This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CAmmot get windows updates after malware removal

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Im running Win XP pro service pack 3. I recently posted to TomK and my malware problem was resolved. All was fine for about 2 days.
However I suspect I have a malware issue again. I get an error message from windows "[Error number: 0x800A0046] and I can't get updates.
Yesterday my google toolbar dissappeared and all saved bookmarks.
I have posted in the internet browser forum and after some attempts to fix the problem I asked Ztruker I I should post in Malware form. He said "have them take a look and come back here if you still have problems".

Below is OTL.TXT and Extras.TXT

OTL logfile created on: 6/30/2011 4:28:27 PM - Run 1
OTL by OldTimer - Version 3.2.25.0 Folder = C:\Documents and Settings\John Casey\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.01 Gb Available Physical Memory | 50.38% Memory free
3.85 Gb Paging File | 2.93 Gb Available in Paging File | 76.14% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.97 Gb Total Space | 191.37 Gb Free Space | 83.58% Space Free | Partition Type: NTFS

Computer Name: DB8X6CC1 | User Name: John Casey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/30 16:20:26 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John Casey\Desktop\OTL.exe
PRC - [2011/06/30 09:33:48 | 000,059,964 | —- | M] (Macrovision Europe Ltd.) – C:\Documents and Settings\John Casey\Local Settings\Temp\clclean.0001
PRC - [2011/04/18 17:40:08 | 002,334,560 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/04/18 17:39:42 | 007,398,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2011/04/14 05:36:42 | 001,080,672 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/03/28 03:00:52 | 000,351,072 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2011/03/16 16:05:14 | 000,656,736 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2011/03/09 19:24:44 | 002,708,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgfws.exe
PRC - [2011/02/10 07:55:18 | 001,148,256 | —- | M] () – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/02/08 05:33:42 | 000,269,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2011/02/08 05:33:20 | 000,658,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2011/02/08 05:32:42 | 000,750,432 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgam.exe
PRC - [2011/02/01 05:54:46 | 000,185,640 | —- | M] (SupportSoft, Inc.) – C:\Program Files\VERIZONDM\bin\tgsrvc.exe
PRC - [2011/02/01 05:54:42 | 000,206,120 | —- | M] (SupportSoft, Inc.) – C:\Program Files\VERIZONDM\bin\sprtsvc.exe
PRC - [2011/02/01 05:54:30 | 000,206,120 | —- | M] (SupportSoft, Inc.) – C:\Program Files\VERIZONDM\bin\sprtcmd.exe
PRC - [2010/12/20 11:06:32 | 001,734,480 | —- | M] (Diskeeper Corporation) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
PRC - [2010/09/27 11:09:52 | 000,090,864 | —- | M] (PC Pitstop LLC) – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe
PRC - [2009/06/23 15:59:32 | 000,259,368 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
PRC - [2009/05/21 10:55:32 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/05/08 23:54:01 | 000,068,592 | —- | M] (Google Inc.) – C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
PRC - [2008/08/13 18:32:40 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/12/18 09:00:58 | 000,286,720 | —- | M] () – C:\Program Files\Analogue Vista Clock\Analogue Vista Clock.exe
PRC - [2007/01/08 16:58:07 | 000,069,632 | —- | M] (Creative Labs) – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
PRC - [2006/11/02 20:40:12 | 000,174,656 | —- | M] () – C:\WINDOWS\system32\PSIService.exe
PRC - [2006/08/28 20:57:12 | 000,395,776 | —- | M] (Gteko Ltd.) – C:\Program Files\Dell Support\DSAgnt.exe
PRC - [2006/07/06 06:15:00 | 000,151,552 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2006/07/06 06:14:30 | 000,090,112 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2006/01/02 16:41:22 | 000,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2005/10/05 02:12:00 | 000,094,208 | —- | M] () – C:\Program Files\Dell\Media Experience\DMXLauncher.exe


========== Modules (SafeList) ==========

MOD - [2011/06/30 16:20:26 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John Casey\Desktop\OTL.exe
MOD - [2010/08/23 09:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/04/18 17:39:42 | 007,398,752 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2011/03/09 19:24:44 | 002,708,024 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG10\avgfws.exe – (avgfws)
SRV - [2011/02/08 05:33:42 | 000,269,520 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG10\avgwdsvc.exe – (avgwd)
SRV - [2011/02/01 05:54:46 | 000,185,640 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\VERIZONDM\bin\tgsrvc.exe – (tgsrvc_verizondm) SupportSoft Repair Service (verizondm)
SRV - [2011/02/01 05:54:42 | 000,206,120 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\VERIZONDM\bin\sprtsvc.exe – (sprtsvc_verizondm) SupportSoft Sprocket Service (verizondm)
SRV - [2010/12/20 11:06:32 | 001,734,480 | —- | M] (Diskeeper Corporation) [Auto | Running] – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe – (Diskeeper)
SRV - [2010/09/27 11:09:52 | 000,090,864 | —- | M] (PC Pitstop LLC) [Auto | Running] – C:\Program Files\PCPitstop\PCPitstopScheduleService.exe – (PCPitstop Scheduling)
SRV - [2009/06/23 15:59:32 | 000,259,368 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe – (NeroMediaHomeService.4)
SRV - [2008/08/13 18:32:40 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/05/02 02:42:06 | 000,121,360 | —- | M] (Logitech, Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe – (LBTServ)
SRV - [2007/01/08 16:58:07 | 000,069,632 | —- | M] (Creative Labs) [Auto | Running] – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe – (Creative Labs Licensing Service)
SRV - [2006/11/03 19:19:58 | 000,013,592 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend)
SRV - [2006/11/02 20:40:12 | 000,174,656 | —- | M] () [Auto | Running] – C:\WINDOWS\system32\PSIService.exe – (ProtexisLicensing)
SRV - [2006/07/06 06:14:30 | 000,090,112 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®


========== Driver Services (SafeList) ==========

DRV - [2011/04/14 21:28:42 | 000,134,480 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV - [2011/04/05 00:59:56 | 000,297,168 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (Avgtdix)
DRV - [2011/03/16 16:03:20 | 000,032,592 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys – (Avgrkx86)
DRV - [2011/03/01 14:25:18 | 000,034,896 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (Avgmfx86)
DRV - [2011/02/22 08:13:02 | 000,022,992 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys – (AVGIDSEH)
DRV - [2011/02/10 07:53:54 | 000,027,216 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSShim.sys – (AVGIDSShim)
DRV - [2011/02/10 07:53:52 | 000,024,144 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV - [2011/01/07 06:41:46 | 000,248,656 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (Avgldx86)
DRV - [2010/09/22 11:10:18 | 000,044,368 | —- | M] (Diskeeper Corporation) [File_System | On_Demand | Running] – C:\WINDOWS\system32\drivers\DKRtWrt.sys – (DKRtWrt)
DRV - [2010/07/12 04:33:54 | 000,030,432 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\avgfwdx.sys – (Avgfwfd)
DRV - [2010/07/12 04:33:54 | 000,030,432 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\avgfwdx.sys – (Avgfwdx)
DRV - [2008/04/13 11:56:06 | 000,088,320 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnkipx.sys – (NwlnkIpx)
DRV - [2008/02/29 03:13:24 | 000,036,880 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LMouFilt.Sys – (LMouFilt)
DRV - [2008/02/29 03:13:16 | 000,035,344 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LHidFilt.Sys – (LHidFilt)
DRV - [2006/08/01 14:03:36 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\monfilt.sys – (monfilt)
DRV - [2006/08/01 14:03:36 | 000,158,464 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctusfsyn.sys – (CTUSFSYN)
DRV - [2006/08/01 14:03:36 | 000,138,752 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctsfm2k.sys – (ctsfm2k)
DRV - [2006/08/01 14:03:36 | 000,106,496 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctoss2k.sys – (ossrv)
DRV - [2006/07/24 09:20:00 | 001,156,648 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2006/07/05 11:10:23 | 000,019,345 | —- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMPR5.sys – (MREMPR5)
DRV - [2006/07/05 11:10:23 | 000,018,003 | —- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRENDIS5.sys – (MRENDIS5)
DRV - [2006/06/07 14:08:58 | 001,580,544 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2006/06/05 02:39:56 | 000,024,064 | —- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\iqvw32.sys – (NAL)
DRV - [2006/05/25 01:53:06 | 000,003,712 | —- | M] (Logitech, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\LBeepKE.sys – (LBeepKE)
DRV - [2006/05/10 10:56:54 | 000,027,264 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LHidKE.Sys – (LHidKe)
DRV - [2006/05/10 10:56:50 | 000,071,680 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LMouKE.Sys – (LMouKE)
DRV - [2006/01/10 10:07:58 | 000,004,864 | —- | M] (GTek Technologies Ltd.) [Kernel | On_Demand | Running] – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2005/09/08 04:20:00 | 000,094,332 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2005/09/08 04:20:00 | 000,087,036 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2005/09/08 04:20:00 | 000,086,524 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2005/09/08 04:20:00 | 000,025,628 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2005/09/08 04:20:00 | 000,014,684 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2005/09/08 04:20:00 | 000,006,364 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2005/09/08 04:20:00 | 000,002,496 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResN.SYS – (DLADResN)
DRV - [2005/08/25 11:16:52 | 000,005,628 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2005/08/25 11:16:16 | 000,022,684 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_N.SYS – (DLARTL_N)
DRV - [2004/10/19 08:07:22 | 000,009,728 | —- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\PfModNT.sys – (PfModNT)
DRV - [2004/08/04 04:00:00 | 000,063,232 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnknb.sys – (NwlnkNb)
DRV - [2004/08/04 04:00:00 | 000,055,936 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnkspx.sys – (NwlnkSpx)
DRV - [2003/11/17 13:59:20 | 000,212,224 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2003/11/17 13:58:02 | 000,680,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2003/11/17 13:56:26 | 001,042,432 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/facesmooch3/{9F1…5-8574BBE1E51D}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070108
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070108

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070108
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/10 15:39:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/06/23 11:46:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/17 17:14:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/26 04:03:04 | 000,000,000 | —D | M]

[2011/03/24 22:50:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Casey\Application Data\Mozilla\Extensions
[2011/06/18 10:04:40 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Casey\Application Data\Mozilla\Profiles\nca4nygx.Casey\extensions
[2011/06/15 12:20:42 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/06/15 12:20:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\NETSCAPE\NAVIGATOR 9\EXTENSIONS\{3EC9C995-8072-4FC0-953E-4F30620D17F3}
[2011/05/17 17:13:56 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 14:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/06/15 12:20:33 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 14:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2010/07/15 16:15:40 | 000,002,226 | -H– | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2010/01/01 01:00:00 | 000,002,252 | -H– | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2004/08/04 04:00:00 | 000,000,734 | -H– | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (The Weather Channel Toolbar) - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AppleSyncNotifier] File not found
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [MBMon] C:\WINDOWS\System32\CTMBHA.DLL ()
O4 - HKLM..\Run: [Nero MediaHome 4] C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe (Nero AG)
O4 - HKLM..\Run: [VERIZONDM] C:\Program Files\VERIZONDM\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Analogue Vista Clock] C:\Program Files\Analogue Vista Clock\Analogue Vista Clock.exe ()
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DW6] File not found
O4 - HKCU..\Run: [SetDefaultMIDI] C:\WINDOWS\MIDIDEF.EXE (Creative Technology Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\bw+0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw+0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0 {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0s {5a9fa3c7-380a-4fb2-b60f-f15de8bca76a} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\offline-8876480 {5A9FA3C7-380A-4FB2-B60F-F15DE8BCA76A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 16:15:00 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{3cfa888e-2cb2-11dc-8126-0019d12e319d}\Shell - "" = AutoRun
O33 - MountPoints2\{3cfa888e-2cb2-11dc-8126-0019d12e319d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{3cfa888e-2cb2-11dc-8126-0019d12e319d}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (autocheck C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - File not found
O34 - HKLM BootExecute: (autocheck C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/06/30 16:20:22 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\John Casey\Desktop\OTL.exe
[2011/06/29 00:54:54 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Local Settings\Application Data\WMTools Downloaded Files
[2011/06/28 20:11:33 | 000,000,000 | —D | C] – C:\Program Files\Sony
[2011/06/28 19:56:45 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\BabyPaul
[2011/06/28 02:28:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ErrorEND
[2011/06/27 22:42:14 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\My Pictures
[2011/06/25 19:33:54 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\Billing for instructional design
[2011/06/23 17:54:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\John Casey\Desktop\Daily - Per Net Attnd June July 2011
[2011/06/22 14:17:59 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\Recovered files after 6.2011 virus
[2011/06/22 14:17:14 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\Setting standards, GRD, HIS, ATT
[2011/06/22 14:15:52 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\1_Sam mtg 10.22
[2011/06/22 14:15:47 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\Instructional Design Future
[2011/06/22 14:15:20 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\instructional design docs and ppt
[2011/06/18 11:09:10 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Start Menu\Programs\Amazon
[2011/06/18 11:06:55 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\My Documents\Picasa
[2011/06/17 23:31:36 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\2011-06-05, ireland pat's pics
[2011/06/16 11:55:09 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/06/15 16:46:42 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Application Data\Malwarebytes
[2011/06/15 16:46:33 | 000,039,984 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/06/15 16:46:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/15 16:46:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/06/15 16:46:29 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/06/15 16:46:29 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/06/15 12:28:05 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Application Data\Sammsoft
[2011/06/15 12:21:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/06/15 12:21:04 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/06/15 12:20:41 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/06/15 12:20:41 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/06/15 12:20:41 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/06/15 12:20:41 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/06/15 12:20:41 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/06/13 13:14:49 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\mypics
[2011/06/12 10:20:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/06/12 10:20:12 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/06/12 10:20:10 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/06/10 22:25:46 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/06/09 17:16:57 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Local Settings\Application Data\Downloaded Installations
[2011/06/08 09:49:37 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Application Data\AVG10
[2011/06/08 09:48:04 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/06/08 09:47:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2011
[2011/06/08 09:47:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/06/08 09:47:10 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/06/08 09:46:51 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2011/06/08 09:43:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/06/08 09:36:48 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Application Data\AVG8
[2011/06/08 06:52:03 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/08 06:46:02 | 000,000,000 | RH-D | C] – C:\Documents and Settings\John Casey\Recent
[2011/06/07 06:10:45 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\Ireland FB Pics
[2011/06/05 23:12:17 | 000,000,000 | —D | C] – C:\Documents and Settings\John Casey\Desktop\2011-06-05, ireland john's camera
[2011/06/05 11:25:19 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2011/06/05 11:25:18 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2011/06/05 11:25:17 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2010/02/12 20:11:53 | 038,808,920 | —- | C] (Microsoft Corporation) – C:\Program Files\FileFormatConverters.exe
[2010/01/28 00:16:46 | 002,170,694 | —- | C] (Tinnes Software ) – C:\Program Files\desktopcalendar.exe

========== Files - Modified Within 30 Days ==========

[2011/06/30 16:23:22 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2615364061-664855879-2601835229-1006.job
[2011/06/30 16:23:22 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2615364061-664855879-2601835229-1006.job
[2011/06/30 16:20:26 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John Casey\Desktop\OTL.exe
[2011/06/30 16:07:40 | 120,528,148 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/06/30 15:48:00 | 000,000,998 | -H– | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2615364061-664855879-2601835229-1006UA.job
[2011/06/30 15:43:00 | 000,000,886 | -H– | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/30 09:38:21 | 000,655,619 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/06/30 09:35:00 | 000,002,206 | -H– | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/06/30 09:33:36 | 000,000,882 | -H– | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/30 09:33:22 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/06/30 09:33:16 | 2145,296,384 | -HS- | M] () – C:\hiberfil.sys
[2011/06/29 23:11:58 | 000,000,432 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{3BF1FC0A-C9DA-4085-B6EC-170B88C1CD35}.job
[2011/06/29 17:48:00 | 000,000,946 | -H– | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2615364061-664855879-2601835229-1006Core.job
[2011/06/29 03:00:00 | 000,000,506 | -H– | M] () – C:\WINDOWS\tasks\SpywareStop Scheduled Scan.job
[2011/06/29 03:00:00 | 000,000,498 | -H– | M] () – C:\WINDOWS\tasks\SpywareBot Scheduled Scan.job
[2011/06/28 20:13:54 | 000,001,829 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DSC-W560 Handbook (PDF).lnk
[2011/06/28 08:49:01 | 000,000,284 | -H– | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/06/28 04:04:56 | 000,027,648 | —- | M] () – C:\Documents and Settings\John Casey\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/28 02:28:32 | 000,000,392 | —- | M] () – C:\WINDOWS\tasks\ErrorEND.job
[2011/06/27 22:21:44 | 000,278,997 | —- | M] () – C:\Documents and Settings\John Casey\Desktop\Picture Mail.mht
[2011/06/27 00:30:57 | 000,000,190 | —- | M] () – C:\WINDOWS\aeries2.ini
[2011/06/26 03:46:35 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/06/26 03:34:19 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/25 12:22:16 | 000,139,212 | —- | M] () – C:\Documents and Settings\John Casey\Desktop\video.JPG
[2011/06/20 13:40:53 | 000,000,052 | —- | M] () – C:\Documents and Settings\John Casey\Desktop\Yahoo! Calendar June 2011.URL
[2011/06/19 00:07:59 | 000,195,663 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/06/18 11:09:11 | 000,001,700 | —- | M] () – C:\Documents and Settings\John Casey\Desktop\Kindle.lnk
[2011/06/18 10:47:04 | 000,001,440 | —- | M] () – C:\Documents and Settings\John Casey\Application Data\Microsoft\Internet Explorer\Quick Launch\Facebook.url
[2011/06/17 09:49:36 | 000,282,928 | -H– | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/06/17 00:09:00 | 000,000,360 | —- | M] () – C:\Documents and Settings\John Casey\My Documents\spider.sav
[2011/06/15 20:48:14 | 000,000,478 | -H– | M] () – C:\Documents and Settings\John Casey\Desktop\AOL.com - Welcome to AOL.url
[2011/06/15 12:20:33 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/06/15 12:20:33 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/06/15 12:20:33 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/06/15 12:20:33 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/06/15 12:20:33 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/06/15 12:09:30 | 000,000,641 | —- | M] () – C:\Documents and Settings\John Casey\Application Data\Microsoft\Internet Explorer\Quick Launch\Gmail Email from Google (2).url
[2011/06/15 12:09:01 | 000,000,641 | —- | M] () – C:\Documents and Settings\John Casey\Desktop\Gmail Email from Google (2).url
[2011/06/15 12:06:24 | 000,000,609 | —- | M] () – C:\Documents and Settings\John Casey\Desktop\Gmail Email from Google.url
[2011/06/14 07:39:55 | 000,000,166 | —- | M] () – C:\Documents and Settings\John Casey\Application Data\Microsoft\Internet Explorer\Quick Launch\DRUDGE REPORT 2011®.url
[2011/06/12 10:20:41 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/06/09 12:58:20 | 000,000,232 | —- | M] () – C:\Documents and Settings\John Casey\Desktop\Eagle Trainer Admin Panel teresa.url
[2011/06/09 12:49:47 | 000,000,240 | —- | M] () – C:\Documents and Settings\John Casey\Desktop\Welcome to Webmail.url
[2011/06/09 01:01:12 | 000,001,373 | —- | M] () – C:\Documents and Settings\John Casey\Desktop\Facebook.url
[2011/06/07 23:32:33 | 000,000,392 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\19390244
[2011/06/07 23:20:44 | 000,000,160 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~19390244r
[2011/06/07 23:20:44 | 000,000,144 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~19390244

========== Files Created - No Company Name ==========

[2011/06/30 16:07:40 | 120,528,148 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/06/30 09:38:21 | 000,655,619 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2011/06/28 20:11:34 | 000,001,829 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DSC-W560 Handbook (PDF).lnk
[2011/06/28 19:58:23 | 000,139,212 | —- | C] () – C:\Documents and Settings\John Casey\Desktop\video.JPG
[2011/06/28 02:28:32 | 000,000,392 | —- | C] () – C:\WINDOWS\tasks\ErrorEND.job
[2011/06/27 22:21:43 | 000,278,997 | —- | C] () – C:\Documents and Settings\John Casey\Desktop\Picture Mail.mht
[2011/06/26 03:46:35 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/06/26 03:46:35 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/06/20 13:38:15 | 000,000,052 | —- | C] () – C:\Documents and Settings\John Casey\Desktop\Yahoo! Calendar June 2011.URL
[2011/06/19 00:07:59 | 000,195,663 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/06/18 11:09:11 | 000,001,700 | —- | C] () – C:\Documents and Settings\John Casey\Desktop\Kindle.lnk
[2011/06/15 12:09:30 | 000,000,641 | —- | C] () – C:\Documents and Settings\John Casey\Application Data\Microsoft\Internet Explorer\Quick Launch\Gmail Email from Google (2).url
[2011/06/15 12:09:01 | 000,000,641 | —- | C] () – C:\Documents and Settings\John Casey\Desktop\Gmail Email from Google (2).url
[2011/06/15 12:06:24 | 000,000,609 | —- | C] () – C:\Documents and Settings\John Casey\Desktop\Gmail Email from Google.url
[2011/06/14 07:39:55 | 000,000,166 | —- | C] () – C:\Documents and Settings\John Casey\Application Data\Microsoft\Internet Explorer\Quick Launch\DRUDGE REPORT 2011®.url
[2011/06/12 10:20:41 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/06/09 01:02:27 | 000,001,440 | —- | C] () – C:\Documents and Settings\John Casey\Application Data\Microsoft\Internet Explorer\Quick Launch\Facebook.url
[2011/06/09 01:01:12 | 000,001,373 | —- | C] () – C:\Documents and Settings\John Casey\Desktop\Facebook.url
[2011/06/08 06:47:44 | 2145,296,384 | -HS- | C] () – C:\hiberfil.sys
[2011/06/07 23:20:44 | 000,000,160 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~19390244r
[2011/06/07 23:20:44 | 000,000,144 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~19390244
[2011/06/07 23:20:36 | 000,000,392 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\19390244
[2011/05/13 22:50:54 | 000,000,190 | —- | C] () – C:\WINDOWS\aeries2.ini
[2010/12/22 02:11:46 | 000,331,776 | —- | C] () – C:\WINDOWS\System32\TwcToolbarIe7.dll
[2010/12/22 02:11:46 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\TwcToolbarBho.dll
[2010/11/01 00:11:03 | 000,000,760 | —- | C] () – C:\Documents and Settings\John Casey\Application Data\setup_ldm.iss
[2010/04/12 22:30:01 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2009/10/28 00:54:24 | 000,059,572 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/03/05 00:24:26 | 000,000,019 | —- | C] () – C:\WINDOWS\KNP.INI
[2008/02/22 02:21:56 | 000,019,696 | —- | C] () – C:\WINDOWS\System32\drivers\spywarebot.sys
[2007/10/28 14:04:36 | 000,000,044 | —- | C] () – C:\WINDOWS\liveup.ini
[2007/09/29 09:00:15 | 000,000,072 | —- | C] () – C:\WINDOWS\sbwin.ini
[2007/09/26 18:30:31 | 000,003,177 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/08/20 20:22:59 | 000,000,000 | —- | C] () – C:\WINDOWS\netscape.INI
[2007/08/20 20:20:36 | 000,634,087 | —- | C] () – C:\WINDOWS\cd32.exe
[2007/06/23 12:03:40 | 000,003,584 | -H– | C] () – C:\Documents and Settings\John Casey\Application Data\dvd.bmk
[2007/06/06 12:43:05 | 000,407,047 | —- | C] () – C:\WINDOWS\System32\mioengine.exe
[2007/03/30 23:24:19 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/03/17 11:49:20 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2007/02/15 22:46:28 | 000,118,784 | R— | C] () – C:\WINDOWS\bwUnin-7.2.0.137-8876480SL.exe
[2007/01/23 01:50:08 | 000,003,764 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/01/23 01:50:08 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\D3B448CD95.sys
[2007/01/15 02:56:37 | 000,027,648 | —- | C] () – C:\Documents and Settings\John Casey\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/01/13 21:35:26 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2007/01/13 21:33:29 | 000,000,065 | -H– | C] () – C:\WINDOWS\System32\BD7020.dat
[2007/01/13 21:33:19 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2007/01/13 21:32:12 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2007/01/12 18:14:42 | 000,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2007/01/12 16:10:45 | 000,119,808 | —- | C] () – C:\WINDOWS\System32\NTLCC.DLL
[2007/01/12 16:10:45 | 000,003,738 | —- | C] () – C:\WINDOWS\Eagle1.ini
[2007/01/12 14:04:47 | 000,000,133 | -H– | C] () – C:\Documents and Settings\John Casey\Local Settings\Application Data\fusioncache.dat
[2007/01/08 17:17:11 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/01/08 17:06:13 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/01/08 17:05:09 | 000,040,491 | -H– | C] () – C:\WINDOWS\nsreg.dat
[2007/01/08 17:04:00 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/01/08 16:59:07 | 000,022,629 | —- | C] () – C:\WINDOWS\System32\CiFilter.ini
[2007/01/08 16:58:22 | 000,010,820 | —- | C] () – C:\WINDOWS\System32\CTSBMB.INI
[2007/01/08 16:58:08 | 000,000,040 | —- | C] () – C:\WINDOWS\System32\mes2046.dll
[2007/01/08 16:30:14 | 001,355,042 | —- | C] () – C:\WINDOWS\System32\CTMBHA.DLL
[2007/01/08 16:29:52 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2007/01/08 16:29:40 | 000,129,112 | -H– | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2007/01/08 16:28:05 | 000,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/11/02 20:40:12 | 000,174,656 | —- | C] () – C:\WINDOWS\System32\PSIService.exe
[2005/11/10 00:38:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/11 16:24:19 | 000,000,799 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 16:19:30 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/11 16:12:14 | 000,021,640 | -H– | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 16:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 16:07:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/11 16:06:43 | 000,282,928 | -H– | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 16:00:30 | 000,004,569 | -H– | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/11 16:00:28 | 000,503,776 | -H– | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/11 16:00:28 | 000,272,128 | -H– | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/11 16:00:28 | 000,089,042 | -H– | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/11 16:00:28 | 000,028,626 | -H– | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/11 16:00:27 | 000,004,627 | -H– | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/11 16:00:26 | 013,107,200 | -H– | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/11 16:00:24 | 000,000,741 | -H– | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/11 16:00:19 | 000,673,088 | -H– | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/11 16:00:19 | 000,046,258 | -H– | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/11 16:00:12 | 000,218,003 | -H– | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/11 16:00:04 | 000,001,804 | -H– | C] () – C:\WINDOWS\System32\dcache.bin
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/03/04 09:16:34 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Jpeg32.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/11 16:15:00 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2010/09/14 15:07:51 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2004/08/11 16:15:00 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2007/01/08 16:39:48 | 000,007,375 | RH– | M] () – C:\dell.sdr
[2011/06/30 09:33:16 | 2145,296,384 | -HS- | M] () – C:\hiberfil.sys
[2007/01/12 14:58:51 | 000,004,128 | -H– | M] () – C:\INFCACHE.1
[2004/08/11 16:15:00 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2007/01/08 17:06:04 | 000,000,832 | -H– | M] () – C:\IPH.PH
[2007/08/20 20:21:32 | 000,000,151 | -H– | M] () – C:\liprefs.js
[2004/08/11 16:15:00 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2010/01/25 22:10:13 | 000,069,981 | -H– | M] () – C:\NET - PERIOD ATTEND.pdf
[2004/08/04 04:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/05/06 14:28:45 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/06/30 09:33:15 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2008/10/13 15:11:52 | 000,005,694 | —- | M] () – C:\Sdicon32.ico
[2007/01/08 17:10:45 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2007/06/02 13:11:40 | 000,167,815 | -H– | M] () – C:\teaching application.pdf.pdf
[2011/06/21 23:28:42 | 000,002,016 | -H– | M] () – C:\ttLog.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | -H– | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | -H– | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/11 16:14:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2001/11/20 13:37:28 | 000,047,616 | R— | M] (Black Ice Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ppbiPr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/01/28 00:16:54 | 002,170,694 | —- | M] (Tinnes Software ) – C:\Program Files\desktopcalendar.exe
[2010/02/12 20:11:54 | 038,808,920 | —- | M] (Microsoft Corporation) – C:\Program Files\FileFormatConverters.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/11 16:06:14 | 000,094,208 | -H– | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/11 16:06:14 | 000,659,456 | -H– | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/11 16:06:14 | 000,876,544 | -H– | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/05/06 14:33:30 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2007/01/08 16:56:59 | 000,265,916 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\TRANSFORMS=1033.mst

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/01/12 14:04:59 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\John Casey\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/06/14 07:39:55 | 000,000,166 | —- | M] () – C:\Documents and Settings\John Casey\Application Data\Microsoft\Internet Explorer\Quick Launch\DRUDGE REPORT 2011®.url
[2011/06/18 10:47:04 | 000,001,440 | —- | M] () – C:\Documents and Settings\John Casey\Application Data\Microsoft\Internet Explorer\Quick Launch\Facebook.url
[2011/06/15 12:09:30 | 000,000,641 | —- | M] () – C:\Documents and Settings\John Casey\Application Data\Microsoft\Internet Explorer\Quick Launch\Gmail Email from Google (2).url

< %USERPROFILE%\Desktop\*.exe >
[2011/03/23 17:33:06 | 001,748,448 | —- | M] (Dell Inc) – C:\Documents and Settings\John Casey\Desktop\aulauncher.exe
[2009/09/17 10:27:33 | 000,365,920 | —- | M] (Diskeeper Corporation) – C:\Documents and Settings\John Casey\Desktop\Autorun.exe
[2010/02/24 20:26:22 | 000,891,248 | —- | M] (AVG Technologies) – C:\Documents and Settings\John Casey\Desktop\avg_free_stb_all_9_40_cnet.exe
[2007/11/16 23:19:27 | 001,074,244 | —- | M] (Etru Software Development ) – C:\Documents and Settings\John Casey\Desktop\capture.exe
[2010/06/08 01:03:18 | 002,453,132 | —- | M] (OpenWith.org ) – C:\Documents and Settings\John Casey\Desktop\OpenWith.org_Installer.exe
[2011/06/30 16:20:26 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John Casey\Desktop\OTL.exe
[2009/10/09 17:33:53 | 032,441,648 | —- | M] (Apple Inc.) – C:\Documents and Settings\John Casey\Desktop\QuickTimeInstaller.exe
[2010/04/09 13:24:59 | 013,772,912 | —- | M] (Smart Soft ) – C:\Documents and Settings\John Casey\Desktop\smart-pdf-converter-setup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-03 09:50:12

< >

< End of report >


See next posting for next report
OTL Extras logfile created on: 6/30/2011 4:28:27 PM - Run 1
OTL by OldTimer - Version 3.2.25.0 Folder = C:\Documents and Settings\John Casey\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.01 Gb Available Physical Memory | 50.38% Memory free
3.85 Gb Paging File | 2.93 Gb Available in Paging File | 76.14% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.97 Gb Total Space | 191.37 Gb Free Space | 83.58% Space Free | Partition Type: NTFS

Computer Name: DB8X6CC1 | User Name: John Casey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger – (Logitech)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe" = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox – (Yahoo! Inc.)
"C:\Documents and Settings\John Casey\Desktop\spyware bot\setupxv.exe" = C:\Documents and Settings\John Casey\Desktop\spyware bot\setupxv.exe:*:Enabled:setupxv.exe
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Disabled:America Online 9.0
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL
"C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe" = C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe:*:Enabled:Nero MediaHome 4 – (Nero AG)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Disabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Disabled:Google Earth – (Google)
"C:\Documents and Settings\John Casey\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\John Casey\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgam.exe" = C:\Program Files\AVG\AVG10\avgam.exe:*:Enabled:AVG Alert manager – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0A0873E1-D9BA-4994-B85D-A0A331EF1F0C}" = Intel® PRO Network Connections
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0ED38503-B69A-44B4-98BE-21BFF284A9B6}" = Brother Driver Deployment Wizard
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{12665B01-3F3A-4433-B179-9D8E352D7547}" = Try Corel Snapfire muvee autoProducer add on
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.5.3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20F51690-133A-453C-B616-1C15AB2C0EF0}" = SBA
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD Plus
"{228814B2-6A64-4AD5-8D2D-4E2188DEB191}" = AVG 2011
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 26
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2CCBABCB-6427-4A55-B091-49864623C43F}" =
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{32B4B536-4443-42F0-9676-98373BE9114F}" =
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{34EBD418-B8E6-4E86-89C4-33B72CF5663F}" =
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{403EF592-953B-4794-BCEF-ECAB835C2095}" =
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{46C73DE4-E96D-4F7C-8371-F28052183B12}" = Advanced Decoder Patch
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52338F65-A1C3-4CDC-B733-50051682B297}" =
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{53C6D09E-EAB6-49E5-BA4C-BA7FF13830FB}" = Sound Blaster Audigy ADVANCED MB
"{548EAC70-EE00-11DD-908C-005056806466}" = Google Earth
"{569A9538-86EC-44C3-8EE4-C68B165F2A75}" =
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5832CE91-A108-490E-A341-6BD8462EE6BC}" = SpywareStop
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}" =
"{5E68BB65-4059-4FE5-AAC4-0CD1D79BBDE2}" = EarthLink Setup Files
"{5EEE551B-7692-4D68-91BF-DAD745243AFB}" =
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6913FBE5-1B4B-4308-8DDD-2944F9C91E06}" = ATI Catalyst Control Center
"{69fc3b9a-4149-43db-a557-6ed0c8d8ba44}" = Nero MediaHome 4 Help
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{700932B3-A964-4878-82A2-96054622A1F7}" =
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73919E2B-725C-4FAA-8473-45E063A3575F}" =
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{78ffc49a-a5bb-4a47-8d2d-e79582b65e30}" = Nero MediaHome 4 Essentials
"{7ADE3A47-B425-45E9-8FF6-11BE2B775645}" = Corel Snapfire Plus
"{7BDD6642-76D6-49F7-9157-6100E5C75B97}" = Vz In Home Agent
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{7E6066E6-8B5B-4100-B0FA-1D9E9B663CBA}" = iTunes
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A42F680-2DD6-11D4-9A8C-0040F6982C20}" =
"{8D2AE3F6-79DF-423C-91CB-389F6FB5837B}" = Andrea VoiceCenter
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{943884D4-B604-496F-B132-DFA9C63FAF6A}" =
"{95D9B4D8-B091-4fab-80EA-313EB4B82FD6}" =
"{99ef387e-633e-4cfb-bfa3-ab961b685ddf}" = Nero MediaHome 4
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A2529672-574A-4A99-86A5-C1770A0E31FE}" =
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}" =
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B702CCCE-3176-4DBF-B932-D1B8F402F330}" = Digital Content Portal
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD202930-5F70-4B35-B875-1E28604F328D}" = Logitech Communications Manager
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C64409FA-42A7-49C6-837A-D2E5D813BD57}" =
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEE2252C-4035-4B27-8EC6-0B085DD3A413}" = Dell Support 3.2.1
"{CF0EDB56-BBF6-3C9F-9C50-2E3B3D444641}" = Google Talk Plugin
"{D0957BCD-AE33-42B1-82F6-B2D4B3C6E2A4}" = Diskeeper 2010 Professional
"{D547A594-AA85-4B92-80EB-47B371B98C68}" = Verizon Download Manager
"{D83BD5E2-5AF4-49F6-B5C1-484A9760E73D}" = Brother MFL-Pro Suite
"{DB90FF25-9932-48F2-B643-1802F1864FAF}" = AVG 2011
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{DE4A4C48-2232-4CCB-AD61-490ACD29BA85}" =
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EB997E90-5EB0-4eb5-90D0-90B1D2F0CA03}" =
"{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}" = Yahoo! Music Jukebox
"{EEEF992E-270C-4B4C-8389-4B3DEEE33190}" =
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{F413D795-B077-4A96-AE75-810BBA673A0E}" = Microsoft Office Small Business Accounting 2006
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"AAA Screen Capture 2.1_is1" = AAA Screen Capture 2.1
"AddressBook" =
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"AERIES" = AERIES
"Amazon Kindle" = Amazon Kindle
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"Analogue Vista Clock" = Analogue Vista Clock 1.10
"ATI Display Driver" = ATI Display Driver
"AudioPlugin.dll" =
"AVG" = AVG 2011
"Branding" =
"CADI" =
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Connection Manager" =
"CopyNow.dll" =
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Creative Audio Pack" = Creative Audio Pack
"Creative MediaSource 5" =
"Creative MediaSource Go!" =
"Creative MediaSource Net Content Plugin Unicode" =
"Creative MediaSource Unicode" =
"Creative Restore Defaults" =
"Creative WaveStudio" =
"DataPlugin.dll" =
"DirectAnimation" =
"DirectDrawEx" =
"dlatray.exe" =
"DXM_Runtime" =
"EAXSet" =
"Equalizer" =
"ESET Online Scanner" = ESET Online Scanner v3
"Fontcore" =
"Google Desktop" = Google Desktop
"ICW" =
"IE40" =
"IE4Data" =
"IE5BAKEX" =
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IEData" =
"Learn Windows Vista" = Learn Windows Vista
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.0.1200
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" =
"Microsoft .NET Framework 3.0" =
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Interactive Training" =
"MobileOptionPack" =
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"NetMeeting" =
"oggcodecs" =
"OutlookExpress" =
"PC Pitstop Optimize_is1" = PC Pitstop Optimize 1.5
"PC Pitstop Optimize2_is1" = PC Pitstop Optimize2 2.0
"PC Pitstop Optimize3_is1" = PC Pitstop Optimize3 3.0
"PCHealth" =
"Picasa 3" = Picasa 3
"PIXELRULER" = PIXELRULER
"PROSetDX" =
"Quick Screen Capture 3.0_is1" = Quick Screen Capture 3.0
"Quick Screen Recorder 1.5_is1" = Quick Screen Recorder 1.5
"RealPlayer 12.0" = RealPlayer
"SAMB_ADVMB_FILTER_DRV" = Sound Blaster ADVANCED MB Drivers
"SchedulingAgent" =
"SearchAssist" = SearchAssist
"SFBM" =
"Sound Blaster Audigy ADVANCED MB" =
"Sound Blaster Audigy ADVANCED MB Product Registration" = Sound Blaster Audigy ADVANCED MB Product Registration
"Sound Blaster Audigy ADVANCED MB Windows Drivers" =
"Sound Blaster X-Fi XP & Vista Driver Web Release" =
"SPEAKER" =
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SURMIXER" =
"Ten Thumbs_is1" = Ten Thumbs 4.7
"The Weather Channel Toolbar" = The Weather Channel Toolbar
"Verizon FiOS Activation_is1" = Verizon FiOS Activation
"Verizon Online Help and Support" = Verizon Online Help and Support
"Wdf01000" =
"Wdf01001" =
"Web Sudoku Deluxe_is1" = Web Sudoku Deluxe 1.2.2
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMCSetup" =
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/26/2011 11:50:24 AM | Computer Name = DB8X6CC1 | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 6/26/2011 3:45:20 PM | Computer Name = DB8X6CC1 | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 6/26/2011 6:47:33 PM | Computer Name = DB8X6CC1 | Source = Application Error | ID = 1000
Description = Faulting application realplay.exe, version 12.0.1.609, faulting module
msvcr90.dll, version 9.0.30729.4148, fault address 0x00031484.

Error - 6/26/2011 6:47:39 PM | Computer Name = DB8X6CC1 | Source = Application Error | ID = 1001
Description = Fault bucket -2109786264.

Error - 6/28/2011 12:37:47 AM | Computer Name = DB8X6CC1 | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 6/28/2011 12:53:39 AM | Computer Name = DB8X6CC1 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/28/2011 12:53:53 AM | Computer Name = DB8X6CC1 | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 6/28/2011 3:20:31 AM | Computer Name = DB8X6CC1 | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 6/29/2011 3:12:34 AM | Computer Name = DB8X6CC1 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/29/2011 3:12:38 AM | Computer Name = DB8X6CC1 | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

[ System Events ]
Error - 6/29/2011 3:38:48 AM | Computer Name = DB8X6CC1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 6/29/2011 3:40:02 AM | Computer Name = DB8X6CC1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 6/29/2011 3:40:57 AM | Computer Name = DB8X6CC1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 6/29/2011 3:45:17 AM | Computer Name = DB8X6CC1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 6/29/2011 3:55:51 AM | Computer Name = DB8X6CC1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 6/29/2011 10:34:37 PM | Computer Name = DB8X6CC1 | Source = Service Control Manager | ID = 7001
Description = The Windows Media Player Network Sharing Service service depends on
the Universal Plug and Play Device Host service which failed to start because of
the following error: %%1058

Error - 6/29/2011 10:35:06 PM | Computer Name = DB8X6CC1 | Source = Service Control Manager | ID = 7001
Description = The Windows Media Player Network Sharing Service service depends on
the Universal Plug and Play Device Host service which failed to start because of
the following error: %%1058

Error - 6/30/2011 12:34:37 PM | Computer Name = DB8X6CC1 | Source = Service Control Manager | ID = 7001
Description = The Windows Media Player Network Sharing Service service depends on
the Universal Plug and Play Device Host service which failed to start because of
the following error: %%1058

Error - 6/30/2011 12:34:52 PM | Computer Name = DB8X6CC1 | Source = Service Control Manager | ID = 7001
Description = The Windows Media Player Network Sharing Service service depends on
the Universal Plug and Play Device Host service which failed to start because of
the following error: %%1058

Error - 6/30/2011 6:31:08 PM | Computer Name = DB8X6CC1 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.


< End of report >
:welcome:

For what its worth, and it may have only happened to me, but years back I was a big fan of Diskeeper, had set to set it and forget it, after about a year or so I started to develop all sorts of errors, I found out that Diskeeper some how went haywire and was causing me all sorts or problems, I uninstalled it and all my issues went away.


C:\Documents and Settings\John Casey\Desktop\spyware bot <– This is a rogue malware program, its not legit , Spybot Search and Destroy is the legit one. See if you can uninstall it although I am not looking at in your add remove programs.



Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.








Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please







Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]



Post the Malwarebytes log and the log from aswMBR please
Sypbot Rouge Program has been removed, it does not appear in the "Add Remove Programs. Here are logs requested: Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Database version: 7031 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 7/5/2011 10:35:07 PM mbam-log-2011-07-05 (22-35-07).txt Scan type: Quick scan Objects scanned: 206024 Time elapsed: 3 minute(s), 35 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ******************************************************** aswMBR version 0.9.7.705 Copyright© 2011 AVAST Software Run date: 2011-07-05 22:38:12 —————————– 22:38:12.015 OS Version: Windows 5.1.2600 Service Pack 3 22:38:12.015 Number of processors: 2 586 0xF06 22:38:12.015 ComputerName: DB8X6CC1 UserName: 22:38:12.828 Initialize success 22:39:26.171 AVAST engine defs: 11070501 22:41:02.062 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 22:41:02.062 Disk 0 Vendor: SAMSUNG_ VT10 Size: 238418MB BusType: 3 22:41:02.093 Disk 0 MBR read successfully 22:41:02.093 Disk 0 MBR scan 22:41:02.093 Disk 0 unknown MBR code 22:41:02.093 Disk 0 scanning sectors +488263545 22:41:02.140 Disk 0 scanning C:\WINDOWS\system32\drivers 22:41:05.312 File: C:\WINDOWS\system32\drivers\cdrom.sys **SUSPICIOUS** 22:41:14.343 Service scanning 22:41:15.171 Disk 0 trace - called modules: 22:41:15.187 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 22:41:15.187 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a849870] 22:41:15.187 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8a7e0030] 22:41:15.859 AVAST engine scan C:\WINDOWS 23:02:12.125 File: C:\WINDOWS\system32\drivers\cdrom.sys **SUSPICIOUS** 23:07:49.328 AVAST engine scan C:\Documents and Settings\John Casey 23:29:53.671 AVAST engine scan C:\Documents and Settings\All Users 23:37:14.000 Scan finished successfully 23:42:53.546 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\John Casey\Desktop\MBR.dat" 23:42:53.546 The log file has been saved successfully to "C:\Documents and Settings\John Casey\Desktop\aswMBR.txt"
Hi,

I would like you to run Combofix, unfortunately it wont run with AVG present so you need to uninstall AVG via Add Remove programs in the control panel, we can redownload and reinstall when where done, outside of the forum, dont do any web surfing until we reinstall AVG


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
You do mean "uninstall AVG" rather than disable it? I have the paid version and have printed the registration number. Will that be enough to re-install it? I don’t want to pay for it again. Since that last two scans I sent you, I changed the Windows update program in control panel auto update. I got the gold shield in the sys tray. I didn't write down what I changed, unfortunately. I clicked it and clicked custom update and clicked on the only update showing which was a security update for IE 8. I have not been able to make the update page work again to see if update was successful. It gives the original error message. Hope I didn’t make things worse. I will wait for a response about AVG before I run Combofix. Thanks
You should have the original setup file that you downloaded for AVG, you can use that one or redownload the paid version again, you can use your registration number to activate it.
After uninstalling AVB2011, I ran Combfix
ComboFix 11-07-06.04 - John Casey 07/06/2011 19:07:38.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1431 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\JOHNCA~1\LOCALS~1\Temp\clclean.0001.dir.0000\~df394b.tmp
c:\documents and settings\John Casey\Local Settings\Temp\clclean.0001.dir.0000\~df394b.tmp
c:\documents and settings\John Casey\WINDOWS
.
.
((((((((((((((((((((((((( Files Created from 2011-06-07 to 2011-07-07 )))))))))))))))))))))))))))))))
.
.
2011-06-29 07:54 . 2011-06-29 07:54 ——– d—–w- c:\documents and settings\John Casey\Local Settings\Application Data\WMTools Downloaded Files
2011-06-29 03:11 . 2011-06-29 03:11 ——– d—–w- c:\program files\Sony
2011-06-28 09:28 . 2011-06-28 09:28 ——– d—–w- c:\documents and settings\All Users\Application Data\ErrorEND
2011-06-16 18:55 . 2011-06-16 18:55 ——– d—–w- c:\program files\ESET
2011-06-15 23:46 . 2011-06-15 23:46 ——– d—–w- c:\documents and settings\John Casey\Application Data\Malwarebytes
2011-06-15 23:46 . 2011-05-29 16:11 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-15 23:46 . 2011-06-15 23:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-06-15 23:46 . 2011-07-06 05:30 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-15 23:46 . 2011-05-29 16:11 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-15 19:28 . 2011-06-16 01:39 ——– d—–w- c:\documents and settings\John Casey\Application Data\Sammsoft
2011-06-15 19:21 . 2011-06-15 19:21 ——– d—–w- c:\program files\Common Files\Java
2011-06-15 19:20 . 2011-06-15 19:20 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-06-15 19:20 . 2011-06-15 19:20 476904 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-06-15 19:20 . 2011-06-15 19:20 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-06-12 17:20 . 2011-06-12 17:20 ——– d—–w- c:\program files\iPod
2011-06-12 17:20 . 2011-06-12 17:20 ——– d—–w- c:\program files\iTunes
2011-06-10 00:16 . 2011-06-10 00:16 ——– d—–w- c:\documents and settings\John Casey\Local Settings\Application Data\Downloaded Installations
2011-06-08 16:49 . 2011-06-08 16:49 ——– d—–w- c:\documents and settings\John Casey\Application Data\AVG10
2011-06-08 16:48 . 2011-06-08 16:48 ——– d–h–w- c:\documents and settings\All Users\Application Data\Common Files
2011-06-08 16:47 . 2011-07-07 01:56 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG10
2011-06-08 16:46 . 2011-06-08 16:46 ——– d—–w- c:\program files\AVG
2011-06-08 16:43 . 2011-07-07 01:55 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData
2011-06-08 16:36 . 2011-06-08 16:36 ——– d—–w- c:\documents and settings\John Casey\Application Data\AVG8
2011-06-08 13:52 . 2011-06-26 10:34 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-08 13:47 . 2011-05-09 20:46 6962000 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{C15A379C-44F4-4DFB-B34C-91C0B6892087}\mpengine.dll
2011-06-08 13:46 . 2011-06-08 13:46 ——– d—–w- c:\windows\system32\wbem\Repository
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-09 20:46 . 2007-10-27 08:42 6962000 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-04-13 22:40 . 2011-04-13 22:40 4284416 —-a-w- c:\windows\system32\GPhotos.scr
2010-02-13 03:11 . 2010-02-13 03:11 38808920 —-a-w- c:\program files\FileFormatConverters.exe
2010-01-28 07:16 . 2010-01-28 07:16 2170694 —-a-w- c:\program files\desktopcalendar.exe
2011-05-18 00:13 . 2011-03-25 05:49 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-08-10 04:16 . 2007-04-04 22:39 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 24576]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-29 395776]
"Analogue Vista Clock"="c:\program files\Analogue Vista Clock\Analogue Vista Clock.exe" [2007-12-18 286720]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"MBMon"="CTMBHA.DLL" [2006-06-29 1355042]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-05-09 68592]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-10 30192]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-10 16384]
"VERIZONDM"="c:\program files\VERIZONDM\bin\sprtcmd.exe" [2011-02-01 206120]
"Nero MediaHome 4"="c:\program files\Nero\Nero MediaHome 4\NeroMediaHome.exe" [2009-06-23 4891944]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-08 421160]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 09:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=c:\windows\pss\ymetray.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-09 18:09 63712 —-a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Analogue Vista Clock]
2007-12-18 16:00 286720 —-a-w- c:\program files\Analogue Vista Clock\Analogue Vista Clock.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter2.0]
2005-01-07 23:30 864256 ——w- c:\program files\Brother\ControlCenter2\brctrcen.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
2007-02-06 17:20 478800 —-a-w- c:\program files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
2009-05-21 17:55 206064 —-a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
2005-09-08 11:20 122940 —-a-w- c:\windows\system32\DLA\DLACTRLW.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2007-10-10 01:57 16384 —-a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-08-10 04:16 30192 —-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2004-04-14 21:04 40960 —-a-w- c:\program files\ScanSoft\PaperPort\IndexSearch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-06-08 00:51 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2008-02-29 10:12 76304 —-a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
2008-02-29 10:12 76304 —-a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2007-01-12 10:09 488984 —-a-w- c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2007-01-12 10:12 244512 —-a-w- c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nero MediaHome 4]
2009-06-23 22:59 4891944 —-a-w- c:\program files\Nero\Nero MediaHome 4\NeroMediaHome.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2004-04-14 20:46 57393 —-a-w- c:\program files\ScanSoft\PaperPort\pptd40nt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize Scheduler]
2008-03-27 00:40 2577120 —-a-w- c:\program files\PCPitstop\Optimize\PCPOptimize.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefPrt]
2004-11-11 23:14 49152 ——w- c:\program files\Brother\Brmfl04g\BrStDvPt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2003-10-14 16:22 155648 —-a-r- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-06-14 07:06 68856 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoiceCenter]
2006-02-16 15:20 1118208 ——w- c:\program files\Creative\VoiceCenter\AndreaVC.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 02:20 866584 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Nero\\Nero MediaHome 4\\NMMediaServerService.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Documents and Settings\\John Casey\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2/15/2007 10:45 PM 3712]
R2 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [12/28/2009 12:15 AM 90864]
R2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files\VERIZONDM\bin\sprtsvc.exe [2/1/2011 5:54 AM 206120]
R2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files\VERIZONDM\bin\tgsrvc.exe [2/1/2011 5:54 AM 185640]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [2/15/2011 2:35 PM 44368]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 gupdate1c9c0b6a12946ac;Google Update Service (gupdate1c9c0b6a12946ac);c:\program files\Google\Update\GoogleUpdate.exe [4/18/2009 11:18 PM 133104]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [1/8/2007 5:07 PM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/18/2009 11:18 PM 133104]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]
.
2011-07-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-19 06:18]
.
2011-07-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-19 06:18]
.
2011-07-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2615364061-664855879-2601835229-1006Core.job
- c:\documents and settings\John Casey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-29 00:38]
.
2011-07-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2615364061-664855879-2601835229-1006UA.job
- c:\documents and settings\John Casey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-29 00:38]
.
2011-07-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]
.
2011-07-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2615364061-664855879-2601835229-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 19:33]
.
2011-07-02 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2615364061-664855879-2601835229-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 19:33]
.
2011-07-06 c:\windows\Tasks\User_Feed_Synchronization-{3BF1FC0A-C9DA-4085-B6EC-170B88C1CD35}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://news.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: aol.com\free
TCP: DhcpNameServer = 192.168.1.1 [removed]
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
HKLM-Run-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-CTFMON - (no file)
MSConfigStartUp-DiskeeperSystray - c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe
MSConfigStartUp-pccguide - c:\program files\Trend Micro\Internet Security 14\pccguide.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-06 19:14
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\windows\TEMP\TMP000000109A8EF68AA5067E5F 524288 bytes
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(740)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
- - - - - - - > 'explorer.exe'(2288)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\Google\Quick Search Box\bin\1.2.1151.245\qsb.dll
c:\windows\system32\dfshim.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\Nero\Nero MediaHome 4\NMMediaServerService.exe
c:\windows\system32\PSIService.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-07-06 19:19:30 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-07 02:19
.
Pre-Run: 205,450,678,272 bytes free
Post-Run: 205,395,648,512 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 6C295275FFF01EF88B3A4BC03CCE9C75
Good Morning Joe,


You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see. If the site says this file has been checked before, have them check it again

C:\WINDOWS\system32\drivers\cdrom.sys <– This file

If the site is busy you can try this one
http://virusscan.jotti.org/en







This scan will most likely not find anything but lets go ahead and run it to be sure

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)






ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
Ken,
Thanks for the reply. I don't think I told you that I get an error message at boot up showing that CTMDHA.BLL could not load. It does not happen every time, but often enough.

I will work on the scans this weekend.

John
CTMDHA.BLL <– Is related to Creative/SoundBlaster Software, does your sound work ok ? I think the work around for this is to reinstall your Creative/SoundBlaster Software, do you have the disk ? If not when were done I will link you to our windows forum that can help you fix it
2011/07/08 13:21:16.0109 3284 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21 2011/07/08 13:21:16.0687 3284 ================================================================================ 2011/07/08 13:21:16.0687 3284 SystemInfo: 2011/07/08 13:21:16.0687 3284 2011/07/08 13:21:16.0687 3284 OS Version: 5.1.2600 ServicePack: 3.0 2011/07/08 13:21:16.0687 3284 Product type: Workstation 2011/07/08 13:21:16.0687 3284 ComputerName: DB8X6CC1 2011/07/08 13:21:16.0687 3284 UserName: John Casey 2011/07/08 13:21:16.0687 3284 Windows directory: C:\WINDOWS 2011/07/08 13:21:16.0687 3284 System windows directory: C:\WINDOWS 2011/07/08 13:21:16.0687 3284 Processor architecture: Intel x86 2011/07/08 13:21:16.0687 3284 Number of processors: 2 2011/07/08 13:21:16.0687 3284 Page size: 0x1000 2011/07/08 13:21:16.0687 3284 Boot type: Normal boot 2011/07/08 13:21:16.0687 3284 ================================================================================ 2011/07/08 13:21:16.0984 3284 Initialize success 2011/07/08 13:21:33.0015 1864 ================================================================================ 2011/07/08 13:21:33.0015 1864 Scan started 2011/07/08 13:21:33.0015 1864 Mode: Manual; 2011/07/08 13:21:33.0015 1864 ================================================================================ 2011/07/08 13:21:33.0359 1864 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 2011/07/08 13:21:33.0406 1864 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/07/08 13:21:33.0437 1864 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2011/07/08 13:21:33.0468 1864 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 2011/07/08 13:21:33.0484 1864 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/07/08 13:21:33.0546 1864 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys 2011/07/08 13:21:33.0625 1864 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 2011/07/08 13:21:33.0687 1864 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 2011/07/08 13:21:33.0750 1864 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 2011/07/08 13:21:33.0781 1864 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 2011/07/08 13:21:33.0796 1864 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 2011/07/08 13:21:33.0828 1864 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 2011/07/08 13:21:33.0859 1864 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 2011/07/08 13:21:33.0875 1864 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 2011/07/08 13:21:33.0890 1864 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 2011/07/08 13:21:33.0953 1864 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 2011/07/08 13:21:33.0984 1864 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 2011/07/08 13:21:34.0000 1864 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 2011/07/08 13:21:34.0031 1864 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 2011/07/08 13:21:34.0062 1864 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/07/08 13:21:34.0093 1864 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/07/08 13:21:34.0187 1864 ati2mtag (f5fc6ac1e7bc776871361d463fc86be2) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/07/08 13:21:34.0218 1864 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/07/08 13:21:34.0250 1864 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/07/08 13:21:34.0312 1864 Avgfwdx (0c5941af0b6bf2fdf378937392865217) C:\WINDOWS\system32\DRIVERS\avgfwdx.sys 2011/07/08 13:21:34.0328 1864 Avgfwfd (0c5941af0b6bf2fdf378937392865217) C:\WINDOWS\system32\DRIVERS\avgfwdx.sys 2011/07/08 13:21:34.0375 1864 AVGIDSDriver (c403e7f715bb0a851a9dfae16ec4ae42) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys 2011/07/08 13:21:34.0406 1864 AVGIDSEH (1af676db3f3d4cc709cfab2571cf5fc3) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys 2011/07/08 13:21:34.0421 1864 AVGIDSFilter (4c51e233c87f9ec7598551de554bc99d) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys 2011/07/08 13:21:34.0437 1864 AVGIDSShim (c3fc426e54f55c1cc3219e415b88e10c) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys 2011/07/08 13:21:34.0468 1864 Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\WINDOWS\system32\DRIVERS\avgldx86.sys 2011/07/08 13:21:34.0500 1864 Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 2011/07/08 13:21:34.0515 1864 Avgrkx86 (d1baf652eda0ae70896276a1fb32c2d4) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 2011/07/08 13:21:34.0546 1864 Avgtdix (aaf0ebcad95f2164cffb544e00392498) C:\WINDOWS\system32\DRIVERS\avgtdix.sys 2011/07/08 13:21:34.0593 1864 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/07/08 13:21:34.0640 1864 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\Drivers\BrScnUsb.sys 2011/07/08 13:21:34.0718 1864 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 2011/07/08 13:21:34.0734 1864 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/07/08 13:21:34.0750 1864 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 2011/07/08 13:21:34.0812 1864 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/07/08 13:21:34.0859 1864 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/07/08 13:21:34.0890 1864 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/07/08 13:21:34.0953 1864 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 2011/07/08 13:21:35.0015 1864 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 2011/07/08 13:21:35.0078 1864 ctsfm2k (8db84de3aab34a8b4c2f644eff41cd76) C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys 2011/07/08 13:21:35.0140 1864 CTUSFSYN (4ee8822adb764edd28ce44e808097995) C:\WINDOWS\system32\drivers\ctusfsyn.sys 2011/07/08 13:21:35.0171 1864 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 2011/07/08 13:21:35.0203 1864 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 2011/07/08 13:21:35.0234 1864 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/07/08 13:21:35.0281 1864 DKRtWrt (42823617433f6f9463e627644e716358) C:\WINDOWS\system32\DRIVERS\DKRtWrt.sys 2011/07/08 13:21:35.0343 1864 DLABOIOM (e2d0de31442390c35e3163c87cb6a9eb) C:\WINDOWS\system32\DLA\DLABOIOM.SYS 2011/07/08 13:21:35.0375 1864 DLACDBHM (d979bebcf7edcc9c9ee1857d1a68c67b) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS 2011/07/08 13:21:35.0390 1864 DLADResN (83545593e297f50a8e2524b4c071a153) C:\WINDOWS\system32\DLA\DLADResN.SYS 2011/07/08 13:21:35.0421 1864 DLAIFS_M (96e01d901cdc98c7817155cc057001bf) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS 2011/07/08 13:21:35.0437 1864 DLAOPIOM (0a60a39cc5e767980a31ca5d7238dfa9) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS 2011/07/08 13:21:35.0468 1864 DLAPoolM (9fe2b72558fc808357f427fd83314375) C:\WINDOWS\system32\DLA\DLAPoolM.SYS 2011/07/08 13:21:35.0484 1864 DLARTL_N (7ee0852ae8907689df25049dcd2342e8) C:\WINDOWS\system32\Drivers\DLARTL_N.SYS 2011/07/08 13:21:35.0515 1864 DLAUDFAM (f08e1dafac457893399e03430a6a1397) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS 2011/07/08 13:21:35.0531 1864 DLAUDF_M (e7d105ed1e694449d444a9933df8e060) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS 2011/07/08 13:21:35.0578 1864 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/07/08 13:21:35.0656 1864 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 2011/07/08 13:21:35.0671 1864 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/07/08 13:21:35.0703 1864 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/07/08 13:21:35.0734 1864 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 2011/07/08 13:21:35.0765 1864 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/07/08 13:21:35.0828 1864 DRVMCDB (fd0f95981fef9073659d8ec58e40aa3c) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS 2011/07/08 13:21:35.0875 1864 DRVNDDM (b4869d320428cdc5ec4d7f5e808e99b5) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS 2011/07/08 13:21:35.0968 1864 DSproct (2ac2372ffad9adc85672cc8e8ae14be9) C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys 2011/07/08 13:21:36.0000 1864 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys 2011/07/08 13:21:36.0062 1864 e1express (00192f0c612591d585594e9467e6ca8b) C:\WINDOWS\system32\DRIVERS\e1e5132.sys 2011/07/08 13:21:36.0093 1864 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/07/08 13:21:36.0125 1864 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 2011/07/08 13:21:36.0140 1864 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/07/08 13:21:36.0171 1864 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2011/07/08 13:21:36.0234 1864 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/07/08 13:21:36.0265 1864 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/07/08 13:21:36.0296 1864 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/07/08 13:21:36.0328 1864 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 2011/07/08 13:21:36.0375 1864 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/07/08 13:21:36.0406 1864 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/07/08 13:21:36.0453 1864 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/07/08 13:21:36.0484 1864 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 2011/07/08 13:21:36.0515 1864 HSFHWBS2 (77e4ff0b73bc0aeaaf39bf0c8104231f) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys 2011/07/08 13:21:36.0625 1864 HSF_DP (60e1604729a15ef4a3b05f298427b3b1) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 2011/07/08 13:21:36.0703 1864 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/07/08 13:21:36.0734 1864 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 2011/07/08 13:21:36.0765 1864 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 2011/07/08 13:21:36.0796 1864 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/07/08 13:21:36.0859 1864 iaStor (019cf5f31c67030841233c545a0e217a) C:\WINDOWS\system32\drivers\iaStor.sys 2011/07/08 13:21:36.0875 1864 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/07/08 13:21:36.0906 1864 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 2011/07/08 13:21:36.0937 1864 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 2011/07/08 13:21:36.0968 1864 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/07/08 13:21:36.0984 1864 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/07/08 13:21:37.0015 1864 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/07/08 13:21:37.0031 1864 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/07/08 13:21:37.0062 1864 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/07/08 13:21:37.0093 1864 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/07/08 13:21:37.0125 1864 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/07/08 13:21:37.0156 1864 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/07/08 13:21:37.0203 1864 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/07/08 13:21:37.0234 1864 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2011/07/08 13:21:37.0265 1864 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/07/08 13:21:37.0312 1864 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/07/08 13:21:37.0359 1864 LBeepKE (b28c741ae2912a079cf90041a9e5c0a4) C:\WINDOWS\system32\Drivers\LBeepKE.sys 2011/07/08 13:21:37.0406 1864 LHidFilt (24e0ddb99aeccf86bb37702611761459) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys 2011/07/08 13:21:37.0421 1864 LHidKe (dd40c03d85649205ec086722474c8a63) C:\WINDOWS\system32\DRIVERS\LHidKE.Sys 2011/07/08 13:21:37.0468 1864 LMouFilt (d58b330d318361a66a9fe60d7c9b4951) C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys 2011/07/08 13:21:37.0500 1864 LMouKE (2ebd4c02d259944869630a912ec86bce) C:\WINDOWS\system32\DRIVERS\LMouKE.Sys 2011/07/08 13:21:37.0531 1864 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 2011/07/08 13:21:37.0562 1864 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/07/08 13:21:37.0625 1864 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/07/08 13:21:37.0640 1864 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 2011/07/08 13:21:37.0734 1864 monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\monfilt.sys 2011/07/08 13:21:37.0796 1864 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/07/08 13:21:37.0843 1864 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/07/08 13:21:37.0875 1864 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/07/08 13:21:37.0906 1864 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 2011/07/08 13:21:37.0984 1864 MREMPR5 (2bc9e43f55de8c30fc817ed56d0ee907) C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS 2011/07/08 13:21:38.0031 1864 MRENDIS5 (594b9d8194e3f4ecbf0325bd10bbeb05) C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS 2011/07/08 13:21:38.0078 1864 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/07/08 13:21:38.0140 1864 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/07/08 13:21:38.0171 1864 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/07/08 13:21:38.0203 1864 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/07/08 13:21:38.0218 1864 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/07/08 13:21:38.0234 1864 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/07/08 13:21:38.0250 1864 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/07/08 13:21:38.0296 1864 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/07/08 13:21:38.0328 1864 NAL (1e59aaed42a5e3a5ed86ec403f9c0776) C:\WINDOWS\system32\Drivers\iqvw32.sys 2011/07/08 13:21:38.0375 1864 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/07/08 13:21:38.0390 1864 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/07/08 13:21:38.0421 1864 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/07/08 13:21:38.0453 1864 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/07/08 13:21:38.0515 1864 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/07/08 13:21:38.0546 1864 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 2011/07/08 13:21:38.0609 1864 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/07/08 13:21:38.0671 1864 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 2011/07/08 13:21:38.0703 1864 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/07/08 13:21:38.0750 1864 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/07/08 13:21:38.0796 1864 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/07/08 13:21:38.0875 1864 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2011/07/08 13:21:38.0906 1864 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/07/08 13:21:38.0921 1864 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/07/08 13:21:38.0968 1864 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys 2011/07/08 13:21:39.0000 1864 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys 2011/07/08 13:21:39.0015 1864 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys 2011/07/08 13:21:39.0062 1864 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 2011/07/08 13:21:39.0109 1864 ossrv (103a9b117a7d9903111955cdafe65ac6) C:\WINDOWS\system32\DRIVERS\ctoss2k.sys 2011/07/08 13:21:39.0140 1864 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 2011/07/08 13:21:39.0171 1864 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/07/08 13:21:39.0203 1864 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/07/08 13:21:39.0234 1864 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/07/08 13:21:39.0281 1864 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/07/08 13:21:39.0296 1864 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 2011/07/08 13:21:39.0375 1864 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 2011/07/08 13:21:39.0390 1864 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 2011/07/08 13:21:39.0437 1864 PfModNT (ede8241b75dadef090aadb6c81c8e1d7) C:\WINDOWS\system32\drivers\PfModNT.sys 2011/07/08 13:21:39.0468 1864 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/07/08 13:21:39.0515 1864 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/07/08 13:21:39.0546 1864 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/07/08 13:21:39.0609 1864 PxHelp20 (49452bfcec22f36a7a9b9c2181bc3042) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2011/07/08 13:21:39.0625 1864 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 2011/07/08 13:21:39.0640 1864 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 2011/07/08 13:21:39.0671 1864 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 2011/07/08 13:21:39.0687 1864 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 2011/07/08 13:21:39.0703 1864 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 2011/07/08 13:21:39.0734 1864 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/07/08 13:21:39.0781 1864 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/07/08 13:21:39.0812 1864 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/07/08 13:21:39.0843 1864 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/07/08 13:21:39.0875 1864 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/07/08 13:21:39.0890 1864 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/07/08 13:21:39.0921 1864 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/07/08 13:21:39.0968 1864 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/07/08 13:21:40.0015 1864 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/07/08 13:21:40.0093 1864 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/07/08 13:21:40.0125 1864 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/07/08 13:21:40.0156 1864 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/07/08 13:21:40.0203 1864 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\DRIVERS\sfloppy.sys 2011/07/08 13:21:40.0234 1864 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 2011/07/08 13:21:40.0265 1864 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 2011/07/08 13:21:40.0328 1864 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/07/08 13:21:40.0390 1864 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/07/08 13:21:40.0421 1864 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/07/08 13:21:40.0515 1864 STHDA (797fcc1d859b203958e915bb82528da9) C:\WINDOWS\system32\drivers\sthda.sys 2011/07/08 13:21:40.0578 1864 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/07/08 13:21:40.0640 1864 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/07/08 13:21:40.0687 1864 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 2011/07/08 13:21:40.0703 1864 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 2011/07/08 13:21:40.0734 1864 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 2011/07/08 13:21:40.0750 1864 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 2011/07/08 13:21:40.0796 1864 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/07/08 13:21:40.0859 1864 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/07/08 13:21:40.0890 1864 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/07/08 13:21:40.0906 1864 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/07/08 13:21:40.0921 1864 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/07/08 13:21:40.0968 1864 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 2011/07/08 13:21:40.0984 1864 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/07/08 13:21:41.0015 1864 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 2011/07/08 13:21:41.0078 1864 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/07/08 13:21:41.0156 1864 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\WINDOWS\system32\Drivers\usbaapl.sys 2011/07/08 13:21:41.0187 1864 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/07/08 13:21:41.0218 1864 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/07/08 13:21:41.0234 1864 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/07/08 13:21:41.0250 1864 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/07/08 13:21:41.0312 1864 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/07/08 13:21:41.0375 1864 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/07/08 13:21:41.0390 1864 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/07/08 13:21:41.0421 1864 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/07/08 13:21:41.0468 1864 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 2011/07/08 13:21:41.0484 1864 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 2011/07/08 13:21:41.0515 1864 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/07/08 13:21:41.0562 1864 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/07/08 13:21:41.0640 1864 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 2011/07/08 13:21:41.0687 1864 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/07/08 13:21:41.0734 1864 winachsf (f59ed5a43b988a18ef582bb07b2327a7) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 2011/07/08 13:21:41.0828 1864 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/07/08 13:21:41.0843 1864 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/07/08 13:21:41.0890 1864 MBR (0x1B8) (5cb90281d1a59b251f6603134774eec3) \Device\Harddisk0\DR0 2011/07/08 13:21:41.0906 1864 Boot (0x1200) (9284d81ffa29bb7ef1f95965b6c0e682) \Device\Harddisk0\DR0\Partition0 2011/07/08 13:21:41.0921 1864 ================================================================================ 2011/07/08 13:21:41.0921 1864 Scan finished 2011/07/08 13:21:41.0921 1864 ================================================================================ 2011/07/08 13:21:41.0921 1072 Detected object count: 0 2011/07/08 13:21:41.0921 1072 Actual detected object count: 0
After ESET scanner was run, one threat was detected. C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1564\A0445763.dll Win32/Adware.AntiSpyware2008 application OK, done with the most recent scans. Should I hide files now, or does it matter?
Yes, go ahead and rehide files and folders, you PC is safer that way.

TDSSKiller found no rootkit, thats wonderful :thumbup:

What ESET found was in your System Restore Program


System Restore is a component of Microsoft's Windows Me, Windows XP, Windows Vista and Windows 7 operating systems that allows for the rolling back of system files, registry keys, installed programs, etc., to a previous state in the event of malfunctioning or failure. Old restore points can be a source of re-infection.

Please follow the steps below to create a clean restore point:
  • Click Start > Run > copy and paste the following into the run box:

    %SystemRoot%\System32\restore\rstrui.exe

  • Press OK. Choose Create a Restore Point then click Next.
  • Name it (something you'll remember) and click Create.
  • When the confirmation screen shows the restore point has been created click Close.

Then remove all previous Restore Points
  • Click Start > Run > copy and paste the following into the run box:

    cleanmgr

  • Choose to scan drive C:\ (if C:\ is your main drive).
  • At the top, click on More Options tab. Click the Clean up… button in the System Restore box.
  • Click on the Yes button.
  • When finished, click on Cancel button to exit.



How are things running now ?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI