This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Referred By Admin Doug - From Windows thread.

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, My computer is running slow and it was not opening .exe files, I was able to fix that problem but I wanted to make sure that it was not harmful software that caused it and if it was how to remove it. Admin Doug said there was a lot of Malware. Below I have attached the HiJackThis Log. Any help is much appreciated. Thank You.
Hello hrhwrlddom and Welcome to WhatTheTech Forums

My name is BlackPegasus.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for
    further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to
    get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out
    the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to
    ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
Hello hrhwrlddom

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
========================

NEXT

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
      Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

    =======================
    NEXT

    Please download aswMBR ( 511KB ) to your desktop.
    • Double click the aswMBR.exe icon to run it
    • Click the Scan button to start the scan
    • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
    =======================
    Please include in your next reply:
    1. Any problem executing the instructions?
    2. OTL log and Extras.Txt
    3. aswMBR log
No problems occurred!

OTL logfile created on: 8/5/2011 3:53:03 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\porcsha\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.53 Gb Available Physical Memory | 55.53% Memory free
5.70 Gb Paging File | 4.30 Gb Available in Paging File | 75.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.19 Gb Total Space | 72.19 Gb Free Space | 51.86% Space Free | Partition Type: NTFS
Drive D: | 9.85 Gb Total Space | 1.72 Gb Free Space | 17.45% Space Free | Partition Type: NTFS

Computer Name: CHEER | User Name: porcsha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\porcsha\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\AVAST Software\Avast\Setup\avast.setup (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\SelectRebates\SelectRebates.exe ()
PRC - C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
PRC - C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe (Affinegy, Inc.)
PRC - C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
PRC - C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\SiteRanker\SiteRankTray.exe (Crawler, LLC)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Crawler\Smileys\CSmileysIM.exe (Crawler.com)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Apple Software Update\SoftwareUpdate.exe (Apple Inc.)
PRC - C:\Windows\SMINST\BLService.exe ()
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\porcsha\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\AVAST Software\Avast\snxhk.dll (AVAST Software)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (LMIMaint) โ€“ C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) โ€“ C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (avast! Antivirus) โ€“ C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (LogMeIn) โ€“ C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (AffinegyService) โ€“ C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe (Affinegy, Inc.)
SRV - (Recovery Service for Windows) โ€“ C:\Windows\SMINST\BLService.exe ()
SRV - (WinDefend) โ€“ C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Viewpoint Manager Service) โ€“ C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Driver Services (SafeList) ==========

DRV - (LMIRfsClientNP) โ€“ C:\Windows\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (aswSnx) โ€“ C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) โ€“ C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) โ€“ C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRdr) โ€“ C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMonFlt) โ€“ C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) โ€“ C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (LMIRfsDriver) โ€“ C:\Windows\System32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) โ€“ C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (NVNET) โ€“ C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (NVENETFD) โ€“ C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (nvlddmkm) โ€“ C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (SMSIVZAM5) โ€“ C:\Program Files\Verizon Wireless\VZAccess Manager\SMSIVZAM5.sys (Smith Micro Inc.)
DRV - (PTDUWWAN) โ€“ C:\Windows\System32\drivers\PTDUWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDUVsp) โ€“ C:\Windows\System32\drivers\PTDUVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDUMdm) โ€“ C:\Windows\System32\drivers\PTDUMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDUBus) โ€“ C:\Windows\System32\drivers\PTDUBus.sys (DEVGURU Co,LTD.)
DRV - (NWUSBCDFIL) โ€“ C:\Windows\System32\drivers\NwUsbCdFil.sys (Novatel Wireless Inc.)
DRV - (CnxtHdAudService) โ€“ C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (NWADI) โ€“ C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NVHDA) โ€“ C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (NWUSBPort2) โ€“ C:\Windows\System32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) โ€“ C:\Windows\System32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) โ€“ C:\Windows\System32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (athr) โ€“ C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (nvsmu) โ€“ C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (XAudio) โ€“ C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) โ€“ C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (busbcrw) โ€“ C:\Windows\System32\drivers\busbcrw.sys (Brother Industries, Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&aโ€ฆion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&aโ€ฆion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80126
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80126

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&aโ€ฆion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/dispatcherโ€ฆ%tb_id%language
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Crawler Search"
FF - prefs.js..browser.search.order.1: "Crawler Search"
FF - prefs.js..browser.search.selectedEngine: "Inbox Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.inbox.com/?tbid=80126"
FF - prefs.js..extensions.enabledItems: {4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:5.2.0.0
FF - prefs.js..keyword.URL: "http://toolbar.inbox.com/search/dispatcher.aspx?tp=sf&tbid=80126&language=en&qkw="
FF - prefs.js..keyword.defaultURL: "http://www.crawler.com/search/dispatcher.aspx?tp=aus&tbid=60194&qkw="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: C:\Users\porcsha\AppData\Roaming\nprhapengine.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2008/08/04 13:35:27 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}: C:\Program Files\Crawler\Toolbar\firefox\ [2009/08/06 20:06:52 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\SiteRanker\firefox\ [2009/08/06 20:07:16 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/08/01 16:59:23 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/12/03 12:06:32 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/15 22:10:19 | 000,000,000 | โ€”D | M]

[2010/02/11 15:40:52 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\porcsha\AppData\Roaming\mozilla\Extensions
[2010/02/11 15:40:52 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\porcsha\AppData\Roaming\mozilla\Extensions\[removed]
[2011/08/01 16:23:23 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\porcsha\AppData\Roaming\mozilla\Firefox\Profiles\qn4pia2z.default\extensions
[2009/12/18 00:30:38 | 000,000,000 | โ€”D | M] (Microsoft .NET Framework Assistant) โ€“ C:\Users\porcsha\AppData\Roaming\mozilla\Firefox\Profiles\qn4pia2z.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/06 20:05:15 | 000,000,000 | โ€”D | M] ("Inbox Toolbar") โ€“ C:\Users\porcsha\AppData\Roaming\mozilla\Firefox\Profiles\qn4pia2z.default\extensions\[removed]
[2011/05/09 20:26:43 | 000,000,000 | โ€”D | M] (ShopAtHome.com Intelligent Shopping Toolbar) โ€“ C:\Users\porcsha\AppData\Roaming\mozilla\Firefox\Profiles\qn4pia2z.default\extensions\[removed]
[2009/11/08 18:51:28 | 000,002,168 | โ€”- | M] () โ€“ C:\Users\porcsha\AppData\Roaming\Mozilla\Firefox\Profiles\qn4pia2z.default\searchplugins\inbox-search.xml
[2009/05/23 19:23:43 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Program Files\Mozilla Firefox\extensions
[2009/08/06 20:06:52 | 000,000,000 | โ€”D | M] (Crawler Toolbar) โ€“ C:\PROGRAM FILES\CRAWLER\TOOLBAR\FIREFOX
[2009/08/06 20:07:16 | 000,000,000 | โ€”D | M] (SiteRanker) โ€“ C:\PROGRAM FILES\SITERANKER\FIREFOX
[2007/07/26 12:05:16 | 000,001,329 | โ€”- | M] () โ€“ C:\Program Files\mozilla firefox\searchplugins\crawlersrch.xml

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | โ€”- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: () - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\Program Files\SiteRanker\SiteRank.dll (Crawler, LLC)
O2 - BHO: () - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
O3 - HKLM\..\Toolbar: (&Crawler Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Crawler Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKCU\..\Toolbar\WebBrowser: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
O3 - HKCU\..\Toolbar\WebBrowser: (&Inbox Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [CSmileys] C:\Program Files\Crawler\Smileys\CSmileysIM.exe (Crawler.com)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SelectRebates] C:\Program Files\SelectRebates\SelectRebates.exe ()
O4 - HKLM..\Run: [SiteRanker] C:\Program Files\SiteRanker\SiteRankTray.exe (Crawler, LLC)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [4Y3Y0C3AUYVV4Y9GCYBOPHFEUNNFBI] File not found
O4 - HKCU..\Run: [CSmileys] C:\Program Files\Crawler\Smileys\CSmileysIM.exe (Crawler.com)
O4 - HKCU..\Run: [lpc] File not found
O4 - HKCU..\Run: [uswqpwkn] File not found
O4 - Startup: C:\Users\porcsha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)
O15 - HKCU\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} http://vsp.closetmaid.com/vsp/cmaidctl_vspโ€ฆ_downloader.cab (Closet Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} http://panda-plugin.disney.go.com/plugin/wโ€ฆ/p3dactivex.cab (P3DActiveX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - File not found
O18 - Protocol\Handler\tbr {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\porcsha\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\porcsha\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O27 - HKLM IFEO\ehshell.exe: Debugger - "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" -MceShellRedirect (LogMeIn, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/04 13:03:40 | 000,000,074 | โ€”- | M] () - C:\autoexec.bat โ€“ [ NTFS ]
O33 - MountPoints2\{689b8ac7-fd5c-11de-b821-001f164d2e66}\Shell\AutoRun\command - "" = F:\Autorun.exe /run
O33 - MountPoints2\{689b8ac7-fd5c-11de-b821-001f164d2e66}\Shell\Shell00\Command - "" = F:\Autorun.exe /run
O33 - MountPoints2\{689b8ac7-fd5c-11de-b821-001f164d2e66}\Shell\Shell01\Command - "" = F:\Autorun.exe /action
O33 - MountPoints2\{689b8ac7-fd5c-11de-b821-001f164d2e66}\Shell\Shell02\Command - "" = F:\Autorun.exe /uninstall
O33 - MountPoints2\{7ccd79e3-d33f-11dd-9f62-001f164d2e66}\Shell - "" = AutoRun
O33 - MountPoints2\{7ccd79e3-d33f-11dd-9f62-001f164d2e66}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{c1d90387-f4aa-11de-94a8-001f164d2e66}\Shell - "" = AutoRun
O33 - MountPoints2\{c1d90387-f4aa-11de-94a8-001f164d2e66}\Shell\AutoRun\command - "" = F:\VZAccess_Manager.exe /z detect
O33 - MountPoints2\{c1d903c0-f4aa-11de-94a8-001f164d2e66}\Shell - "" = AutoRun
O33 - MountPoints2\{c1d903c0-f4aa-11de-94a8-001f164d2e66}\Shell\AutoRun\command - "" = G:\VZAccess_Manager.exe /z detect
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O35 - HKCU\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*
O37 - HKCU\โ€ฆexe [@ = exefile] โ€“ "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/05 16:13:48 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/08/05 16:12:26 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Microsoft Silverlight
[2011/08/05 15:55:31 | 000,758,784 | โ€”- | C] (NVIDIA Corporation) โ€“ C:\Windows\System32\cohelper.dll
[2011/08/05 15:55:21 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\NVIDIA Corporation
[2011/08/05 15:55:14 | 000,000,000 | โ€”D | C] โ€“ C:\Windows\LastGood
[2011/08/05 15:49:50 | 000,579,584 | โ€”- | C] (OldTimer Tools) โ€“ C:\Users\porcsha\Desktop\OTL.exe
[2011/08/01 17:07:24 | 000,388,608 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Users\porcsha\Desktop\HiJackThis.exe
[2011/08/01 16:59:56 | 000,019,544 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\drivers\aswFsBlk.sys
[2011/08/01 16:59:56 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2011/08/01 16:59:55 | 000,309,848 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\drivers\aswSP.sys
[2011/08/01 16:59:51 | 000,043,608 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\drivers\aswTdi.sys
[2011/08/01 16:59:51 | 000,025,432 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\drivers\aswRdr.sys
[2011/08/01 16:59:50 | 000,441,176 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\drivers\aswSnx.sys
[2011/08/01 16:59:48 | 000,054,104 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\drivers\aswMonFlt.sys
[2011/08/01 16:59:12 | 000,040,112 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\avastSS.scr
[2011/08/01 16:59:11 | 000,199,304 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\aswBoot.exe
[2011/08/01 16:58:35 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\AVAST Software
[2011/08/01 16:58:35 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\AVAST Software
[2011/08/01 15:30:58 | 000,000,000 | โ€”D | C] โ€“ C:\Users\porcsha\AppData\Local\LogMeIn
[2011/08/01 15:30:44 | 000,029,568 | โ€”- | C] (LogMeIn, Inc.) โ€“ C:\Windows\System32\LMIport.dll
[2011/08/01 15:30:43 | 000,083,360 | โ€”- | C] (LogMeIn, Inc.) โ€“ C:\Windows\System32\LMIRfsClientNP.dll
[2011/08/01 15:30:43 | 000,047,640 | โ€”- | C] (LogMeIn, Inc.) โ€“ C:\Windows\System32\drivers\LMIRfsDriver.sys
[2011/08/01 15:30:31 | 000,087,424 | โ€”- | C] (LogMeIn, Inc.) โ€“ C:\Windows\System32\LMIinit.dll
[2011/08/01 15:30:21 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\LogMeIn
[2011/08/01 15:29:58 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\LogMeIn
[2011/08/01 15:23:56 | 000,000,000 | โ€”D | C] โ€“ C:\Users\porcsha\AppData\Local\Deployment
[2011/07/31 15:22:00 | 000,000,000 | โ€”D | C] โ€“ C:\Users\porcsha\AppData\Local\Apps
[2011/07/31 15:14:01 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Art Explosion
[2011/07/31 15:13:30 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Common Files\Nova Development
[2011/07/31 15:13:27 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Art Explosion
[2011/07/12 20:44:15 | 002,042,368 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\System32\win32k.sys
[2011/07/12 20:39:23 | 000,375,808 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\System32\winsrv.dll
[2011/07/12 20:39:22 | 000,049,152 | โ€”- | C] (Microsoft Corporation) โ€“ C:\Windows\System32\csrsrv.dll
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\porcsha\AppData\Local\*.tmp files -> C:\Users\porcsha\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/05 15:58:29 | 000,000,886 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/05 15:50:30 | 000,579,584 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\porcsha\Desktop\OTL.exe
[2011/08/05 15:47:44 | 000,032,061 | โ€”- | M] () โ€“ C:\ProgramData\nvModes.dat
[2011/08/05 15:47:41 | 000,032,061 | โ€”- | M] () โ€“ C:\ProgramData\nvModes.001
[2011/08/05 15:43:16 | 000,000,252 | โ€”- | M] () โ€“ C:\Users\Public\Documents\hpqp.ini
[2011/08/05 15:42:55 | 000,000,882 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/05 15:41:28 | 000,003,216 | -Hโ€“ | M] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/05 15:41:28 | 000,003,216 | -Hโ€“ | M] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/05 15:40:18 | 000,067,584 | โ€“S- | M] () โ€“ C:\Windows\bootstat.dat
[2011/08/05 15:40:14 | 2951,049,216 | -HS- | M] () โ€“ C:\hiberfil.sys
[2011/08/04 18:35:28 | 000,604,502 | โ€”- | M] () โ€“ C:\Windows\System32\perfh009.dat
[2011/08/04 18:35:28 | 000,104,170 | โ€”- | M] () โ€“ C:\Windows\System32\perfc009.dat
[2011/08/04 18:33:23 | 000,000,422 | -Hโ€“ | M] () โ€“ C:\Windows\tasks\User_Feed_Synchronization-{55E760F5-400F-4276-AF87-EDD068F0DA7C}.job
[2011/08/02 21:57:00 | 000,042,496 | โ€”- | M] () โ€“ C:\Users\porcsha\Documents\baby shower invite.fiv
[2011/08/01 17:07:32 | 000,388,608 | โ€”- | M] (Trend Micro Inc.) โ€“ C:\Users\porcsha\Desktop\HiJackThis.exe
[2011/08/01 16:59:56 | 000,001,829 | โ€”- | M] () โ€“ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/08/01 16:59:48 | 000,002,577 | โ€”- | M] () โ€“ C:\Windows\System32\config.nt
[2011/08/01 16:09:00 | 216,197,095 | โ€”- | M] () โ€“ C:\Windows\MEMORY.DMP
[2011/08/01 15:30:28 | 000,001,024 | โ€”- | M] () โ€“ C:\.rnd
[2011/07/31 16:36:53 | 000,350,368 | โ€”- | M] () โ€“ C:\Windows\System32\FNTCACHE.DAT
[2011/07/31 16:00:20 | 000,002,034 | โ€”- | M] () โ€“ C:\Users\porcsha\Application Data\Microsoft\Internet Explorer\Quick Launch\Greeting Card Factory (3).lnk
[2011/07/31 15:18:43 | 000,002,034 | โ€”- | M] () โ€“ C:\Users\porcsha\Application Data\Microsoft\Internet Explorer\Quick Launch\Greeting Card Factory (2).lnk
[2011/07/31 15:17:04 | 000,002,034 | โ€”- | M] () โ€“ C:\Users\porcsha\Application Data\Microsoft\Internet Explorer\Quick Launch\Greeting Card Factory.lnk
[2011/07/28 18:23:15 | 000,000,330 | โ€”- | M] () โ€“ C:\Windows\tasks\HPCeeScheduleForporcsha.job
[2011/07/23 12:07:16 | 000,210,984 | โ€”- | M] () โ€“ C:\Users\porcsha\Documents\CouponAlert.exe
[2011/07/06 20:52:13 | 000,487,317 | โ€”- | M] () โ€“ C:\Users\porcsha\Documents\bird.JPG
[2011/07/06 16:32:50 | 000,083,360 | โ€”- | M] (LogMeIn, Inc.) โ€“ C:\Windows\System32\LMIRfsClientNP.dll
[2011/07/06 16:32:30 | 000,029,568 | โ€”- | M] (LogMeIn, Inc.) โ€“ C:\Windows\System32\LMIport.dll
[2011/07/06 16:32:28 | 000,087,424 | โ€”- | M] (LogMeIn, Inc.) โ€“ C:\Windows\System32\LMIinit.dll
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\porcsha\AppData\Local\*.tmp files -> C:\Users\porcsha\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/01 20:24:45 | 000,042,496 | โ€”- | C] () โ€“ C:\Users\porcsha\Documents\baby shower invite.fiv
[2011/08/01 16:59:56 | 000,001,829 | โ€”- | C] () โ€“ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/08/01 15:30:25 | 000,001,024 | โ€”- | C] () โ€“ C:\.rnd
[2011/08/01 15:30:04 | 000,000,865 | โ€”- | C] () โ€“ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn.lnk
[2011/07/31 16:00:20 | 000,002,034 | โ€”- | C] () โ€“ C:\Users\porcsha\Application Data\Microsoft\Internet Explorer\Quick Launch\Greeting Card Factory (3).lnk
[2011/07/31 15:18:43 | 000,002,034 | โ€”- | C] () โ€“ C:\Users\porcsha\Application Data\Microsoft\Internet Explorer\Quick Launch\Greeting Card Factory (2).lnk
[2011/07/31 15:17:04 | 000,002,034 | โ€”- | C] () โ€“ C:\Users\porcsha\Application Data\Microsoft\Internet Explorer\Quick Launch\Greeting Card Factory.lnk
[2011/07/23 12:07:12 | 000,210,984 | โ€”- | C] () โ€“ C:\Users\porcsha\Documents\CouponAlert.exe
[2011/07/06 20:49:28 | 000,487,317 | โ€”- | C] () โ€“ C:\Users\porcsha\Documents\bird.JPG
[2011/05/16 13:50:40 | 000,000,208 | โ€”- | C] () โ€“ C:\ProgramData\h5776CnKiAdO6323
[2011/05/16 13:11:21 | 000,009,152 | -HS- | C] () โ€“ C:\ProgramData\2dhnh1n2qa
[2011/05/16 13:11:20 | 000,009,152 | -HS- | C] () โ€“ C:\Users\porcsha\AppData\Local\2dhnh1n2qa
[2009/09/17 06:24:36 | 000,000,680 | โ€”- | C] () โ€“ C:\Users\porcsha\AppData\Local\d3d9caps.dat
[2009/08/03 16:07:42 | 000,403,816 | โ€”- | C] () โ€“ C:\Windows\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | โ€”- | C] () โ€“ C:\Windows\System32\OGAEXEC.exe
[2009/06/15 22:32:26 | 000,009,728 | โ€”- | C] () โ€“ C:\Users\porcsha\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/30 17:57:33 | 000,000,004 | โ€”- | C] () โ€“ C:\Users\porcsha\AppData\Roaming\B69CEF
[2009/05/30 17:57:32 | 000,870,128 | โ€”- | C] () โ€“ C:\Users\porcsha\AppData\Roaming\mcs.rma
[2009/03/21 10:36:19 | 000,106,605 | โ€”- | C] () โ€“ C:\Windows\System32\StructuredQuerySchema.bin
[2009/03/21 10:36:19 | 000,018,904 | โ€”- | C] () โ€“ C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/12/26 03:09:45 | 000,032,061 | โ€”- | C] () โ€“ C:\ProgramData\nvModes.001
[2008/12/26 03:03:48 | 000,032,061 | โ€”- | C] () โ€“ C:\ProgramData\nvModes.dat
[2008/11/06 21:03:54 | 000,011,164 | โ€”- | C] () โ€“ C:\Windows\System32\drivers\nvphy.bin
[2008/08/04 13:19:17 | 000,101,605 | โ€”- | C] () โ€“ C:\Windows\hpqins13.dat
[2006/11/02 07:57:28 | 000,067,584 | โ€“S- | C] () โ€“ C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,350,368 | โ€”- | C] () โ€“ C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | โ€”- | C] () โ€“ C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,604,502 | โ€”- | C] () โ€“ C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | โ€”- | C] () โ€“ C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,104,170 | โ€”- | C] () โ€“ C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | โ€”- | C] () โ€“ C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | โ€”- | C] () โ€“ C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | โ€”- | C] () โ€“ C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | โ€”- | C] () โ€“ C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | โ€”- | C] () โ€“ C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | โ€”- | C] () โ€“ C:\Windows\System32\mlang.dat
[2006/03/09 04:58:00 | 001,060,424 | โ€”- | C] () โ€“ C:\Windows\System32\WdfCoInstaller01000.dll

========== LOP Check ==========

[2010/07/06 17:42:27 | 000,000,000 | โ€”D | M] โ€“ C:\Users\porcsha\AppData\Roaming\Canon
[2008/12/25 19:58:23 | 000,000,000 | โ€”D | M] โ€“ C:\Users\porcsha\AppData\Roaming\iWin
[2011/08/05 15:44:17 | 000,000,000 | โ€”D | M] โ€“ C:\Users\porcsha\AppData\Roaming\LimeWire
[2010/09/28 17:50:40 | 000,000,000 | โ€”D | M] โ€“ C:\Users\porcsha\AppData\Roaming\Smith Micro
[2008/12/25 23:59:10 | 000,000,000 | โ€”D | M] โ€“ C:\Users\porcsha\AppData\Roaming\Snapfish
[2008/12/26 02:35:23 | 000,000,000 | โ€”D | M] โ€“ C:\Users\porcsha\AppData\Roaming\WildTangent
[2011/08/04 23:15:22 | 000,032,558 | โ€”- | M] () โ€“ C:\Windows\Tasks\SCHEDLGU.TXT
[2011/08/04 18:33:23 | 000,000,422 | -Hโ€“ | M] () โ€“ C:\Windows\Tasks\User_Feed_Synchronization-{55E760F5-400F-4276-AF87-EDD068F0DA7C}.job

========== Purity Check ==========



< End of report >
aswMBR version 0.9.8.978 Copyrightยฉ 2011 AVAST Software Run date: 2011-08-05 16:51:29 โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“ 16:51:29.601 OS Version: Windows 6.0.6001 Service Pack 1 16:51:29.602 Number of processors: 1 586 0x301 16:51:29.615 ComputerName: CHEER UserName: 16:51:42.878 Initialize success 16:51:44.774 AVAST engine defs: 11080501 16:51:48.681 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-5 16:51:48.730 Disk 0 Vendor: Hitachi_HTS543216L9A300 FB2OC44C Size: 152627MB BusType: 3 16:51:50.792 Disk 0 MBR read successfully 16:51:50.798 Disk 0 MBR scan 16:51:50.805 Disk 0 unknown MBR code 16:51:50.847 Disk 0 scanning sectors +312573952 16:51:51.062 Disk 0 scanning C:\Windows\system32\drivers 16:52:44.090 Service scanning 16:52:46.581 Modules scanning 16:53:27.012 Disk 0 trace - called modules: 16:53:27.043 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys 16:53:27.051 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86753ac8] 16:53:27.063 3 CLASSPNP.SYS[807a3745] -> nt!IofCallDriver -> [0x857b0570] 16:53:27.099 5 acpi.sys[806116a0] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-5[0x8611d830] 16:53:28.068 AVAST engine scan C:\Windows 16:53:50.783 AVAST engine scan C:\Windows\system32 16:56:51.843 AVAST engine scan C:\Windows\system32\drivers 16:57:05.022 AVAST engine scan C:\Users\porcsha 17:15:58.829 AVAST engine scan C:\ProgramData 17:22:38.898 Scan finished successfully 20:08:31.614 Disk 0 MBR has been saved successfully to "C:\Users\porcsha\Desktop\MBR.dat" 20:08:31.631 The log file has been saved successfully to "C:\Users\porcsha\Desktop\aswMBR.txt"
Hello hrhwrlddom

I'm going through your log now. When you ran OTL two logs were produced you posted the OTL scan, could you please post the Extras.Txt. You can find the Extras.txt logs located in the OTL folder on you C:\ drive.
Sorry about that.

OTL Extras logfile created on: 8/5/2011 3:53:03 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\porcsha\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.53 Gb Available Physical Memory | 55.53% Memory free
5.70 Gb Paging File | 4.30 Gb Available in Paging File | 75.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.19 Gb Total Space | 72.19 Gb Free Space | 51.86% Space Free | Partition Type: NTFS
Drive D: | 9.85 Gb Total Space | 1.72 Gb Free Space | 17.45% Space Free | Partition Type: NTFS

Computer Name: CHEER | User Name: porcsha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] โ€“ C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] โ€“ C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ€“ "%1" %*
cmdfile [open] โ€“ "%1" %*
comfile [open] โ€“ "%1" %*
cplfile [cplopen] โ€“ %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] โ€“ "%1" %*
helpfile [open] โ€“ Reg Error: Key error.
hlpfile [open] โ€“ %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] โ€“ %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] โ€“ "%1" %*
regfile [merge] โ€“ Reg Error: Key error.
scrfile [config] โ€“ "%1"
scrfile [install] โ€“ rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] โ€“ "%1" /S
txtfile โ€“ Reg Error: Key error.
Unknown [openas] โ€“ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] โ€“ cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] โ€“ %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] โ€“ %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0 โ€“ ()
"InternetSettingsDisableNotify" = 0 โ€“ ()
"AutoUpdateDisableNotify" = 0 โ€“ ()

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0 โ€“ ()
"AntiSpywareOverride" = 0 โ€“ ()
"FirewallOverride" = 0 โ€“ ()
"VistaSp1" = Reg Error: Unknown registry data type โ€“ File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0 โ€“ ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0 โ€“ ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0 โ€“ ()

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{088B728D-2201-4231-89AF-C15C647CBB56}" = lport=138 | protocol=17 | dir=in | app=system |
"{0972543B-5117-4DB1-994C-0CF068E44F9F}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{0CD9FE66-9B97-45E6-B789-8C8C4BB2FFE4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{19B2D215-3662-417B-86FD-6DD224DF6A45}" = lport=139 | protocol=6 | dir=in | app=system |
"{20554C4D-0C32-40F0-92FE-F1368148532B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{271D9329-29E6-4A99-AB80-7F492921B63C}" = rport=445 | protocol=6 | dir=out | app=system |
"{3071A32D-ADB2-4936-8DC8-7FE63BE41D54}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{44BFCBF3-0B8B-4408-A9EF-66EBD4502A50}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{47CA7524-6EF0-4E20-8AFA-6C3E9BC5376A}" = lport=445 | protocol=6 | dir=in | app=system |
"{4BEAFEA1-ED81-4FAD-B51D-98DAD3769772}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{51FB7E88-1823-465B-9EA9-A58E35D1A4C0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5514E6A8-BBE6-403C-AB90-1D2697439072}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{5793898C-EFF5-47EC-81F5-38F1469E327E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5D8232B5-5221-4102-8991-A72CE87E8951}" = rport=138 | protocol=17 | dir=out | app=system |
"{5E3E9D65-4844-4A5C-97C7-E3415627DF0E}" = rport=137 | protocol=17 | dir=out | app=system |
"{62E77FF5-7EC7-46EA-BBA4-6CA0FC4ADF34}" = rport=139 | protocol=6 | dir=out | app=system |
"{727F93C0-9B71-4050-940E-A188A416E4E5}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{7FE45775-8CE9-4031-9F72-BC9D662F0E63}" = lport=137 | protocol=17 | dir=in | app=system |
"{82E10EDA-7C42-47F2-9730-9BA591C1A579}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{85418094-4CD2-4897-9C57-4D91E284FB0D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{855F1AA4-40BB-4B72-9EE4-61427B68D99D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{983DA7B7-ABEE-4CF4-A467-25620182BA82}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{BBC3F721-D57F-48A3-884A-B587658F398A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BFC9F311-41AC-41F1-BB2E-BD1171A848FE}" = rport=2869 | protocol=6 | dir=out | app=system |
"{DA8CCC0D-60AB-4634-B451-848D82FB769B}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{E5441B4E-D386-487D-AE75-9830746C13AE}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{053E5549-ECD5-4FE4-8DB9-641DFB10CF77}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{0B6A7EE6-2EA1-4A6E-8DFD-93EA5830B778}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{0C006C1F-1C9E-4076-8740-7BA29B0B0E5E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{1DA64217-74EC-4022-9D57-447EECAD1E4B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{26D8C13B-0A9C-4495-A3C3-0E46B9356334}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{2BC0AA3D-53F4-44B4-BFE3-4309B80E25CF}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{360E3640-FB26-4DEF-8288-8B53B8EBB28A}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{46A714F4-A1D4-4B54-8DEB-2E2F0B52AB27}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{49FBA551-93F7-4867-BB42-5E0862E7F8A2}" = protocol=6 | dir=in | app=c:\program files\belkin\router setup and monitor\belkinsetup.exe |
"{4CBF8642-44B4-4410-9960-2365E4946BF3}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{4FB66750-D9CF-41C2-953C-46E3589447DB}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{50097AE8-CEBC-461C-87D6-55BACB2785B9}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{83D95BD1-8408-489C-B2CA-5EEFD93A079E}" = protocol=17 | dir=in | app=c:\program files\belkin\router setup and monitor\belkinsetup.exe |
"{8A9074D8-887C-460B-9A09-B7E62693DA35}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{8B50FD6A-B1F9-400F-84B0-EBDADF403559}" = protocol=17 | dir=in | app=c:\program files\belkin\router setup and monitor\belkinsetup.exe |
"{A8A1DA03-6E90-403A-A707-E439E0507310}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B78A2294-6B09-416E-B2D7-0ACFDAC290BA}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BE34B1AF-F991-4F6F-8C48-F780C4CF9A96}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{C1BAABB6-21B7-49B7-91E1-E455B4B6BC44}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{C55EE582-4D18-4465-B67C-01CCBFDC83AC}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{CA1E9A74-8FE0-49FD-80B3-B964AD0C5314}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{CE417CC2-006D-44BC-B33A-291B02416FCB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{DD5F5C2C-0402-4DEE-BDC3-182E6679B7D2}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"{DDDBC024-385F-4612-922B-BA9B452774F6}" = dir=in | app=c:\program files\belkin\router setup and monitor\belkinsetup.exe |
"{DE72A683-015D-4B3E-A141-E9BE98FC2012}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{E7E1CB46-41C1-4BFF-A099-E9F5032AA50B}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{ED0B0AF2-8789-4D49-A431-3E38134A8398}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{EF97CE3A-BAEF-42EA-95A6-EF14A8CE9F41}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{F48D9FCE-B5D0-4940-ADDC-693C36D80C36}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{FD637898-4EB8-4B44-B20B-F6915E918F00}" = protocol=6 | dir=in | app=c:\program files\belkin\router setup and monitor\belkinsetup.exe |
"TCP Query User{477A0D83-7EB0-4C80-853F-67453A10E42D}C:\program files\rhapsody\rhapsody.exe" = protocol=6 | dir=in | app=c:\program files\rhapsody\rhapsody.exe |
"TCP Query User{B3A01012-E523-4F59-A47B-8E5292A5330E}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{C53C6109-00D1-4A7E-9C7D-7B455C6666DC}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{05149BCC-7AB7-4148-A9AE-E8AB3516AB10}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{94EC83FF-8592-4414-B9A1-9F0BD7EC6FDC}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{A2540704-1964-4104-BFA9-8163129E98CD}C:\program files\rhapsody\rhapsody.exe" = protocol=17 | dir=in | app=c:\program files\rhapsody\rhapsody.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{029B5901-1F27-4347-9923-E8ACC8F54E15}" = Snapfish Picture Mover
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0DFB3DE8-65B9-44FF-AA0A-3BECC5A2BFD1}" = Adobe Flash Player 10 Plugin
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX340_series" = Canon MX340 series MP Drivers
"{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}_is1" = SiteRanker
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Javaโ„ข 6 Update 13
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Javaโ„ข 6 Update 5
"{340F521E-3576-4E1A-B75C-EB0ACF751379}" = HP Wireless Assistant
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 D3
"{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}" = muvee autoProducer 6.1
"{380357CA-29F4-4B3C-B401-32C057E6B59B}" = HP Smart Web Printing
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{57573545-74EB-46D2-B362-AA05364E4ED8}" = LogMeIn
"{5D76440F-B69A-43F8-8F5E-D537349A398C}" = PED-Basic
"{612AD33D-9824-4E87-8396-92374E91C4BB}_is1" = Inbox Toolbar
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7641FD7D-E94E-424E-A95C-0593C84DC0C0}" = VZAccess Manager
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B2ADCB5-3F3D-478A-90A9-A8C04EF82BF6}" = Mobile Broadband Generic Drivers
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DF92D68-F8EE-4F9C-89A2-26254C1C4B6B}" = HP Help and Support
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E2CCD5E-1990-4EF2-9B61-32F0BBACC29B}" = HP Active Support Library
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A64D224E-E06A-43D2-A919-8BE108F47305}_is1" = Crawler Smileys
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AE15D0F7-8C2E-4419-97B4-995ED16FBB4E}" = Art Explosion Greeting Card Factory Express
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B6D0B141-B2BE-4DD0-B08F-B9186F3E36B3}" = HP User Guides 0118
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{C13AF9C7-8E06-4354-B629-DF6192CE4A66}" = PANTECH UM175 Driver
"{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}" = HP Customer Experience Enhancements
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuideยฎ Viewer ActiveX Control Release 6.5
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{f32502b5-5b64-4882-bf61-77f23edcac4f}" = HP Total Care Advisor
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{FA3B34BE-4246-4062-90A3-34CBBEA12B72}" = HPTCSSetup
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM_6" = AIM 6
"avast" = avast! Free Antivirus
"Belkin Setup and Router Monitor_is1" = Belkin Setup and Router Monitor
"Canon MX340 series User Registration" = Canon MX340 series User Registration
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"CToolbar_UNINSTALL" = Crawler Toolbar
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"LimeWire" = LimeWire 5.4.6
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mobile Broadband Generic Drivers" = Mobile Broadband Generic Drivers
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MP Navigator EX 3.1" = Canon MP Navigator EX 3.1
"NVIDIA Drivers" = NVIDIA Drivers
"Rhapsody" = Rhapsody
"SelectRebatesUninstall" = ShopAtHome.com Toolbar
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"Speed Dial Utility" = Canon Speed Dial Utility
"Star Trek Online" = Star Trek Online
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent hp Master Uninstall" = My HP Games
"Yahoo! Companion" = Yahoo! Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/3/2011 3:32:06 PM | Computer Name = cheer | Source = WinMgmt | ID = 10
Description =

Error - 8/3/2011 3:36:19 PM | Computer Name = cheer | Source = Windows Search Service | ID = 3013
Description =

Error - 8/3/2011 3:46:33 PM | Computer Name = cheer | Source = Application Error | ID = 1000
Description = Faulting application VZAccess Manager.exe, version 7.0.1.8, time stamp
0x4a179fe1, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception
code 0xc0000005, fault offset 0x00000000, process id 0x570, application start time
0x01cc52141e20b837.

Error - 8/3/2011 9:29:57 PM | Computer Name = cheer | Source = Application Error | ID = 1000
Description = Faulting application BelkinSetup.exe, version 4.0.2.16717, time stamp
0x4ba0dcb0, faulting module ntdll.dll, version 6.0.6001.18538, time stamp 0x4cb733dc,
exception code 0xc0000005, fault offset 0x000487f8, process id 0x9e4, application
start time 0x01cc521420993247.

Error - 8/4/2011 6:42:16 PM | Computer Name = cheer | Source = WinMgmt | ID = 10
Description =

Error - 8/4/2011 7:18:25 PM | Computer Name = cheer | Source = Windows Search Service | ID = 3013
Description =

Error - 8/4/2011 11:15:40 PM | Computer Name = cheer | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.19088, time stamp
0x4de07b1b, faulting module yt.dll_unloaded, version 0.0.0.0, time stamp 0x4719257c,
exception code 0xc0000005, fault offset 0x62922326, process id 0x1790, application
start time 0x01cc52fe6560a8d4.

Error - 8/5/2011 4:41:43 PM | Computer Name = cheer | Source = WinMgmt | ID = 10
Description =

Error - 8/5/2011 4:46:58 PM | Computer Name = cheer | Source = Windows Search Service | ID = 3013
Description =

Error - 8/5/2011 5:02:25 PM | Computer Name = cheer | Source = Application Error | ID = 1000
Description = Faulting application VZAccess Manager.exe, version 7.0.1.8, time stamp
0x4a179fe1, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception
code 0xc0000005, fault offset 0x00000000, process id 0x92c, application start time
0x01cc53b044860bc9.

[ Media Center Events ]
Error - 9/14/2009 11:30:50 PM | Computer Name = cheer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 4/6/2010 9:33:51 PM | Computer Name = cheer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 9/17/2010 8:48:46 PM | Computer Name = cheer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.


========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hello hrhwrlddom



Please do the following:

Hold down the Windows key and press R to open a run box
type the following text into the run box

appwiz.cpl

This will open your Programs And Features
A list of installed programs will populate
Remove the following programs:

ShopAtHome.com Toolbar
====================
NEXT

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    PRC - C:\Program Files\SelectRebates\SelectRebates.exe ()
    O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
    O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
    O3 - HKCU\..\Toolbar\WebBrowser: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (ShopAtHome.com)
    O4 - HKLM..\Run: [SelectRebates] C:\Program Files\SelectRebates\SelectRebates.exe ()
    O4 - HKCU..\Run: [4Y3Y0C3AUYVV4Y9GCYBOPHFEUNNFBI] File not found
    O4 - HKCU..\Run: [lpc] File not found
    O4 - HKCU..\Run: [uswqpwkn] File not found
    O33 - MountPoints2\{689b8ac7-fd5c-11de-b821-001f164d2e66}\Shell\AutoRun\command - "" = F:\Autorun.exe /run
    O33 - MountPoints2\{689b8ac7-fd5c-11de-b821-001f164d2e66}\Shell\Shell00\Command - "" = F:\Autorun.exe /run
    O33 - MountPoints2\{689b8ac7-fd5c-11de-b821-001f164d2e66}\Shell\Shell01\Command - "" = F:\Autorun.exe /action
    O33 - MountPoints2\{689b8ac7-fd5c-11de-b821-001f164d2e66}\Shell\Shell02\Command - "" = F:\Autorun.exe /uninstall
    O33 - MountPoints2\{7ccd79e3-d33f-11dd-9f62-001f164d2e66}\Shell - "" = AutoRun
    O33 - MountPoints2\{7ccd79e3-d33f-11dd-9f62-001f164d2e66}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
    O33 - MountPoints2\{c1d90387-f4aa-11de-94a8-001f164d2e66}\Shell - "" = AutoRun
    O33 - MountPoints2\{c1d90387-f4aa-11de-94a8-001f164d2e66}\Shell\AutoRun\command - "" = F:\VZAccess_Manager.exe /z detect
    O33 - MountPoints2\{c1d903c0-f4aa-11de-94a8-001f164d2e66}\Shell - "" = AutoRun
    O33 - MountPoints2\{c1d903c0-f4aa-11de-94a8-001f164d2e66}\Shell\AutoRun\command - "" = G:\VZAccess_Manager.exe /z detect
    [2011/07/23 12:07:16 | 000,210,984 | โ€”- | M] () โ€“ C:\Users\porcsha\Documents\CouponAlert.exe
    [2011/07/23 12:07:12 | 000,210,984 | โ€”- | C] () โ€“ C:\Users\porcsha\Documents\CouponAlert.exe
    [2011/05/16 13:50:40 | 000,000,208 | โ€”- | C] () โ€“ C:\ProgramData\h5776CnKiAdO6323
    [2011/05/16 13:11:21 | 000,009,152 | -HS- | C] () โ€“ C:\ProgramData\2dhnh1n2qa
    [2011/05/16 13:11:20 | 000,009,152 | -HS- | C] () โ€“ C:\Users\porcsha\AppData\Local\2dhnh1n2qa
    [2009/05/30 17:57:33 | 000,000,004 | โ€”- | C] () โ€“ C:\Users\porcsha\AppData\Roaming\B69CEF
    [2008/12/25 19:58:23 | 000,000,000 | โ€”D | M] โ€“ C:\Users\porcsha\AppData\Roaming\iWin
    
    :Reg
    
    :Files
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
====================
NEXT

Download and Run ComboFix
  • Please download ComboFix from one of the following links.

    Link 1.

    Link 2.

    **IMPORTANT !!! Save ComboFix.exe to your Desktop**
  • Please disable any Antivirus or Firewall you have active, as shown in this topic. Please close all open application windows.
  • Double click on ComboFix.exe & follow the prompts
  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper

===========================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. Combofix log
4. How is the computer behaving?
Ok after Deleting toolbar, OTL.exe fix, and Combofix, I think it was Combofix, I could not connect to the internet with my Verizon Wireless USB modem and then I could not open Programs either, so I did a system restore and problems were fixed. Do you want me to retry the previous steps?
Hello hrhwrlddom,

I'm sorry you had problems, but if you have another problem please don't do a system restore. There is other steps we can do to get your internet connection back a lot of times just a reboot of the computer will work. Do you have another computer to contact me just in case we run into this problem again? Lets run OTL again and get a fresh log since you did a system restore. I don't want you to run the OTL fix just run a scan for now. In your next reply please post the new OTL scan.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI