This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer freezes after startup

38 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I'm running Windows XP on a 7 year old Toshiba Satellite laptop. I was recently hit by some malware, which I managed to remove after much difficulty using Spyware Doctor. During the fix, Spyware Doctor removed something like 300 infected files! After this, I was able to use my laptop for a few days, but the system was pretty shaky, especially after startup. At first, I had trouble connecting to the internet, with my browser not recognizing my internet connection. I fixed this by reinstalling IE8.0. At the same time Windows Security Center kept telling me that Automatic Updates was diasbled, but when I went to check on System through Control Panel, it said that it was enabled. Spyware Doctor also found and removed another Trojan. I also downloaded and used Eusing Free Registry Cleaner which helped when I was having trouble running scans.

Today, I started up my laptop and then it froze around 2-3 minutes after starting up. I was able to move my mouse cursor, but could not click anything. I started the system up in safe mode and ran Spyware Doctor again and removed yet another trojan. However this did not stop the freezing problem whenever I start up windows normally.

Please help! I am unwilling to reformat my laptop as I have many crucial programs installed which I do not have discs for. I also cannot access the internet while on safe mode as I use a mobile internet usb which will not connect while the computer is on safemode. I am typing this in desperation using another computer. I have not installed any new hardware and I suspect I have remnant corrupted files from the recent infection, even though my current scans are showing up clean. I've run Hijackthis on safe mode and this is the log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:23:21 PM, on 8/14/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Jessica Lim\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O1 - Hosts: ::1 localhost
O1 - Hosts: 209.44.111.62 aware-protect.com
O1 - Hosts: 209.44.111.62 www.aware-protect.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [ZoomingHook] ZoomingHook.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools Security\pctsGui.exe" /hideGUI
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-MY/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F8A5966E-C606-4386-8F30-61843D900A9C}: NameServer = 202.188.1.5,202.188.0.133
O20 - Winlogon Notify: dsautil - dsautil.dll (file missing)
O20 - Winlogon Notify: mprkor - mprkor.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Update Service (gupdate1ca1836b5e58920) (gupdate1ca1836b5e58920) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools Security\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

–
End of file - 10957 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.


IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! :thumbup:
Hi hylim!!


Print out these instructions as we may need to close every window that is open later in the fix.


It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.

Do not reboot your computer after running rkill as the malware programs will start again.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
  • rkill.exe
  • rkill.com
  • rkill.scr
  • WiNlOgOn.exe
  • uSeRiNiT.exe

Do not reboot your computer after running rkill as the malware programs will start again.
———-

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-


In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
Thank you. I'm about to do that now. Is it fine for me to do it in safe mode? As I mentioned before, I can't work on the computer if I start it normally.
Hi hylim, Yes that is more than fine to run these in Safe Mode. Be sure to include the logs that are created into your next reply. :)
Hi I've done as you instructed, however I was not able to finish running DDS. It always freezes at around 70% through the scan, and the laptop crashes. I'm afraid I don't know what would be a script-blocking protection or if I have one running. The log from aswMBR is as follows: aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software Run date: 2011-08-15 03:16:41 —————————– 03:16:41.921 OS Version: Windows 5.1.2600 Service Pack 3 03:16:41.921 Number of processors: 1 586 0xD08 03:16:41.921 ComputerName: JESSICA UserName: 03:16:48.578 Initialize success 03:17:12.656 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 03:17:12.671 Disk 0 Vendor: FUJITSU_MHV2100AH 00400097 Size: 95205MB BusType: 3 03:17:14.718 Disk 0 MBR read successfully 03:17:14.734 Disk 0 MBR scan 03:17:14.750 Disk 0 unknown MBR code 03:17:14.765 Disk 0 scanning sectors +194980905 03:17:14.828 Disk 0 scanning C:\WINDOWS\system32\drivers 03:17:27.406 Service scanning 03:17:32.937 Modules scanning 03:17:39.625 Disk 0 trace - called modules: 03:17:39.687 ntoskrnl.exe CLASSPNP.SYS disk.sys PCTCore.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 03:17:39.703 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x872c0ab8] 03:17:39.718 3 CLASSPNP.SYS[f7543fd7] -> nt!IofCallDriver -> [0x872e7908] 03:17:39.750 5 PCTCore.sys[f73dc6a1] -> nt!IofCallDriver -> \Device\0000008c[0x8732f170] 03:17:41.765 7 ACPI.sys[f749a620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x87370940] 03:17:41.875 Scan finished successfully 03:17:54.578 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Jessica Lim\Desktop\logs\MBR.dat" 03:17:54.609 The log file has been saved successfully to "C:\Documents and Settings\Jessica Lim\Desktop\logs\aswMBR.txt"
Hi hylim!!

Thanks for getting me that aswMBR.exe log. Let's try something else shall we? After you get the following tool downloaded you can run it in Safe Mode. :)

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Thank you. Here are the txts generated by the OTL scan:

OTL.txt =


OTL logfile created on: 8/15/2011 6:45:40 PM - Run 1
OTL by OldTimer - Version 3.2.26.4 Folder = C:\Documents and Settings\Jessica Lim\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.42 Mb Total Physical Memory | 750.63 Mb Available Physical Memory | 73.42% Memory free
2.41 Gb Paging File | 2.31 Gb Available in Paging File | 95.87% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 92.97 Gb Total Space | 8.31 Gb Free Space | 8.94% Space Free | Partition Type: NTFS

Computer Name: JESSICA | User Name: Jessica Lim | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jessica Lim\Desktop\OTL.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\Jessica Lim\Desktop\OTL.exe ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (sdCoreService) – C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (NOD32krn) – C:\Program Files\Eset\nod32krn.exe (Eset )
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LVPrcSrv) – c:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (Autodesk Network Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe (Autodesk, Inc.)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (StarWindService) – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe (Rocket Division Software)
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (TabletService) – C:\WINDOWS\system32\Tablet.exe (Wacom Technology, Corp.)


========== Driver Services (SafeList) ==========

DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (PCTSD) – C:\WINDOWS\system32\drivers\PCTSD.sys (PC Tools)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (AMON) – C:\WINDOWS\system32\drivers\amon.sys (Eset )
DRV - (nod32drv) – C:\WINDOWS\system32\drivers\nod32drv.sys ()
DRV - (USB_RNDIS) – C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (hwdatacard) – C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (LVMVDrv) – C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (LVcKap) – C:\WINDOWS\system32\drivers\Lvckap.sys ()
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (Nokia USB Phone Parent) – C:\WINDOWS\system32\drivers\nmwcd.sys (Nokia)
DRV - (Nokia USB Port) – C:\WINDOWS\system32\drivers\nmwcdcj.sys (Nokia)
DRV - (Nokia USB Modem) – C:\WINDOWS\system32\drivers\nmwcdcm.sys (Nokia)
DRV - (Nokia USB Generic) – C:\WINDOWS\system32\drivers\nmwcdc.sys (Nokia)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (ENETHUSB) – C:\WINDOWS\system32\drivers\enethusb.sys (Siemens Subscriber Networks, Inc.)
DRV - (SrvcSSIOMngr) – C:\WINDOWS\system32\drivers\SSIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEKIOMngr) – C:\WINDOWS\system32\drivers\EKIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (Tvs) – C:\WINDOWS\system32\drivers\Tvs.sys (TOSHIBA Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\SYMIDS.SYS (Symantec Corporation)
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\WINDOWS\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (tosrfec) – C:\WINDOWS\system32\drivers\Tosrfec.sys (TOSHIBA Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (TPwSav) – C:\WINDOWS\system32\drivers\TPwSav.sys (TOSHIBA )
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (w29n51) Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (SerTVOutCtlr) – C:\WINDOWS\system32\drivers\EPIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMSC)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (CnxTrUsb) – C:\WINDOWS\system32\drivers\CnxTrUsb.sys (Conexant)
DRV - (CnxTrLan) – C:\WINDOWS\system32\drivers\CnxTrLan.sys (Conexant)
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (PenClass) – C:\WINDOWS\System32\Drivers\PenClass.sys (Wacom Technology Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://google.com/"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()


[2008/09/02 09:34:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jessica Lim\Application Data\Mozilla\Extensions
[2009/07/02 18:13:05 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jessica Lim\Application Data\Mozilla\Firefox\Profiles\nzu4pdes.default\extensions
[2009/01/08 09:54:51 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Jessica Lim\Application Data\Mozilla\Firefox\Profiles\nzu4pdes.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2007/08/03 20:13:09 | 000,002,386 | —- | M] () – C:\Documents and Settings\Jessica Lim\Application Data\Mozilla\Firefox\Profiles\nzu4pdes.default\searchplugins\siteadvisor.xml
[2009/07/11 15:42:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2007/05/28 15:34:23 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008/09/04 10:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\mozilla firefox\plugins\npbittorrent.dll

O1 HOSTS File: ([2011/08/11 08:40:42 | 000,000,106 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 209.44.111.62 aware-protect.com
O1 - Hosts: 209.44.111.62 www.aware-protect.com
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (bho2gr Class) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [CFSServ.exe] File not found
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam10\QuickCam10.exe ()
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe (Eset )
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [Symantec NetDriver Monitor] C:\Program Files\SymNetDrv\SNDMon.exe (Symantec Corporation)
O4 - HKLM..\Run: [TCtryIOHook] C:\WINDOWS\System32\TCtrlIOHook.exe (TOSHIBA)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ZoomingHook] C:\WINDOWS\System32\ZoomingHook.exe (TOSHIBA)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\NPJPI150_01.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-MY/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\dsautil: DllName - dsautil.dll - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\mprkor: DllName - mprkor.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/05/12 14:57:09 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{10c19989-860c-11dc-b53a-000fb09bba3b}\Shell - "" = AutoRun
O33 - MountPoints2\{10c19989-860c-11dc-b53a-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{10c19989-860c-11dc-b53a-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\Shell - "" = AutoRun
O33 - MountPoints2\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\Shell - "" = AutoRun
O33 - MountPoints2\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\System\DriveGuard\DriveProtect.exe -run 
O33 - MountPoints2\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\Shell\Explore\Command - "" = E:\System\DriveGuard\DriveProtect.exe -run  
O33 - MountPoints2\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\Shell\Open\Command - "" = E:\System\DriveGuard\DriveProtect.exe -run 
O33 - MountPoints2\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\Shell - "" = AutoRun
O33 - MountPoints2\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\Shell - "" = AutoRun
O33 - MountPoints2\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\Shell - "" = AutoRun
O33 - MountPoints2\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{77091a5a-e811-11dd-b823-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{77091a5a-e811-11dd-b823-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{77091a5a-e811-11dd-b823-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{77091a5b-e811-11dd-b823-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{77091a5b-e811-11dd-b823-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{77091a5b-e811-11dd-b823-0013ce7d50c8}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\Shell\Auto\command - "" = E:\autorun.exe
O33 - MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe
O33 - MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\Shell\Auto\command - "" = autorun.exe
O33 - MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe
O33 - MountPoints2\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif
O33 - MountPoints2\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\Shell - "" = AutoRun
O33 - MountPoints2\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/15 03:30:41 | 000,607,017 | R— | C] (Swearware) – C:\Documents and Settings\Jessica Lim\Desktop\dds.pif
[2011/08/15 02:32:03 | 000,000,000 | R–D | C] – C:\Documents and Settings\Jessica Lim\Start Menu\Programs\Administrative Tools
[2011/08/15 02:29:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Jessica Lim\Desktop\logs
[2011/08/15 02:07:40 | 001,915,904 | —- | C] (AVAST Software) – C:\Documents and Settings\Jessica Lim\Desktop\aswMBR.exe
[2011/08/15 02:07:40 | 000,607,017 | R— | C] (Swearware) – C:\Documents and Settings\Jessica Lim\Desktop\dds.com
[2011/08/14 20:05:11 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Jessica Lim\Desktop\HiJackThis.exe
[2011/08/11 20:03:43 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/08/11 07:23:48 | 000,656,320 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctEFA.sys
[2011/08/11 07:23:48 | 000,338,880 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctDS.sys
[2011/08/11 07:23:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2011/08/11 07:22:36 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2011/08/11 07:13:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Jessica Lim\Start Menu\Programs\Free Registry Cleaner
[2011/08/11 07:13:46 | 000,000,000 | —D | C] – C:\Program Files\Eusing Free Registry Cleaner
[2011/08/11 07:07:14 | 039,987,520 | —- | C] (PC Tools ) – C:\Documents and Settings\Jessica Lim\Desktop\sdsetup.exe
[2011/08/11 06:58:44 | 000,233,976 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTSD.sys
[2011/08/11 06:33:29 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sdtmp
[2011/08/11 06:21:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\Threat Expert
[2011/08/11 06:16:17 | 001,652,688 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2011/08/11 06:16:17 | 000,165,840 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2011/08/11 06:16:17 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2011/08/11 06:15:49 | 000,251,560 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2011/08/11 06:15:19 | 000,263,888 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2011/08/11 06:15:19 | 000,160,576 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2011/08/11 06:15:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spyware Doctor
[2011/08/11 06:14:53 | 000,070,664 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2011/08/11 06:14:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2011/08/11 06:14:25 | 000,000,000 | —D | C] – C:\Program Files\Spyware Doctor
[2011/08/11 06:14:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Jessica Lim\Application Data\PC Tools
[2011/08/11 06:14:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2011/08/11 06:13:27 | 036,317,280 | —- | C] (PC Tools ) – C:\Documents and Settings\Jessica Lim\Desktop\spyware-doctor.exe
[2011/08/10 17:19:03 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/08/10 17:15:38 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/08/08 07:14:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Jessica Lim\Application Data\SYSTEMAX Software Development
[2011/08/08 07:14:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SYSTEMAX Software Development
[2011/08/08 07:14:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Jessica Lim\Desktop\PaintTool SAI English Pack
[2011/08/07 05:19:16 | 016,883,056 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Jessica Lim\Desktop\IE8-WindowsXP-x86-ENU.exe
[2011/08/07 04:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Jessica Lim\Application Data\Veal
[2011/08/07 04:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Jessica Lim\Application Data\Arextu
[2011/07/16 22:48:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Jessica Lim\My Documents\Batman - Battle For The Cowl
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\*.tmp files -> C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/15 18:08:46 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/15 18:04:53 | 000,000,323 | —- | M] () – C:\WINDOWS\System32\wacom.dat
[2011/08/15 18:04:05 | 000,000,000 | —- | M] () – C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\{4495784C-203E-4B51-9B83-8D3ACCD3DE73}
[2011/08/15 18:03:46 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/15 18:00:07 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/15 16:25:53 | 000,579,584 | —- | M] () – C:\Documents and Settings\Jessica Lim\Desktop\OTL.exe
[2011/08/15 03:25:42 | 000,607,017 | R— | M] (Swearware) – C:\Documents and Settings\Jessica Lim\Desktop\dds.pif
[2011/08/15 02:30:01 | 000,000,020 | —- | M] () – C:\Documents and Settings\Jessica Lim\defogger_reenable
[2011/08/15 02:27:57 | 000,000,139 | —- | M] () – C:\Documents and Settings\Jessica Lim\Desktop\rk-proxy.reg
[2011/08/15 02:05:00 | 001,915,904 | —- | M] (AVAST Software) – C:\Documents and Settings\Jessica Lim\Desktop\aswMBR.exe
[2011/08/15 02:04:32 | 000,607,017 | R— | M] (Swearware) – C:\Documents and Settings\Jessica Lim\Desktop\dds.com
[2011/08/15 02:03:02 | 000,050,477 | —- | M] () – C:\Documents and Settings\Jessica Lim\Desktop\Defogger.exe
[2011/08/15 02:02:30 | 001,008,092 | —- | M] () – C:\Documents and Settings\Jessica Lim\Desktop\rkill.exe
[2011/08/14 21:18:08 | 000,625,664 | —- | M] () – C:\Documents and Settings\Jessica Lim\Desktop\dds.scr
[2011/08/14 19:39:42 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jessica Lim\Desktop\HiJackThis.exe
[2011/08/11 20:09:47 | 000,000,826 | —- | M] () – C:\Documents and Settings\Jessica Lim\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/08/11 20:03:19 | 000,732,694 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/08/11 10:03:27 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/11 07:58:43 | 000,012,470 | -HS- | M] () – C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\40yp52f18u8
[2011/08/11 07:58:43 | 000,012,470 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\40yp52f18u8
[2011/08/11 07:19:32 | 000,003,748 | —- | M] () – C:\Documents and Settings\Jessica Lim\Desktop\xp_av_fix.reg
[2011/08/11 07:13:47 | 000,000,751 | —- | M] () – C:\Documents and Settings\Jessica Lim\Desktop\Eusing Free Registry Cleaner.lnk
[2011/08/11 06:31:28 | 041,527,406 | —- | M] () – C:\Documents and Settings\Jessica Lim\Desktop\installer.com
[2011/08/11 06:30:30 | 039,987,520 | —- | M] (PC Tools ) – C:\Documents and Settings\Jessica Lim\Desktop\sdsetup.exe
[2011/08/11 06:11:26 | 036,317,280 | —- | M] (PC Tools ) – C:\Documents and Settings\Jessica Lim\Desktop\spyware-doctor.exe
[2011/08/11 03:25:22 | 000,445,082 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/11 03:25:21 | 000,072,792 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/11 03:20:35 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/08/10 15:52:42 | 000,001,824 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/08/08 07:07:57 | 002,389,529 | —- | M] () – C:\Documents and Settings\Jessica Lim\Desktop\PaintTool SAI English Pack.zip
[2011/08/07 05:19:16 | 016,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Jessica Lim\Desktop\IE8-WindowsXP-x86-ENU.exe
[2011/08/06 22:30:26 | 000,970,509 | —- | M] () – C:\Documents and Settings\Jessica Lim\Desktop\EFRCSetup.exe
[2011/08/06 21:04:18 | 000,232,448 | —- | M] () – C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/30 07:18:08 | 000,007,525 | —- | M] () – C:\Documents and Settings\Jessica Lim\My Documents\Jason_Dick fics[1].rtf
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\*.tmp files -> C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/15 18:04:05 | 000,000,000 | —- | C] () – C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\{4495784C-203E-4B51-9B83-8D3ACCD3DE73}
[2011/08/15 16:25:49 | 000,579,584 | —- | C] () – C:\Documents and Settings\Jessica Lim\Desktop\OTL.exe
[2011/08/15 02:52:12 | 000,625,664 | —- | C] () – C:\Documents and Settings\Jessica Lim\Desktop\dds.scr
[2011/08/15 02:29:43 | 000,000,020 | —- | C] () – C:\Documents and Settings\Jessica Lim\defogger_reenable
[2011/08/15 02:27:57 | 000,000,139 | —- | C] () – C:\Documents and Settings\Jessica Lim\Desktop\rk-proxy.reg
[2011/08/15 02:07:40 | 001,008,092 | —- | C] () – C:\Documents and Settings\Jessica Lim\Desktop\rkill.exe
[2011/08/15 02:07:40 | 000,050,477 | —- | C] () – C:\Documents and Settings\Jessica Lim\Desktop\Defogger.exe
[2011/08/11 07:23:50 | 000,732,694 | —- | C] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/08/11 07:21:47 | 000,003,748 | —- | C] () – C:\Documents and Settings\Jessica Lim\Desktop\xp_av_fix.reg
[2011/08/11 07:13:47 | 000,000,751 | —- | C] () – C:\Documents and Settings\Jessica Lim\Desktop\Eusing Free Registry Cleaner.lnk
[2011/08/11 07:13:09 | 000,970,509 | —- | C] () – C:\Documents and Settings\Jessica Lim\Desktop\EFRCSetup.exe
[2011/08/11 06:33:04 | 041,527,406 | —- | C] () – C:\Documents and Settings\Jessica Lim\Desktop\installer.com
[2011/08/11 06:16:18 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2011/08/11 06:16:17 | 001,152,444 | —- | C] () – C:\WINDOWS\UDB.zip
[2011/08/11 06:16:17 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2011/08/11 06:16:17 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2011/08/11 06:16:17 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2011/08/11 06:15:49 | 000,007,387 | —- | C] () – C:\WINDOWS\System32\drivers\pctgntdi.cat
[2011/08/11 06:14:53 | 000,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctplsg.cat
[2011/08/11 05:39:48 | 000,012,470 | -HS- | C] () – C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\40yp52f18u8
[2011/08/11 05:39:48 | 000,012,470 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\40yp52f18u8
[2011/08/08 07:07:57 | 002,389,529 | —- | C] () – C:\Documents and Settings\Jessica Lim\Desktop\PaintTool SAI English Pack.zip
[2011/08/07 05:38:53 | 000,000,814 | —- | C] () – C:\Documents and Settings\Jessica Lim\Start Menu\Programs\Internet Explorer.lnk
[2011/07/30 07:18:07 | 000,007,525 | —- | C] () – C:\Documents and Settings\Jessica Lim\My Documents\Jason_Dick fics[1].rtf
[2009/12/20 21:54:16 | 000,078,600 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/08/09 00:48:40 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/08/09 00:20:17 | 000,050,127 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/08/06 13:06:48 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2009/08/06 13:02:40 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\libcurl.dll
[2009/08/06 13:02:22 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\libexpatw.dll
[2009/07/06 07:08:23 | 000,000,050 | —- | C] () – C:\WINDOWS\System32\imon1.dat
[2008/10/03 11:09:55 | 000,065,536 | —- | C] () – C:\WINDOWS\IFinst27.exe
[2008/08/05 13:52:05 | 000,015,424 | —- | C] () – C:\WINDOWS\System32\drivers\nod32drv.sys
[2008/03/12 12:33:25 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2007/10/23 09:25:56 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS4s.DLL
[2007/06/09 14:34:00 | 000,001,368 | —- | C] () – C:\WINDOWS\mozver.dat
[2007/05/28 15:34:27 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/02/06 17:45:04 | 000,025,632 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/02/06 17:42:40 | 001,691,808 | —- | C] () – C:\WINDOWS\System32\drivers\Lvckap.sys
[2007/01/12 11:43:01 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/12/15 13:16:12 | 000,000,323 | —- | C] () – C:\WINDOWS\System32\wacom.dat
[2006/12/15 13:16:07 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\TabUnst.dll
[2006/12/15 13:16:07 | 000,015,744 | —- | C] () – C:\WINDOWS\System32\wintab.dll
[2006/12/15 13:15:37 | 000,013,408 | —- | C] () – C:\WINDOWS\System32\tabinst.dll
[2006/12/15 13:15:37 | 000,004,032 | —- | C] () – C:\WINDOWS\System32\tabins16.dll
[2006/06/30 08:40:01 | 000,000,134 | —- | C] () – C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\fusioncache.dat
[2006/06/28 14:49:38 | 000,104,209 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2006/06/28 14:49:38 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2006/01/22 17:15:08 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2006/01/15 10:26:52 | 000,232,448 | —- | C] () – C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/01/15 10:26:09 | 000,001,890 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/01/15 10:26:09 | 000,000,056 | RHS- | C] () – C:\WINDOWS\System32\09F7B4B705.sys
[2006/01/08 05:31:39 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2006/01/08 05:31:39 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2006/01/08 05:31:39 | 000,010,165 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2006/01/08 05:31:39 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2005/05/20 09:53:02 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/05/13 23:01:34 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/05/13 22:56:55 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2005/05/13 22:55:15 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/05/13 22:54:30 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/05/13 22:54:30 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/05/13 22:54:30 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/05/13 22:54:30 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/05/13 22:54:30 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/05/13 22:54:30 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/05/13 22:47:34 | 000,034,048 | —- | C] () – C:\WINDOWS\System32\drivers\WOWXT_kern_i386.sys
[2005/05/13 22:47:34 | 000,029,184 | —- | C] () – C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2005/05/13 22:32:21 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\EBLib.DLL
[2005/05/13 22:29:33 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2005/05/13 22:29:33 | 000,001,256 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2005/05/13 22:29:33 | 000,000,176 | —- | C] () – C:\WINDOWS\System32\drivers\alcxhweq.dat
[2005/05/13 22:29:33 | 000,000,176 | —- | C] () – C:\WINDOWS\System32\drivers\alcxeq.dat
[2005/05/12 15:00:51 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/05/12 14:59:22 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/05/12 14:55:09 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/05/12 14:35:13 | 000,081,342 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2005/05/12 14:35:03 | 000,002,388 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/05/12 14:34:38 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/05/12 14:34:36 | 000,445,082 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/05/12 14:34:36 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005/05/12 14:34:36 | 000,072,792 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/05/12 14:34:36 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005/05/12 14:34:35 | 000,004,631 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005/05/12 14:34:34 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/05/12 14:34:32 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/05/12 14:34:29 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005/05/12 14:34:29 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005/05/12 14:34:23 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005/05/12 14:34:17 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2005/05/12 07:50:11 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/05/12 07:49:21 | 000,348,992 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/04/26 06:44:04 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\TPeculiarity.dll
[2005/04/21 13:00:00 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\EKECioCtl.dll
[2005/03/31 07:50:38 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\SPCtl.dll
[2005/03/30 16:47:58 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\HWS_Ctrl.dll
[2005/02/28 16:28:12 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/02/25 14:44:56 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\TCtrlIO.dll
[2004/12/02 14:20:12 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2004/10/27 08:39:05 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/09/22 09:09:06 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2004/07/20 16:04:02 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 13:43:28 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\TBTMonUI.dll
[2004/01/13 21:46:34 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\tifmicon.dll
[2003/07/29 14:33:26 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\TosHidAPI.dll
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2009/02/17 09:02:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2008/02/25 10:28:28 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/05/10 10:09:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2007/10/20 21:35:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2011/08/08 07:14:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SYSTEMAX Software Development
[2011/08/15 18:05:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/03/12 12:33:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/04/01 10:17:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/01 12:18:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/04 10:13:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/08/14 17:45:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\Arextu
[2009/02/17 08:42:34 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Jessica Lim\Application Data\Autodesk
[2010/05/31 19:32:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\BitTorrent
[2011/07/24 22:38:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\Canon
[2011/08/15 18:04:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\DNA
[2009/02/20 21:21:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\ImgBurn
[2005/05/13 22:42:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\InterTrust
[2007/01/12 11:15:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\InterVideo
[2007/10/20 21:37:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\Nokia
[2007/10/20 21:34:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\PC Suite
[2011/08/08 07:14:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\SYSTEMAX Software Development
[2005/05/13 22:55:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\toshiba
[2011/08/14 01:07:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\Veal
[2009/07/14 14:58:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Jessica Lim\Application Data\YoudaGames

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 264 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 177 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:96EE29A3
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
Extras.txt =

OTL Extras logfile created on: 8/15/2011 6:45:40 PM - Run 1
OTL by OldTimer - Version 3.2.26.4 Folder = C:\Documents and Settings\Jessica Lim\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.42 Mb Total Physical Memory | 750.63 Mb Available Physical Memory | 73.42% Memory free
2.41 Gb Paging File | 2.31 Gb Available in Paging File | 95.87% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 92.97 Gb Total Space | 8.31 Gb Free Space | 8.94% Space Free | Partition Type: NTFS

Computer Name: JESSICA | User Name: Jessica Lim | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.js [@ = JSFile] – C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe (Macromedia, Inc.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
jsfile [open] – "C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA – (BitTorrent, Inc.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC – (mIRC Co. Ltd.)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"G:\TalesWeaver\InphaseNXD.EXE" = G:\TalesWeaver\InphaseNXD.EXE:*:Enabled:Talesweaver InphaseNXD.exe


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{02EED746-8C5A-43C8-BB3D-D29C8B363A4D}" = TOSHIBA Zooming Utility
"{04F3BF74-9E34-4D3E-93C3-D3D1F24199C8}" = PC Connectivity Solution
"{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}" = Macromedia Dreamweaver MX 2004
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{12E75B98-8463-4C1F-8DDA-F6CF31566A55}" = Google SketchUp Pro 6
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{2405665A-16C9-4D3A-B70E-F006220E1472}" = Overland
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2DDEE1AF-730A-4CE0-90DB-A9EE84B9A959}" = EssenceRO
"{2F353D44-73BB-4971-B31D-F7642E9E9531}" = Macromedia Flash MX 2004
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator 2
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0150010}" = J2SE Runtime Environment 5.0 Update 1
"{345112D9-0930-4A68-AB71-A831BA5DE7AA}" = Microsoft IntelliType Pro 6.2
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{3A57482F-BEBC-47E4-ADA1-6302403C7E50}" = TOSHIBA Accessibility
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{3EAAC5FD-E209-4856-8C49-D4EA40F85032}" = 3 Mobile Broadband
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{450063AA-643B-417C-8CF5-405BA3F4EF40}" = Autodesk Design Review 2009
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets
"{48CF9A66-5F03-4025-ABD0-B3A3FA095A59}" = TOSHIBA SD Memory Card Format
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5783F2D7-6001-0409-0002-0060B0CE6BBA}" = AutoCAD 2008 - English
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{597D73A8-5FDB-4bc1-9893-40B54459F1BC}" = ProductContext
"{5BCA8D15-BCB6-421E-9654-238B43456A4F}" = TOSHIBA Controls
"{5D96E2B1-D9AC-46E0-9073-425C5F63E338}" = Touch and Launch
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6E448242-1967-4470-A3F5-FFB62B341D8F}" = 2600
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7900D3A6-A9E8-4954-ACCB-AB15867978BF}" = TOSHIBA Hotkey Utility
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Open For Business
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Pro Trial
"{7D2370AC-D8E6-4996-986A-19824F8A167C}" = Logitech QuickCam
"{7F22ADCE-3549-49C2-BC16-07B692F57EFF}" = 2600_Help
"{7F4C8163-F259-49A0-A018-2857A90578BC}" = Adobe InDesign CS2
"{80977342-27E8-4FF7-8B6A-D8D89461DA7F}" = TouchPad On/Off Utility
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{87A8CF4F-6C4D-4B17-8382-5954D37CBC9A}" = Youda Sushi Chef
"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = The Sims™ 2 FreeTime
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B12BA86-ADAC-4BA6-B441-FFC591087252}" = TOSHIBA Virtual Sound
"{8C5FAD77-F678-4758-A296-C12F08D179E0}" = Microsoft IntelliPoint 6.2
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for TOSHIBA
"{91A10409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office OneNote 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{98F837F9-A1B4-4155-AABC-4C80637165B5}" = Nokia Connectivity Cable Driver
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A346205-EA92-4406-B1AB-50379DA3F057}" = Autodesk DWF Viewer 7
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{9F15F5AD-AA10-46d9-B34D-AF2945DC65A6}" = 2600Trb
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A38D57D1-5F29-4691-B3DD-FE4B3A7B3AFE}" = TOSHIBA Power Saver
"{A3A37DA6-70C0-497C-BCB1-148E9EC1D32E}" = Revit Architecture 2009 (AutoCAD Suite)
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}" = Adobe Illustrator CS2
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6F5B704-06D3-4687-90F3-6195304AD755}" = The Sims™ 2 Apartment Life
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C12D609B-EB71-411B-82C3-9BE6D40435D7}" = Google SketchUp LayOut 6
"{C169D3BB-9A27-43F5-9979-09A0D65FE95C}" = SmartFTP Client
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C45F4811-31D5-4786-801D-F79CD06EDD85}" = SD Secure Module
"{CA0A1E54-CE0F-4366-B09C-A87B61DC5633}" = Symantec Network Drivers Update
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{DBC3FDEC-D5F4-439C-9A18-EF454A74E3DE}_is1" = NOD32 FiX
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Sims™ 2 Seasons
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{EB459C2F-41CA-4222-B9CA-F8EBA40B8DAB}" = Google SketchUp 6 Exporters
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1B8DB67-D30E-4FF9-A85F-3CEE51825AA2}" = SMSC IrCC V5.1.3600.5 SP2
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = The Sims™ 2 Bon Voyage
"{F47B2DF8-35EC-4B51-B5F2-0E03EF5F51DA}" = TIxx21/x515
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife
"{F92AB933-9FE7-4335-92BD-D1C3BA27613C}" = 3ds max 7
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FBE569CA-BFEB-4E57-A674-F94D938E1AEF}" = e-tax 2010
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"4CFD94C379217A02D5EA067615FF789CD731BCDB" = Windows Driver Package - Nokia (WUDFRd) WPD (11/03/2006 6.82.26.2)
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Illustrator CS2" = Adobe Illustrator CS2
"Adobe InDesign CS2 - {7F4C8163-F259-49A0-A018-2857A90578BC}" = Adobe InDesign CS2
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AutoCAD 2008 - English" = AutoCAD 2008 - English
"AutoCAD 2008 - English SP1" = AutoCAD 2008 - English SP1
"Autodesk Design Review 2009" = Autodesk Design Review 2009
"Autodesk Express Viewer" = Autodesk Express Viewer
"Browser Defender_is1" = Browser Defender 2.0.6.15
"Conexant USB Network" = ADSL USB Network Adapter
"EfntSSDSL" = Siemens Subscriber Networks SpeedStream DSL
"eMusic Promotion" = eMusic - 50 Free MP3 offer
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"Google Chrome" = Google Chrome
"HP Photo & Imaging" = HP Image Zone 4.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"ImgBurn" = ImgBurn
"InstallShield_{02EED746-8C5A-43C8-BB3D-D29C8B363A4D}" = TOSHIBA Zooming Utility
"InstallShield_{3A57482F-BEBC-47E4-ADA1-6302403C7E50}" = TOSHIBA Accessibility
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{5BCA8D15-BCB6-421E-9654-238B43456A4F}" = TOSHIBA Controls
"InstallShield_{7900D3A6-A9E8-4954-ACCB-AB15867978BF}" = TOSHIBA Hotkey Utility
"InstallShield_{80977342-27E8-4FF7-8B6A-D8D89461DA7F}" = TouchPad On/Off Utility
"InstallShield_{A38D57D1-5F29-4691-B3DD-FE4B3A7B3AFE}" = TOSHIBA Power Saver
"InstallShield_{F47B2DF8-35EC-4B51-B5F2-0E03EF5F51DA}" = Texas Instruments PCIxx21/x515 drivers.
"Macromedia Director MX 2004" = Macromedia Director MX 2004
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mIRC" = mIRC
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NOD32" = NOD32 antivirus system
"PainterClassicDeinstKey" = Painter Classic
"PC Diagnostic Tool" = TOSHIBA PC Diagnostic Tool
"QcDrv" = Logitech® Camera Driver
"Ragnarok Online" = Ragnarok Online
"SimPE_is1" = SimPE 0.72 (alpha)
"Sims2Pack Clean Installer " = Sims2Pack Clean Installer
"Spyware Doctor" = Spyware Doctor
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"VLC media player" = VLC media player 1.1.4
"Wacom Tablet Driver" = Wacom Tablet Driver
"Winamp" = Winamp (remove only)
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Zoo Tycoon 2" = Zoo Tycoon 2

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/10/2011 10:33:31 AM | Computer Name = JESSICA | Source = Application Hang | ID = 1002
Description = Hanging application wmplayer.exe, version 11.0.5721.5145, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/10/2011 1:14:26 PM | Computer Name = JESSICA | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 8/10/2011 5:02:38 PM | Computer Name = JESSICA | Source = Application Hang | ID = 1002
Description = Hanging application sdsetup.tmp, version 51.1052.0.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/10/2011 5:09:43 PM | Computer Name = JESSICA | Source = Application Hang | ID = 1002
Description = Hanging application sdsetup.tmp, version 51.1052.0.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/10/2011 6:53:27 PM | Computer Name = JESSICA | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/11/2011 3:50:25 PM | Computer Name = JESSICA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18702, fault address 0x00265067.

Error - 8/12/2011 9:25:53 AM | Computer Name = JESSICA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18702, fault address 0x00265067.

Error - 8/12/2011 9:29:02 AM | Computer Name = JESSICA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18702, fault address 0x00265067.

Error - 8/12/2011 9:29:58 AM | Computer Name = JESSICA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18702, fault address 0x00265067.

Error - 8/15/2011 3:39:19 AM | Computer Name = JESSICA | Source = Application Error | ID = 1000
Description = Faulting application pctsAuxs.exe, version 7.0.0.26, faulting module
unknown, version 0.0.0.0, fault address 0x636fabb8.

[ System Events ]
Error - 8/14/2011 1:18:35 PM | Computer Name = JESSICA | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 8/14/2011 1:30:29 PM | Computer Name = JESSICA | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 8/14/2011 2:29:19 PM | Computer Name = JESSICA | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PC Tools Security Service
service to connect.

Error - 8/14/2011 2:29:20 PM | Computer Name = JESSICA | Source = Service Control Manager | ID = 7000
Description = The PC Tools Security Service service failed to start due to the following
error: %%1053

Error - 8/15/2011 2:17:50 AM | Computer Name = JESSICA | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PC Tools Security Service
service to connect.

Error - 8/15/2011 2:17:50 AM | Computer Name = JESSICA | Source = Service Control Manager | ID = 7000
Description = The PC Tools Security Service service failed to start due to the following
error: %%1053

Error - 8/15/2011 3:39:11 AM | Computer Name = JESSICA | Source = Service Control Manager | ID = 7034
Description = The PC Tools Security Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 8/15/2011 3:40:22 AM | Computer Name = JESSICA | Source = Service Control Manager | ID = 7034
Description = The PC Tools Auxiliary Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 8/15/2011 4:09:22 AM | Computer Name = JESSICA | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 8/15/2011 4:10:30 AM | Computer Name = JESSICA | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm nod32drv PCTSD SerTVOutCtlr SrvcEKIOMngr SrvcSSIOMngr SYMTDI TPwSav


< End of report >
Hi hylim,

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-
Hi Jeff It's stated in your instructions that I will need an internet connection to download and install Microsoft Windows Recovery Console. I am unable to access the internet through the infected computer while running in safe mode. Normal mode is still freezing after start-up. I googled a few pages and found that the Recovery Console can be installed with the windows xp disc, but I do not have that with me. What do I do now? ):
Hi hylim!!

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    O1 - Hosts: 209.44.111.62 aware-protect.com
    O1 - Hosts: 209.44.111.62 www.aware-protect.com
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O4 - HKLM..\Run: [CFSServ.exe] File not found
    O4 - HKLM..\Run: [NDSTray.exe] File not found
    O4 - HKLM..\Run: [TFncKy] File not found
    O33 - MountPoints2\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{10c19989-860c-11dc-b53a-000fb09bba3b}\Shell - "" = AutoRun
    O33 - MountPoints2\{10c19989-860c-11dc-b53a-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{10c19989-860c-11dc-b53a-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\Shell - "" = AutoRun
    O33 - MountPoints2\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\Shell - "" = AutoRun
    O33 - MountPoints2\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
    O33 - MountPoints2\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\System\DriveGuard\DriveProtect.exe -run
    O33 - MountPoints2\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\Shell\Explore\Command - "" = E:\System\DriveGuard\DriveProtect.exe -run
    O33 - MountPoints2\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\Shell\Open\Command - "" = E:\System\DriveGuard\DriveProtect.exe -run
    O33 - MountPoints2\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\Shell - "" = AutoRun
    O33 - MountPoints2\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\Shell - "" = AutoRun
    O33 - MountPoints2\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\Shell - "" = AutoRun
    O33 - MountPoints2\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{77091a5a-e811-11dd-b823-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{77091a5a-e811-11dd-b823-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{77091a5a-e811-11dd-b823-0013ce7d50c8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{77091a5b-e811-11dd-b823-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{77091a5b-e811-11dd-b823-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{77091a5b-e811-11dd-b823-0013ce7d50c8}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\Shell\Auto\command - "" = E:\autorun.exe
    O33 - MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe
    O33 - MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\Shell\Auto\command - "" = autorun.exe
    O33 - MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe
    O33 - MountPoints2\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif
    O33 - MountPoints2\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\Shell - "" = AutoRun
    O33 - MountPoints2\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    [2011/08/11 07:58:43 | 000,012,470 | -HS- | M] () – C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\40yp52f18u8
    [2011/08/11 07:58:43 | 000,012,470 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\40yp52f18u8
    
    :Files
    ipconfig /flushdns /c
    dir "C:\Documents and Settings\Jessica Lim\Application Data\Veal" /s /c
    dir "C:\Documents and Settings\Jessica Lim\Application Data\Arextu" /s /c
    dir "C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\{4495784C-203E-4B51-9B83-8D3ACCD3DE73}" /s /c
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-

Once you have that completed, see if you can boot into Normal Mode and let me know how your system is acting. :) Don't forget to post the OTL log that is created into your next post as well.
Hi sorry I couldn't get to this sooner. I've run OTL as per your instructions and it rebooted my computer into normal mode. Here is the log:


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
209.44.111.62 aware-protect.com removed from HOSTS file successfully
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{0BF43445-2F28-4351-9252-17FE6E806AA0} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BF43445-2F28-4351-9252-17FE6E806AA0}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CFSServ.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NDSTray.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\TFncKy deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0e7a2630-7e3b-11de-b968-0013ce7d50c8}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0e7a2632-7e3b-11de-b968-0013ce7d50c8}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10c19989-860c-11dc-b53a-000fb09bba3b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10c19989-860c-11dc-b53a-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10c19989-860c-11dc-b53a-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10c19989-860c-11dc-b53a-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{10c19989-860c-11dc-b53a-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{10c19989-860c-11dc-b53a-000fb09bba3b}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19a6a2e4-942d-11dc-b553-000fb09bba3b}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3dfcc141-6b08-11e0-bce3-0013ce7d50c8}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5f3ad9b9-2dff-11dc-b48d-000fb09bba3b}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{624d1b5d-cdb1-11db-b41d-0013ce7d50c8}\ not found.
File E:\LaunchU3.exe -a not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\ not found.
File E:\System\DriveGuard\DriveProtect.exe -run not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\ not found.
File E:\System\DriveGuard\DriveProtect.exe -run not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62f14fb6-44aa-11dd-b6b4-0013ce7d50c8}\ not found.
File E:\System\DriveGuard\DriveProtect.exe -run not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64b85d05-2b81-11dd-b683-0013ce7d50c8}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64b85d06-2b81-11dd-b683-0013ce7d50c8}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6b2cbac6-8c59-11dc-b542-000fb09bba3b}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6b2cbac7-8c59-11dc-b542-000fb09bba3b}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6b2cbac8-8c59-11dc-b542-000fb09bba3b}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77091a5a-e811-11dd-b823-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77091a5a-e811-11dd-b823-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77091a5a-e811-11dd-b823-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77091a5a-e811-11dd-b823-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77091a5a-e811-11dd-b823-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77091a5a-e811-11dd-b823-0013ce7d50c8}\ not found.
File E:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77091a5b-e811-11dd-b823-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77091a5b-e811-11dd-b823-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77091a5b-e811-11dd-b823-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77091a5b-e811-11dd-b823-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77091a5b-e811-11dd-b823-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77091a5b-e811-11dd-b823-0013ce7d50c8}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\ not found.
File E:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a26318d4-77c0-11dd-b72a-0013ce7d50c8}\ not found.
File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\ not found.
File autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae54ab4d-73fd-11dd-b721-0013ce7d50c8}\ not found.
File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b31aa77c-d728-11db-b42d-0013ce7d50c8}\ not found.
File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7557f6-316b-11de-b8c6-0013ce7d50c8}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7557f7-316b-11de-b8c6-0013ce7d50c8}\ not found.
File G:\AutoRun.exe not found.
C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\40yp52f18u8 moved successfully.
C:\Documents and Settings\All Users\Application Data\40yp52f18u8 moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Jessica Lim\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Jessica Lim\Desktop\cmd.txt deleted successfully.
< dir "C:\Documents and Settings\Jessica Lim\Application Data\Veal" /s /c >
Volume in drive C is S3A2920D002
Volume Serial Number is D133-F66B
Directory of C:\Documents and Settings\Jessica Lim\Application Data\Veal
08/14/2011 01:07 AM .
08/14/2011 01:07 AM ..
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
2 Dir(s) 9,008,025,600 bytes free
C:\Documents and Settings\Jessica Lim\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Jessica Lim\Desktop\cmd.txt deleted successfully.
< dir "C:\Documents and Settings\Jessica Lim\Application Data\Arextu" /s /c >
Volume in drive C is S3A2920D002
Volume Serial Number is D133-F66B
Directory of C:\Documents and Settings\Jessica Lim\Application Data\Arextu
08/14/2011 05:45 PM .
08/14/2011 05:45 PM ..
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
2 Dir(s) 9,008,025,600 bytes free
C:\Documents and Settings\Jessica Lim\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Jessica Lim\Desktop\cmd.txt deleted successfully.
< dir "C:\Documents and Settings\Jessica Lim\Local Settings\Application Data\{4495784C-203E-4B51-9B83-8D3ACCD3DE73}" /s /c >
Volume in drive C is S3A2920D002
Volume Serial Number is D133-F66B
Directory of C:\Documents and Settings\Jessica Lim\Local Settings\Application Data
08/15/2011 06:04 PM 0 {4495784C-203E-4B51-9B83-8D3ACCD3DE73}
1 File(s) 0 bytes
Total Files Listed:
1 File(s) 0 bytes
0 Dir(s) 9,008,025,600 bytes free
C:\Documents and Settings\Jessica Lim\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Jessica Lim\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: Jessica Lim
->Temp folder emptied: 648389581 bytes
->Temporary Internet Files folder emptied: 771748646 bytes
->Java cache emptied: 1618737 bytes
->FireFox cache emptied: 3977243 bytes
->Google Chrome cache emptied: 7922176 bytes
->Flash cache emptied: 443426 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 13655018 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 182350373 bytes
->Flash cache emptied: 405 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 2675729 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 119736480 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 237704314 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34318 bytes
RecycleBin emptied: 658313011 bytes

Total Files Cleaned = 2,526.00 mb


OTL by OldTimer - Version 3.2.26.4 log created on 08182011_010828

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…


I'm running the computer on normal right now and I've made it past the five minute mark! It might be early to celebrate, but I'm keeping optimistic! Automatic updates is still coming up as disabled though. But I think the real test will be connecting to the internet, because that's when it used to get really shaky. I'll keep you informed!
Hi hylim,

I would like for you to go ahead and delete ComboFix on your Desktop by Right-click > Delete
———-

Let's now try this again. :)

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-

In your next reply please post the log created by ComboFix. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI