:50 | 000,034,816 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\CTRes32.dll
[2011/06/18 14:58:50 | 000,024,976 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\ctres.dll
[2011/06/18 14:55:32 | 000,000,000 | —D | C] – C:\NVIDIA
[2011/06/18 14:54:30 | 000,018,432 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\Audiohq.cpl
[2011/06/18 14:54:30 | 000,003,584 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\Ahqcpres.dll
[2011/06/18 14:54:07 | 000,000,000 | —D | C] – C:\Media
[2011/06/18 14:54:04 | 000,055,808 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CtMp3.Crl
[2011/06/18 14:54:04 | 000,025,088 | —- | C] (Creative Technology Ltd) – C:\WINDOWS\System32\CTSVCCTL.EXE
[2011/06/18 14:53:20 | 000,307,200 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CtMp3Lib.dll
[2011/06/18 14:53:20 | 000,012,288 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTNMSP.crl
[2011/06/18 14:53:19 | 000,105,984 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\ctmp3io2.dll
[2011/06/18 14:53:19 | 000,006,656 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTMP3io2.crl
[2011/06/18 14:53:17 | 000,106,496 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\Video.skn
[2011/06/18 14:53:16 | 000,278,528 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTMedEng.dll
[2011/06/18 14:53:16 | 000,228,352 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTDetect.cpl
[2011/06/18 14:53:16 | 000,057,856 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTDetres.dll
[2011/06/18 14:53:16 | 000,028,672 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTIntRes.dll
[2011/06/18 14:53:16 | 000,024,576 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTMERes.DLL
[2011/06/18 14:53:15 | 000,098,304 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTDrmUI.dll
[2011/06/18 14:53:15 | 000,054,784 | —- | C] (Blue Sky Software Corporation.) – C:\WINDOWS\System32\Inetwh32.dll
[2011/06/18 14:53:15 | 000,012,288 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\CTDrmRes.dll
[2011/06/18 14:52:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Creative
[2011/06/18 14:52:38 | 000,006,752 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\PfModNT.sys
[2011/06/18 14:52:38 | 000,000,000 | —D | C] – C:\Program Files\Creative
[2011/06/18 14:52:37 | 000,306,688 | —- | C] (InstallShield Software Corporation) – C:\WINDOWS\IsUninst.exe
[2011/06/18 14:50:25 | 000,000,000 | —D | C] – C:\Compaq
[2011/06/18 14:42:35 | 000,000,000 | —D | C] – C:\Downloads
[2011/06/18 14:41:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Device Doctor
[2011/06/18 14:41:20 | 000,000,000 | —D | C] – C:\Program Files\Device Doctor
[2011/06/18 14:41:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\Device Doctor
[2011/06/18 14:38:04 | 000,000,000 | —D | C] – C:\Program Files\Downloaded Installers
[2011/06/18 14:33:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Local Settings\Application Data\SlimWare Utilities Inc
[2011/06/18 14:32:32 | 000,000,000 | —D | C] – C:\Program Files\DriverUpdate
[2011/06/18 14:23:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\FixCleaner
[2011/06/18 14:23:11 | 000,000,000 | —D | C] – C:\Program Files\FixCleaner
[2011/06/16 16:01:09 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/15 22:32:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\My Documents\sqljdbc_3.0
[2011/06/15 22:15:55 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2011/06/09 15:46:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/06/09 15:45:03 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/06/09 15:45:02 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/06/09 15:45:02 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/06/09 15:45:02 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/06/08 21:21:37 | 000,000,000 | —D | C] – C:\Program Files\FrostWire
[2011/06/08 21:21:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Start Menu\Programs\FrostWire
[2011/06/08 20:50:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\IObit
[2011/06/08 19:03:01 | 000,000,000 | —D | C] – C:\WINDOWS\System32\WindowsPowerShell
[2011/06/08 19:03:00 | 000,000,000 | —D | C] – C:\WINDOWS\System32\winrm
[2011/06/08 19:03:00 | 000,000,000 | —D | C] – C:\WINDOWS\System32\GroupPolicy
[2011/06/08 19:02:45 | 000,000,000 | -H-D | C] – C:\WINDOWS\$968930Uinstall_KB968930$
[2011/06/08 18:29:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\IObit
[2011/06/08 18:29:32 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/06/08 17:53:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\DriverCure
[2011/06/08 17:53:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\ParetoLogic
[2011/06/08 17:53:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/06/04 22:44:37 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Ron Lambdin\Recent
[2011/06/04 19:31:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\SUPERAntiSpyware.com
[2011/06/04 19:31:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/06/04 19:31:19 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/06/04 19:21:55 | 000,000,000 | —D | C] – C:\Program Files\uTorrentBar
[2011/06/04 19:21:46 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2011/06/04 19:21:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\Application Data\uTorrent
[2011/06/04 01:04:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Ron Lambdin\My Documents\Add-in Express
[2011/06/03 18:31:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com

========== Files - Modified Within 30 Days ==========

[2011/07/01 17:22:32 | 000,000,129 | —- | M] () – C:\Documents and Settings\Ron Lambdin\jagex_runescape_preferences2.dat
[2011/07/01 17:21:32 | 000,000,034 | —- | M] () – C:\Documents and Settings\Ron Lambdin\jagex_runescape_preferences.dat
[2011/07/01 17:18:54 | 001,474,832 | —- | M] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/07/01 17:16:17 | 000,002,283 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2011/07/01 16:58:00 | 000,001,002 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-1425521274-725345543-1004UA.job
[2011/07/01 13:28:58 | 000,131,129 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/07/01 13:28:47 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/07/01 13:28:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/06/29 23:42:21 | 000,493,944 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/06/29 23:42:21 | 000,084,488 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/06/29 20:00:37 | 000,002,338 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Desktop\Google Chrome.lnk
[2011/06/29 19:20:47 | 000,013,736 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/06/28 18:42:00 | 000,000,268 | —- | M] () – C:\WINDOWS\tasks\defrag.job
[2011/06/28 14:26:11 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2011/06/27 22:33:22 | 000,057,152 | —- | M] (Toolkit Development, Ltd.) – C:\WINDOWS\System32\drivers\toolkitdisk.sys
[2011/06/27 18:40:00 | 000,000,272 | —- | M] () – C:\WINDOWS\tasks\Disk Cleanup.job
[2011/06/21 20:30:59 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/06/21 09:58:00 | 000,000,950 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-1425521274-725345543-1004Core.job
[2011/06/18 15:03:48 | 000,000,130 | —- | M] () – C:\WINDOWS\SBWIN.INI
[2011/06/18 14:54:07 | 000,000,924 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\Creative PlayCenter 2.lnk
[2011/06/18 14:53:45 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/06/16 16:01:09 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/15 22:37:32 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/06/09 15:44:47 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/06/09 15:44:47 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/06/09 15:44:47 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/06/09 15:44:47 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/06/09 15:44:47 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/06/09 12:52:13 | 005,767,168 | -H– | M] () – C:\Documents and Settings\Ron Lambdin\NTUSER.bak
[2011/06/09 03:22:13 | 000,102,232 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/06/08 21:21:37 | 000,000,533 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire.lnk
[2011/06/08 21:13:11 | 000,002,171 | —- | M] () – C:\Documents and Settings\Ron Lambdin\.recently-used.xbel
[2011/06/04 19:21:47 | 000,000,656 | —- | M] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk

========== Files Created - No Company Name ==========

[2011/06/18 14:58:51 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\sfman.dat
[2011/06/18 14:58:50 | 000,000,231 | —- | C] () – C:\WINDOWS\ac3api.ini
[2011/06/18 14:57:08 | 002,259,067 | —- | C] () – C:\WINDOWS\System32\DEFAULT.ECW
[2011/06/18 14:55:06 | 000,000,130 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2011/06/18 14:54:07 | 000,000,924 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\Creative PlayCenter 2.lnk
[2011/06/18 14:52:40 | 000,000,227 | —- | C] () – C:\WINDOWS\SYSTEM.I~I
[2011/06/18 09:52:39 | 000,002,338 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Desktop\Google Chrome.lnk
[2011/06/15 23:42:57 | 000,000,268 | —- | C] () – C:\WINDOWS\tasks\defrag.job
[2011/06/15 23:41:25 | 000,000,272 | —- | C] () – C:\WINDOWS\tasks\Disk Cleanup.job
[2011/06/15 21:52:18 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/06/08 21:21:37 | 000,000,533 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire.lnk
[2011/06/08 21:13:11 | 000,002,171 | —- | C] () – C:\Documents and Settings\Ron Lambdin\.recently-used.xbel
[2011/06/08 19:07:19 | 000,225,262 | —- | C] () – C:\WINDOWS\System32\dllcache\msimain.sdb
[2011/06/08 18:32:09 | 000,000,282 | —- | C] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/06/04 19:21:47 | 000,000,656 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2011/05/22 12:33:37 | 000,616,960 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\unenhetah.exe
[2011/05/14 14:17:25 | 000,000,053 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\RSBot_Accounts.ini
[2011/02/23 17:17:13 | 001,474,832 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat
[2011/02/11 17:41:28 | 000,022,558 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\F446.28D
[2011/01/04 20:06:58 | 000,015,752 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/01/04 18:20:02 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/11/15 20:39:18 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2010/10/01 23:09:29 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/09/04 19:43:51 | 000,137,688 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/09/04 19:43:45 | 000,202,040 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/09/04 19:43:11 | 000,066,872 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2009/07/04 00:05:00 | 000,000,155 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/07/03 23:51:08 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2009/05/06 17:25:17 | 000,005,632 | —- | C] () – C:\Documents and Settings\Ron Lambdin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/25 23:53:41 | 000,000,888 | —- | C] () – C:\WINDOWS\my.ini
[2009/04/25 23:35:24 | 000,000,025 | —- | C] () – C:\WINDOWS\mixerdef.ini
[2009/04/25 17:50:24 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2009/04/25 15:29:23 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2009/04/25 14:20:09 | 001,657,376 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2009/04/25 14:20:08 | 001,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/04/25 14:20:07 | 001,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2009/04/25 14:20:02 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2009/04/25 14:19:56 | 001,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2009/04/25 14:19:55 | 001,346,080 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2009/04/25 14:19:47 | 000,449,056 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2009/04/25 14:19:43 | 000,436,768 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2009/04/25 14:00:41 | 000,155,648 | R— | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2009/04/25 14:00:34 | 000,001,136 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2009/04/25 13:55:30 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/04/25 13:51:23 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/04/25 08:46:31 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/04/25 08:45:28 | 000,102,232 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2006/02/28 08:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/02/28 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/02/28 08:00:00 | 000,493,944 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/02/28 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/02/28 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/02/28 08:00:00 | 000,084,488 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/02/28 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/02/28 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/02/28 08:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/02/28 08:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/02/28 08:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/02/28 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/12/29 03:18:03 | 000,040,103 | -H– | C] () – C:\Documents and Settings\Ron Lambdin\Application Data\Ron Lambdinlog.dat
[2002/11/19 16:46:20 | 000,039,104 | —- | C] () – C:\WINDOWS\cmijack.dat
[2002/11/19 16:43:38 | 000,022,178 | —- | C] () – C:\WINDOWS\cmaudio.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:42DC4246

< End of report >
This scan can take a very long time.



Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download Dr.Web CureIt and save it to your desktop. DO NOT perform a scan yet.
alternate download link
Note: The file will be randomly named (i.e. 5mkuvc4z.exe).

Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with Dr.Web CureIt as follows:
  • Double-click on the randomly named file to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the anti-virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All. (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • After the Express Scan is finished, put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and uncheck "Heuristic analysis" under the "Scanning" tab, then click Apply, Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • Please be patient as this scan could take a long time to complete.
  • When the scan has finished, a message will be displayed at the bottom indicating if any viruses were found.
  • Click Select All, then choose Cure > Move incurable.
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
DrWeb File

List-C.bat;C:\32788R22FWJFW;Probably BATCH.Virus;Incurable.Moved.;
OTL.exe;C:\Documents and Settings\Ron Lambdin\Desktop\Virus Protection St00f;Trojan.Siggen2.43612;Incurable.Moved.;
List-C.bat;C:\32788R22FWJFW;Probably BATCH.Virus;Invalid path to file ;


The Scan stopped at a certain file, about 3/4 of the way done with the Scan, I'm not exactly sure why it did this either. So the DrWeb.Cvs that I posted probably isn't accurate.
Delete the copy of Combofix (if it downloaded at all)

Boot into Safe mode with networking and download from the links below and try to run it there.

Link 1
Link 2
ComboFix File

ComboFix 11-07-03.04 - Ron Lambdin 07/04/2011 15:57:05.1.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1524 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: COMODO Antivirus *Enabled/Updated* {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Tarma Installer
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\documents and settings\Ron Lambdin\Application Data\Microsoft\Protect\Credentials\rundll86.exe
c:\documents and settings\Ron Lambdin\Application Data\Ron Lambdinlog.dat
c:\documents and settings\Ron Lambdin\Application Data\unenhetah.exe
c:\program files\Downloaded Installers
c:\windows\My.ini
c:\windows\system32\windir
.
.
((((((((((((((((((((((((( Files Created from 2011-06-04 to 2011-07-04 )))))))))))))))))))))))))))))))
.
.
2011-07-02 02:36 . 2011-07-02 02:36 ——– d—–w- c:\documents and settings\Ron Lambdin\DoctorWeb
2011-06-30 03:08 . 2011-06-30 03:08 ——– d—–w- c:\program files\ESET
2011-06-30 02:53 . 2011-06-30 02:53 ——– d—–w- C:\0ec5f40f4da7ec12ad0951849c9281
2011-06-30 02:49 . 2011-06-30 02:49 ——– d—–w- c:\documents and settings\Ron Lambdin\Application Data\Malwarebytes
2011-06-30 02:49 . 2011-05-29 13:11 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-30 02:49 . 2011-06-30 02:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-06-30 02:49 . 2011-05-29 13:11 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-30 02:49 . 2011-06-30 02:55 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-28 18:24 . 2011-06-28 18:24 ——– d—–w- C:\_OTL
2011-06-28 02:33 . 2011-06-28 02:33 57152 —-a-w- c:\windows\system32\drivers\toolkitdisk.sys
2011-06-28 02:33 . 2011-06-28 02:41 ——– d—–w- c:\program files\ToolKitService
2011-06-24 01:26 . 2011-06-24 01:26 2106216 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-06-24 01:26 . 2011-06-24 01:26 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-06-22 00:24 . 2011-06-22 00:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Spotmau
2011-06-22 00:24 . 2011-06-22 00:24 ——– d—–w- c:\documents and settings\Ron Lambdin\Application Data\spotmau
2011-06-22 00:24 . 2011-06-22 00:37 ——– d—–w- c:\documents and settings\All Users\Application Data\pc health check
2011-06-22 00:23 . 2011-06-22 00:37 ——– d—–w- c:\documents and settings\All Users\Application Data\TuneUp360
2011-06-22 00:22 . 2011-06-22 00:33 ——– d—–w- c:\program files\TuneUp360
2011-06-22 00:19 . 2011-06-22 00:19 ——– d—–w- c:\documents and settings\Ron Lambdin\Application Data\RegistryKeys
2011-06-18 19:02 . 2000-05-11 05:00 90112 —-a-w- c:\windows\Updreg.exe
2011-06-18 18:58 . 1998-06-05 06:00 84992 —-a-w- c:\windows\system32\sfcvrt32.dll
2011-06-18 18:58 . 1995-08-30 06:02 82432 —-a-w- c:\windows\system32\ctwflt32.dll
2011-06-18 18:58 . 1995-07-13 06:01 26768 —-a-w- c:\windows\system32\ctl3d.dll
2011-06-18 18:58 . 1995-01-13 18:10 149504 —-a-w- c:\windows\system32\mfcans32.dll
2011-06-18 18:58 . 1995-01-13 18:10 108032 —-a-w- c:\windows\system32\mfcuia32.dll
2011-06-18 18:58 . 1997-06-02 08:06 34816 —-a-w- c:\windows\CTRes32.dll
2011-06-18 18:58 . 1996-05-23 06:24 24976 —-a-w- c:\windows\ctres.dll
2011-06-18 18:58 . 1994-12-05 07:11 53552 —-a-w- c:\windows\ctccw.dll
2011-06-18 18:55 . 2011-06-18 18:55 ——– d—–w- C:\NVIDIA
2011-06-18 18:54 . 1998-03-19 05:00 3584 —-a-w- c:\windows\system32\Ahqcpres.dll
2011-06-18 18:54 . 1998-03-19 05:00 18432 —-a-w- c:\windows\system32\Audiohq.cpl
2011-06-18 18:54 . 2011-06-18 18:54 ——– d—–w- C:\Media
2011-06-18 18:54 . 1999-12-13 05:01 44032 —-a-w- c:\windows\system32\CTSVCCDA.EXE
2011-06-18 18:54 . 1999-11-18 05:00 25088 —-a-w- c:\windows\system32\CTSVCCTL.EXE
2011-06-18 18:54 . 1999-10-07 06:00 55808 —-a-w- c:\windows\system32\CtMp3.Crl
2011-06-18 18:52 . 2011-06-18 19:03 ——– d—–w- c:\program files\Creative
2011-06-18 18:52 . 1999-12-17 05:00 6752 —-a-w- c:\windows\system32\PfModNT.sys
2011-06-18 18:52 . 1998-10-29 20:45 306688 —-a-w- c:\windows\IsUninst.exe
2011-06-18 18:50 . 2011-06-18 18:50 ——– d—–w- C:\Compaq
2011-06-18 18:42 . 2011-06-18 18:42 ——– d—–w- C:\Downloads
2011-06-18 18:41 . 2011-06-19 22:48 ——– d—–w- c:\documents and settings\Ron Lambdin\Application Data\Device Doctor
2011-06-18 18:41 . 2011-06-18 18:41 ——– d—–w- c:\program files\Device Doctor
2011-06-18 18:33 . 2011-06-18 18:33 ——– d—–w- c:\documents and settings\Ron Lambdin\Local Settings\Application Data\SlimWare Utilities Inc
2011-06-18 18:32 . 2011-06-18 18:37 ——– d—–w- c:\program files\DriverUpdate
2011-06-18 18:23 . 2011-06-18 18:30 ——– d—–w- c:\documents and settings\Ron Lambdin\Application Data\FixCleaner
2011-06-18 18:23 . 2011-06-18 18:41 ——– d—–w- c:\program files\FixCleaner
2011-06-17 01:09 . 2011-06-17 01:12 ——– d—–w- c:\documents and settings\Administrator
2011-06-16 20:01 . 2011-06-16 20:01 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-16 02:15 . 2011-04-21 13:37 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-06-09 19:46 . 2011-06-09 19:46 ——– d—–w- c:\program files\Common Files\Java
2011-06-09 19:45 . 2011-06-09 19:44 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-06-09 01:21 . 2011-06-09 01:21 ——– d—–w- c:\program files\FrostWire
2011-06-09 00:50 . 2011-06-09 00:50 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2011-06-08 23:03 . 2011-06-08 23:03 ——– d—–w- c:\windows\system32\winrm
2011-06-08 23:03 . 2011-06-08 23:03 ——– d—–w- c:\windows\system32\GroupPolicy
2011-06-08 23:02 . 2011-06-08 23:03 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
2011-06-08 22:29 . 2011-06-08 22:30 ——– d—–w- c:\documents and settings\Ron Lambdin\Application Data\IObit
2011-06-08 22:29 . 2011-06-08 22:29 ——– d—–w- c:\program files\IObit
2011-06-08 21:53 . 2011-06-08 21:53 ——– d—–w- c:\documents and settings\Ron Lambdin\Application Data\DriverCure
2011-06-08 21:53 . 2011-06-08 21:53 ——– d—–w- c:\documents and settings\Ron Lambdin\Application Data\ParetoLogic
2011-06-08 21:53 . 2011-06-08 22:28 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2011-06-04 23:31 . 2011-06-04 23:31 ——– d—–w- c:\documents and settings\Ron Lambdin\Application Data\SUPERAntiSpyware.com
2011-06-04 23:31 . 2011-06-10 22:07 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-06-04 23:21 . 2011-06-04 23:21 ——– d—–w- c:\program files\uTorrent
2011-06-04 23:21 . 2011-06-23 20:25 ——– d—–w- c:\documents and settings\Ron Lambdin\Application Data\uTorrent
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-09 19:44 . 2010-06-08 22:44 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-05-13 00:30 . 2011-01-06 21:37 97504 —-a-w- c:\windows\system32\drivers\inspect.sys
2011-05-13 00:30 . 2011-01-06 21:37 29400 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-05-13 00:30 . 2011-01-06 21:37 17416 —-a-w- c:\windows\system32\drivers\cmderd.sys
2011-05-13 00:30 . 2010-12-29 05:42 284744 —-a-w- c:\windows\system32\guard32.dll
2011-05-13 00:30 . 2011-01-06 21:37 242472 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-05-02 15:31 . 2009-04-25 17:51 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2006-02-28 12:00 151552 —-a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2006-02-28 12:00 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:11 . 2006-02-28 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2006-02-28 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2006-02-28 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2006-02-28 12:00 385024 —-a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2006-02-28 12:00 105472 —-a-w- c:\windows\system32\drivers\mup.sys
2011-06-24 01:26 . 2011-05-23 21:24 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86ef8bd1-47f3-4322-923f-f29cdf477eb0}]
2010-07-01 14:31 462848 —-a-w- c:\program files\CAJ Media\Browser Enhancer\adxloader.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-02-28 22:11 191488 ——w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-05-27 15147400]
"tktray"="c:\program files\ToolKitService\tktray.exe" [2011-06-16 933184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"UpdReg"="c:\windows\Updreg.exe" [2000-05-11 90112]
"AHQInit"="c:\program files\Creative\SBLive\Program\AHQInit.exe" [2001-03-28 102400]
"Logitech Utility"="Logi_MwX.Exe" [2003-03-04 19968]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-16 13680640]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-01-16 07:42 13680640 —-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-06-10 22:07 2424192 —-a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Steam Client Service"=3 (0x3)
"iPod Service"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\ArcEmu Blizzlike\\ArcEmu\\arcemu-logonserver.exe"=
"c:\\ArcEmu Blizzlike\\ArcEmu\\arcemu-world.exe"=
"c:\\Program Files\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1947:TCP"= 1947:TCP:HASP SRM
"1947:UDP"= 1947:UDP:HASP SRM
"8380:TCP"= 8380:TCP:League of Legends Launcher
"8380:UDP"= 8380:UDP:League of Legends Launcher
"6968:TCP"= 6968:TCP:League of Legends Launcher
"6968:UDP"= 6968:UDP:League of Legends Launcher
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [1/6/2011 5:37 PM 17416]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [1/6/2011 5:37 PM 29400]
R2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe [5/13/2011 3:59 AM 154424]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [1/6/2011 5:37 PM 242472]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 2:25 PM 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 2:41 PM 67656]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 hasplms;HASP License Manager; [x]
S2 TuneUp360Mon;TuneUp360Mon;"c:\program files\TuneUp360\TuneUp360Mon.exe" –> c:\program files\TuneUp360\TuneUp360Mon.exe [?]
S3 AC2003;AC2003;c:\windows\system32\drivers\AC2003.sys [4/25/2009 1:59 PM 4224]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/29/2011 10:49 PM 39984]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2/28/2006 8:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-28 c:\windows\Tasks\defrag.job
- c:\windows\system32\defrag.exe [2006-02-28 00:12]
.
2011-06-27 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2006-02-28 00:12]
.
2011-06-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-1425521274-725345543-1004Core.job
- c:\documents and settings\Ron Lambdin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-06 18:42]
.
2011-07-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-1425521274-725345543-1004UA.job
- c:\documents and settings\Ron Lambdin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-06 18:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bing.com/?pc=ZUGO&form;=ZGAPHP
mStart Page =
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Ron Lambdin\Application Data\Mozilla\Firefox\Profiles\6ohojrpq.default\
FF - prefs.js: browser.search.selectedEngine - Web Search (eToolKit)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.startnow.com/s/?src=addrbar&provider;=Bing&provider;_code=Z059&partner;_id=308&product;_id=435&affiliate;_id=&channel;=rjacs&toolbar;_id=200&toolbar;_version=2.0&install;_country=US&install;_date=20110609&user;_guid=037B9461475748468AC505B1A1ADC95C&machine;_id=03635ec99fd02b4eb43fe447401925e9&browser;=FF&os;=win&os;_version=5.1-x86-SP3&q;=
FF - user.js: browser.search.defaultenginename - Web Search (eToolKit)
FF - user.js: browser.search.selectedEngine - Web Search (eToolKit)
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp- - c:\docume~1\RONLAM~1\LOCALS~1\Temp\rsbots.exe
MSConfigStartUp-winlogon - (no file)
AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B} - c:\docume~1\ALLUSE~1\APPLIC~1\TARMAI~1\{889DF~1\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-04 16:01
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mysql]
"ImagePath"="\"c:\arcemu blizzlike\Server\mysql\bin\mysqld-nt\" \"–defaults-file=c:\arcemu blizzlike\Server\mysql\bin\my.cnf\" mysql"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1454471165-1425521274-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:a3,8f,43,6a,2c,d2,8c,65,a4,2e,67,1d,c2,71,ae,50,48,a1,2b,94,bf,
4a,91,54,79,53,1d,33,ac,9a,26,b7,93,27,ca,44,d3,86,66,46,c0,8c,e3,92,ce,1a,\
"rkeysecu"=hex:57,3e,66,05,d5,8d,5d,b6,40,12,ba,1b,e1,04,a9,3d
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\guard32.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'lsass.exe'(732)
c:\windows\system32\guard32.dll
.
Completion time: 2011-07-04 16:04:29
ComboFix-quarantined-files.txt 2011-07-04 20:04
.
Pre-Run: 124,695,449,600 bytes free
Post-Run: 125,315,809,280 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 0DB3204C2A1505360A4181C60B917CD3
A few things we will try 1.Update MBAM,try in safe mode with networking if needed but run scan in normal mode 2.If you cannot update MBAM,try to update and scan with Superantispyware you have installed. 3.Try ESET again,if it will not download tell me exactly what it says the problem is. Post any logs you get.
MBAM File

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 7024

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

7/5/2011 12:04:42 AM
mbam-log-2011-07-05 (00-04-42).txt

Scan type: Quick scan
Objects scanned: 156938
Time elapsed: 5 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

ESET File

C:\Documents and Settings\Ron Lambdin\Application Data\FrostWire\.AppSpecialShare\frostwire-4.21.7.windows.exe Win32/OpenCandy application deleted - quarantined
C:\Documents and Settings\Ron Lambdin\My Documents\Downloads\registryboosterplb.exe Win32/RegistryBooster application deleted - quarantined
C:\Documents and Settings\Ron Lambdin\My Documents\Downloads\TechSmith Camtasia Studio 6.0.1 + Keygen.rar probably a variant of Win32/Keygen.BJ application deleted - quarantined
C:\Program Files\FrostWire\Data\settings\FrostWire\.AppSpecialShare\frostwire-4.21.8.windows.exe Win32/OpenCandy application deleted - quarantined
C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\Program Files\Uniblue\SpeedUpMyPC\spnotifier.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\Program Files\Uniblue\SpeedUpMyPC\sp_decryptor.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\Program Files\Uniblue\SpeedUpMyPC\sp_move_serial.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\Program Files\Uniblue\SpeedUpMyPC\sp_track_install.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\Program Files\Yontoo Layers\YontooIEClient.dll Win32/Adware.Yontoo.A application cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Documents and Settings\Ron Lambdin\Application Data\unenhetah.exe.vir a variant of MSIL/Injector.GV trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Documents and Settings\Ron Lambdin\Application Data\Microsoft\Protect\Credentials\rundll86.exe.vir a variant of MSIL/Injector.GV trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150599.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150600.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150601.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150602.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150603.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150635.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150636.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150637.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150638.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150639.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150640.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP266\A0150649.exe multiple threats deleted - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP282\A0161835.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179334.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179335.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179336.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179337.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179338.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179369.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179370.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179371.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179372.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179373.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179402.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179403.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179404.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179405.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179406.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179441.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179442.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179443.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179444.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP286\A0179445.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP287\A0179486.exe Win32/RegistryBooster application deleted - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP287\A0179502.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP287\A0179507.rbf Win32/RegistryBooster application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP313\A0199043.exe Win32/OpenCandy application deleted - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP313\A0200037.exe a variant of Win32/Adware.HotBar.H application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP323\A0208060.dll a variant of Win32/Adware.Yontoo.B application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP323\A0208063.exe a variant of MSIL/Injector.GV trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP323\A0208064.exe a variant of MSIL/Injector.GV trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP324\A0208160.exe Win32/OpenCandy application deleted - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP324\A0208161.exe Win32/OpenCandy application deleted - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP324\A0208169.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP324\A0208170.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP324\A0208171.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP324\A0208172.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP324\A0208173.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP324\A0208174.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
C:\System Volume Information\_restore{B2A96425-9C72-46AE-BD0D-EB7362049988}\RP324\A0208175.dll Win32/Adware.Yontoo.A application cleaned by deleting - quarantined

Also, recently there has been a program that has been running when I start up my computer, It says C:\PROGRA~1\TOOLKI~1\Tktray.exe. I've had one that says Rundll.32.exe, and that was a virus. I just want to know if this is malware of some sort of not.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI