This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Very Sluggish Computer

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, Im wondering if anyone can help me out with a really sluggish computer. It was working fine until yesterday when a link opened on my computer and froze up my browser. I restarted the computer and ever since then it's been running really slowly. Booting into Windows the login screen takes a good 15 minutes to load and then after the username and password is entered it takes a good 20 - 30 minutes for my Desktop to load and everything runs extremely slowly. I can't even get most programs up and after awhile my system just freezes. If anyone could take a look at my logs below (I hope Ive included everything) I would really appreciate it.

Also, I have run several MBAM and SuperAntiSpyware; Pandascan, Trendmicro scans, etc and none of them have detected anything, but as the computer is extremely slow outside of Safemode, I think there has to be some sort of malware or problem. Thanks again.

OTL logfile created on: 9/21/2011 7:13:51 AM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Program Files
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.57 Gb Available Physical Memory | 78.94% Memory free
3.33 Gb Paging File | 3.08 Gb Available in Paging File | 92.41% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 27.60 Gb Free Space | 37.04% Space Free | Partition Type: NTFS
Drive G: | 350.00 Gb Total Space | 348.60 Gb Free Space | 99.60% Space Free | Partition Type: NTFS
Drive H: | 150.00 Gb Total Space | 93.26 Gb Free Space | 62.17% Space Free | Partition Type: NTFS
Drive M: | 431.51 Gb Total Space | 419.08 Gb Free Space | 97.12% Space Free | Partition Type: NTFS

Computer Name: LB109-001 | User Name: glui | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\HijackThis.exe (Trend Micro Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (avast! Antivirus) – C:\Program Files\Avast5\AvastSvc.exe (AVAST Software)
SRV - (Application Updater) – C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (AdvancedSystemCareService) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (NMSAccess) – C:\Program Files\StudioLine Photo Basic\NMSAccess32.exe ()
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (NMSAccessU) – C:\Program Files\Common Files\NMSAccessU.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (McShield) – C:\Program Files\Network Associates\VirusScan\Mcshield.exe (Network Associates, Inc.)
SRV - (McTaskManager) – C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe (Network Associates, Inc.)
SRV - (McAfeeFramework) – C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (Network Associates, Inc.)
SRV - (ICDSPTSV) – C:\WINDOWS\system32\IcdSptSv.exe (Sony Corporation)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (pavboot) – C:\WINDOWS\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (NaiAvFilter1) – C:\WINDOWS\system32\drivers\naiavf5x.sys (Network Associates, Inc.)
DRV - (NaiAvTdi1) – C:\WINDOWS\system32\drivers\mvstdi5x.sys (Network Associates, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://glendale.edu/
IE - HKCU\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.6\iobitToolbarIE.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.4
FF - prefs.js..extensions.enabledItems: [removed]:3.1.2
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.608
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {29c4afe1-db19-4298-8785-fcc94d1d6c1d}:0.6.2009110501
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110704
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=685749&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=685749"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: X:\Programs\iTunes 10\Mozilla Plugins\npitunes.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Gordon's Folder\Programs\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Gordon's Folder\Programs\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Gordon's Folder\Programs\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.3: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security, S.L.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2240: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2298: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1348: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\glui\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\glui\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=2: C:\Documents and Settings\glui\Local Settings\Application Data\Google\Update\1.2.121.9\npGoogleOneClick.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\glui\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\glui\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/19 07:24:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/19 07:24:15 | 000,000,000 | —D | M]

[2010/01/21 06:18:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\glui\Application Data\Mozilla\Extensions
[2011/09/19 14:19:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\glui\Application Data\Mozilla\Firefox\Profiles\js8gb5gg.default\extensions
[2011/03/28 06:12:35 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\glui\Application Data\Mozilla\Firefox\Profiles\js8gb5gg.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/21 06:27:41 | 000,000,000 | —D | M] ("Split Browser") – C:\Documents and Settings\glui\Application Data\Mozilla\Firefox\Profiles\js8gb5gg.default\extensions\{29c4afe1-db19-4298-8785-fcc94d1d6c1d}
[2011/08/15 05:46:50 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\glui\Application Data\Mozilla\Firefox\Profiles\js8gb5gg.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/08/15 05:46:55 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\glui\Application Data\Mozilla\Firefox\Profiles\js8gb5gg.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/08/15 05:47:32 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\glui\Application Data\Mozilla\Firefox\Profiles\js8gb5gg.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/03/28 06:12:27 | 000,000,000 | —D | M] (Download Statusbar) – C:\Documents and Settings\glui\Application Data\Mozilla\Firefox\Profiles\js8gb5gg.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2011/09/19 14:19:55 | 000,000,000 | —D | M] (FoxyProxy Standard) – C:\Documents and Settings\glui\Application Data\Mozilla\Firefox\Profiles\js8gb5gg.default\extensions\[removed]
[2010/08/05 14:21:31 | 000,000,000 | —D | M] (LogMeIn, Inc. Remote Access Plugin) – C:\Documents and Settings\glui\Application Data\Mozilla\Firefox\Profiles\js8gb5gg.default\extensions\[removed]
[2011/05/04 07:12:06 | 000,000,000 | —D | M] (QuickDrag) – C:\Documents and Settings\glui\Application Data\Mozilla\Firefox\Profiles\js8gb5gg.default\extensions\[removed]
[2011/09/20 14:01:49 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/20 07:32:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/09 06:51:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/03 07:05:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\GLUI\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\JS8GB5GG.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI
[2010/07/20 07:32:35 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/09/02 23:01:45 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/03/23 05:12:53 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\mozilla firefox\plugins\npPandoWebInst.dll
[2011/09/02 16:25:59 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\glui\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: Java Deployment Toolkit 6.0.230.5 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U23 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\glui\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\glui\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\pdf.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\glui\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\glui\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: Pando Web Installer (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Move Streaming Media Player (Enabled) = C:\Documents and Settings\glui\Application Data\Move Networks\plugins\npqmp071505000011.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\glui\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: DivX\u00AE Content Upload Plugin (Enabled) = C:\Gordon's Folder\Programs\DivX Content Uploader\npUpload.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Gordon's Folder\Programs\DivX Player\npDivxPlayerPlugin.dll
CHR - plugin: DivX\u00AE Web Player (Enabled) = C:\Gordon's Folder\Programs\DivX Web Player\npdivx32.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: Panda ActiveScan 2.0 (Enabled) = C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2009/07/28 06:03:42 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.6\iobitToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.6\iobitToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [FJTWAIN Setup] C:\WINDOWS\Twain_32\fjscan32\FjtwSetup.exe (FUJITSU LIMITED)
O4 - HKLM..\Run: [FtLnSOP_setup] C:\WINDOWS\twain_32\Fjscan32\SOP\FtLnSOP.exe (PFU LIMITED)
O4 - HKLM..\Run: [HPUsageTracking] C:\Program Files\HP\HP UT\bin\hppusg.exe ( )
O4 - HKLM..\Run: [iTunesHelper] "X:\Programs\iTunes 10\iTunesHelper.exe" File not found
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe (Network Associates, Inc.)
O4 - HKLM..\Run: [Network Associates Error Reporting Service] C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe (Network Associates, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE (Network Associates, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ToolBoxFX] C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe (HP)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKCU..\Run: [HDDHealth] E:\May 11, 2008\Programs\HDD Health\HDDHealth.exe -wl File not found
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\glui\Start Menu\Programs\Startup\MagicDisc.lnk = H:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html File not found
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Gordon's Folder\Programs\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: glendale.edu ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: glendale.edu ([gccss] https in Trusted sites)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {332bd5a0-8000-11d7-b657-00c04faedb18} Reg Error: Value error. (Oracle JInitiator 1.1.8.22)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} http://picasaweb.google.com/s/v/49.12/uploader2.cab (UploadListView Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1130463694843 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1156470157703 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.100.4.10 10.100.4.20 10.100.4.30
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{013FE026-B536-4567-9708-B1A6C453743B}: DhcpNameServer = 10.100.4.10 10.100.4.20 10.100.4.30
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{627D4264-12D7-47C3-BCB3-55554BA7AF67}: DhcpNameServer = 10.100.4.10 10.100.4.20 10.100.4.30
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\glui\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\glui\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/10/27 18:15:39 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{06cf9354-8bb8-11e0-b5e1-0019b92aa2a9}\Shell - "" = AutoRun
O33 - MountPoints2\{06cf9354-8bb8-11e0-b5e1-0019b92aa2a9}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{06cf9354-8bb8-11e0-b5e1-0019b92aa2a9}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{445eb834-f771-11dd-b53f-0019b92aa2a9}\Shell - "" = AutoRun
O33 - MountPoints2\{445eb834-f771-11dd-b53f-0019b92aa2a9}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{445eb834-f771-11dd-b53f-0019b92aa2a9}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{690a9398-7b91-11de-b584-0019b92aa2a9}\Shell\AutoRun\command - "" = P:\StartPortableApps.exe
O33 - MountPoints2\{78612508-6137-11dc-9194-0019b92aa2a9}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\setup.exe – [2008/04/13 17:12:34 | 000,023,040 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{a13f796e-4610-11de-b571-0019b92aa2a9}\Shell\AutoRun\command - "" = I:\StartPortableApps.exe
O33 - MountPoints2\{b6424833-b6c9-11e0-b5e4-0019b92aa2a9}\Shell\AutoRun\command - "" = P:\CA_EdgeLitemobile.exe
O33 - MountPoints2\{dac49c83-d226-11df-b5cb-0019b92aa2a9}\Shell\AutoRun\command - "" = F:\StartPortableApps.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/09/21 07:12:26 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Program Files\OTL.exe
[2011/09/21 07:09:41 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Program Files\HijackThis.exe
[2011/09/21 06:54:20 | 000,000,000 | —D | C] – C:\Documents and Settings\glui\Application Data\Auslogics
[2011/09/21 06:50:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Auslogics
[2011/09/21 06:50:20 | 000,000,000 | —D | C] – C:\Program Files\Auslogics
[2011/09/21 06:49:49 | 000,454,120 | —- | C] (CBS Interactive) – C:\Program Files\cnet_registry-cleaner-setup_exe.exe
[2011/09/20 14:01:56 | 000,000,000 | —D | C] – C:\Documents and Settings\glui\Application Data\Search Settings
[2011/09/20 14:01:47 | 000,000,000 | —D | C] – C:\Program Files\IObit Toolbar
[2011/09/20 14:01:47 | 000,000,000 | —D | C] – C:\Program Files\Application Updater
[2011/09/20 14:01:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Advanced SystemCare 4
[2011/09/20 14:00:52 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/09/20 11:13:47 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF13264.exe
[2011/09/20 11:11:19 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\cmd.execf
[2011/09/20 11:08:59 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2011/09/20 09:37:22 | 003,194,296 | —- | C] (Javacool Software LLC ) – C:\Program Files\spywareblastersetup44.exe
[2011/09/20 09:34:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/09/20 09:34:46 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/09/20 09:34:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/09/20 09:33:56 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Program Files\spybotsd162.exe
[2011/09/20 07:06:11 | 000,442,200 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/09/19 07:45:06 | 000,000,000 | —D | C] – C:\Documents and Settings\glui\Desktop\The Standby
[2011/09/19 07:26:20 | 000,000,000 | —D | C] – C:\Documents and Settings\glui\Desktop\Carriere
[2011/09/19 07:23:27 | 013,983,976 | —- | C] (Mozilla) – C:\Program Files\Firefox Setup 6.0.2.exe
[2011/09/19 07:19:42 | 000,000,000 | —D | C] – C:\Documents and Settings\glui\My Documents\Adobe
[2011/08/31 07:16:01 | 000,000,000 | —D | C] – C:\Documents and Settings\glui\Desktop\TP2 Time Stamp
[2011/08/30 07:37:56 | 000,000,000 | —D | C] – C:\Documents and Settings\glui\Desktop\Calendar
[2011/08/23 06:01:01 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/08/23 06:00:04 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/08/23 05:59:59 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2011/08/23 05:58:06 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/08/23 05:57:57 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2010/09/08 10:34:35 | 007,302,104 | —- | C] (AOL Inc.) – C:\Program Files\Install_AIM.exe
[2010/06/30 06:22:56 | 030,071,680 | —- | C] (IObit ) – C:\Program Files\asc-setup.exe
[2010/06/21 08:54:46 | 017,327,195 | —- | C] (Mooii) – C:\Program Files\PhotoScapeSetup_V3.5.exe
[2010/01/21 06:16:10 | 008,087,352 | —- | C] (Mozilla) – C:\Program Files\Firefox Setup 3.5.7.exe
[2009/12/03 05:57:29 | 006,008,376 | —- | C] (ashampoo GmbH & Co. KG ) – C:\Program Files\ashampoo_burning_studio_6_free_676_4280.exe
[2009/10/26 04:47:03 | 000,714,528 | —- | C] (Sun Microsystems, Inc.) – C:\Program Files\jre-6u16-windows-i586-iftw.exe
[2009/10/19 07:42:06 | 003,012,768 | —- | C] (Javacool Software LLC ) – C:\Program Files\spywareblastersetup42.exe
[2009/10/01 12:09:05 | 001,853,922 | —- | C] (Digital Volcano ) – C:\Program Files\DuplicateCleaner.exe
[2009/09/17 06:20:33 | 008,416,452 | —- | C] (AoAMedia.Com ) – C:\Program Files\audioextractor.exe
[2009/09/17 05:51:03 | 000,714,528 | —- | C] (Sun Microsystems, Inc.) – C:\Program Files\JavaSetup6u16.exe
[2009/06/29 10:34:59 | 013,906,808 | —- | C] (AOL LLC.) – C:\Program Files\aim65111.exe
[2009/06/29 10:32:27 | 000,415,380 | —- | C] (AOL LLC.) – C:\Program Files\aim6.8.14.6.exe
[2009/04/24 05:18:49 | 001,987,853 | —- | C] (Ipswitch, Inc. ) – C:\Program Files\wsftp6.exe
[2008/02/13 06:55:10 | 006,734,904 | —- | C] (Fengtao Software Inc. ) – C:\Program Files\DVDFabPlatinum4062_avangate-689.exe
[2008/01/24 06:46:27 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\glui\Application Data\pcouffin.sys
[2008/01/16 07:09:18 | 000,828,416 | —- | C] (jan debis) – C:\Program Files\Leechftp.exe
[2007/07/10 06:36:58 | 028,868,320 | —- | C] (Microsoft Corporation) – C:\Program Files\FileFormatConverters.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/21 07:14:26 | 000,625,664 | —- | M] () – C:\Program Files\dds.scr
[2011/09/21 07:13:24 | 000,059,101 | —- | M] () – C:\Documents and Settings\glui\My Documents\cc_20110921_0713.reg
[2011/09/21 07:12:31 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Program Files\OTL.exe
[2011/09/21 07:09:43 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Program Files\HijackThis.exe
[2011/09/21 07:09:28 | 001,402,880 | —- | M] () – C:\Program Files\HiJackThis.msi
[2011/09/21 07:08:54 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/09/21 07:06:24 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/09/21 07:05:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/09/21 07:03:26 | 000,000,268 | —- | M] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/09/21 07:00:20 | 000,000,256 | —- | M] () – C:\WINDOWS\tasks\WGASetup.job
[2011/09/21 06:49:52 | 000,454,120 | —- | M] (CBS Interactive) – C:\Program Files\cnet_registry-cleaner-setup_exe.exe
[2011/09/21 05:31:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2081637087-1150628163-1549625157-1006UA.job
[2011/09/21 02:01:17 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-LB109-001-glui.job
[2011/09/20 20:32:45 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2081637087-1150628163-1549625157-1006Core.job
[2011/09/20 18:34:42 | 000,002,277 | —- | M] () – C:\Documents and Settings\glui\Desktop\Google Chrome.lnk
[2011/09/20 18:34:42 | 000,002,255 | —- | M] () – C:\Documents and Settings\glui\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/09/20 17:08:11 | 000,000,512 | —- | M] () – C:\WINDOWS\randseed.rnd
[2011/09/20 14:32:51 | 2413,577,216 | —- | M] () – C:\Documents and Settings\glui\Desktop\backup-6311.pst
[2011/09/20 14:32:51 | 000,271,360 | —- | M] () – C:\Documents and Settings\glui\Desktop\archive.pst
[2011/09/20 14:15:40 | 000,000,792 | —- | M] () – C:\Documents and Settings\glui\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/09/20 14:01:06 | 000,000,892 | —- | M] () – C:\Documents and Settings\glui\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/09/20 14:00:24 | 030,071,680 | —- | M] (IObit ) – C:\Program Files\asc-setup.exe
[2011/09/20 11:24:42 | 000,403,471 | —- | M] () – C:\Documents and Settings\glui\My Documents\cc_20110920_1121.reg
[2011/09/20 11:14:08 | 000,000,233 | —- | M] () – C:\Start_.cmd
[2011/09/20 11:11:20 | 000,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\cmd.execf
[2011/09/20 11:11:20 | 000,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF13264.exe
[2011/09/20 10:46:25 | 003,642,336 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/09/20 10:36:15 | 000,444,832 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/09/20 10:36:15 | 000,072,582 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/09/20 09:41:49 | 003,194,296 | —- | M] (Javacool Software LLC ) – C:\Program Files\spywareblastersetup44.exe
[2011/09/20 09:34:55 | 000,000,951 | —- | M] () – C:\Documents and Settings\glui\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/09/20 09:34:06 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Program Files\spybotsd162.exe
[2011/09/20 07:06:11 | 000,002,617 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/09/19 07:24:24 | 000,000,742 | —- | M] () – C:\Documents and Settings\glui\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/09/19 07:24:24 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/09/19 07:23:52 | 013,983,976 | —- | M] (Mozilla) – C:\Program Files\Firefox Setup 6.0.2.exe
[2011/09/08 05:45:13 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/09/06 13:45:29 | 000,199,304 | —- | M] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2011/09/06 13:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2011/09/06 13:38:05 | 000,442,200 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/09/06 13:37:53 | 000,320,856 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2011/09/06 13:36:38 | 000,034,392 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/09/06 13:36:36 | 000,052,568 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/09/06 13:36:23 | 000,110,552 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/09/06 13:36:20 | 000,104,536 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2011/09/06 13:36:12 | 000,020,568 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/09/06 13:33:11 | 000,030,808 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/08/31 17:00:50 | 000,022,216 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/08/29 13:04:19 | 000,171,598 | —- | M] () – C:\Documents and Settings\glui\Desktop\LA COUNTY FAIR 2011.pdf
[2011/08/23 15:35:12 | 000,056,025 | —- | M] () – C:\Documents and Settings\glui\My Documents\The Standby - Episode Two 08.23.11.fdr
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/21 07:14:22 | 000,625,664 | —- | C] () – C:\Program Files\dds.scr
[2011/09/21 07:13:18 | 000,059,101 | —- | C] () – C:\Documents and Settings\glui\My Documents\cc_20110921_0713.reg
[2011/09/21 07:09:25 | 001,402,880 | —- | C] () – C:\Program Files\HiJackThis.msi
[2011/09/20 14:15:19 | 000,271,360 | —- | C] () – C:\Documents and Settings\glui\Desktop\archive.pst
[2011/09/20 14:01:36 | 000,000,268 | —- | C] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/09/20 14:01:06 | 000,000,892 | —- | C] () – C:\Documents and Settings\glui\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced SystemCare 4.lnk
[2011/09/20 11:21:13 | 000,403,471 | —- | C] () – C:\Documents and Settings\glui\My Documents\cc_20110920_1121.reg
[2011/09/20 11:14:08 | 000,000,233 | —- | C] () – C:\Start_.cmd
[2011/09/20 09:34:55 | 000,000,951 | —- | C] () – C:\Documents and Settings\glui\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/09/19 07:24:24 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/08/29 13:04:19 | 000,171,598 | —- | C] () – C:\Documents and Settings\glui\Desktop\LA COUNTY FAIR 2011.pdf
[2011/08/23 12:49:39 | 000,056,025 | —- | C] () – C:\Documents and Settings\glui\My Documents\The Standby - Episode Two 08.23.11.fdr
[2011/02/24 10:00:36 | 000,000,132 | —- | C] () – C:\Documents and Settings\glui\Application Data\Adobe PNG Format CS5 Prefs
[2010/06/17 09:01:19 | 079,666,688 | —- | C] () – C:\Program Files\StudioLine_PC3.msi
[2010/06/17 08:23:04 | 068,657,152 | —- | C] () – C:\Program Files\StudioLine_PB3.msi
[2010/04/30 08:05:28 | 000,000,757 | —- | C] () – C:\WINDOWS\FJTWSTI.INI
[2010/04/30 08:05:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi60Fex0C0A.dll
[2010/04/30 08:05:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi60Fex0410.dll
[2010/04/30 08:05:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi60Fex040C.dll
[2010/04/30 08:05:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi60Fex0407.dll
[2010/04/30 08:05:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex0C0A.dll
[2010/04/30 08:05:26 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex0419.dll
[2010/04/30 08:05:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi60Fex0409.dll
[2010/04/30 08:05:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5220ex0412.dll
[2010/04/30 08:05:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi60Fex0804.dll
[2010/04/30 08:05:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi60Fex0411.dll
[2010/04/30 08:05:26 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5220ex0804.dll
[2010/04/30 08:05:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex0409.dll
[2010/04/30 08:05:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex0410.dll
[2010/04/30 08:05:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex040C.dll
[2010/04/30 08:05:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex0409.dll
[2010/04/30 08:05:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5220ex0407.dll
[2010/04/30 08:05:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex0C0A.dll
[2010/04/30 08:05:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex0419.dll
[2010/04/30 08:05:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex0410.dll
[2010/04/30 08:05:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex040C.dll
[2010/04/30 08:05:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex0409.dll
[2010/04/30 08:05:25 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5120ex0407.dll
[2010/04/30 08:05:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5530ex0411.dll
[2010/04/30 08:05:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5220ex0411.dll
[2010/04/30 08:05:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5120ex0412.dll
[2010/04/30 08:05:25 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5120ex0411.dll
[2010/04/30 08:05:25 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5120ex0804.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex0C0A.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex0419.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex0410.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex040C.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5530ex0407.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5110ex0410.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5110ex0409.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5110ex0407.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi4340ex0C0A.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi4340ex0410.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi4340ex040C.dll
[2010/04/30 08:05:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi4340ex0407.dll
[2010/04/30 08:05:24 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5530ex0412.dll
[2010/04/30 08:05:24 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5110ex0411.dll
[2010/04/30 08:05:24 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4340ex0409.dll
[2010/04/30 08:05:24 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5530ex0804.dll
[2010/04/30 08:05:24 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5110ex0804.dll
[2010/04/30 08:05:24 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4340ex0804.dll
[2010/04/30 08:05:24 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4340ex0411.dll
[2010/04/30 08:05:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5110ex0C0A.dll
[2010/04/30 08:05:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5110ex040C.dll
[2010/04/30 08:05:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi42202ex0C0A.dll
[2010/04/30 08:05:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi42202ex0410.dll
[2010/04/30 08:05:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi42202ex040C.dll
[2010/04/30 08:05:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi42202ex0407.dll
[2010/04/30 08:05:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi41202ex0C0A.dll
[2010/04/30 08:05:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi41202ex0410.dll
[2010/04/30 08:05:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi41202ex040C.dll
[2010/04/30 08:05:23 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi41202ex0407.dll
[2010/04/30 08:05:23 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi42202ex0409.dll
[2010/04/30 08:05:23 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi41202ex0409.dll
[2010/04/30 08:05:23 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5650ex0804.dll
[2010/04/30 08:05:23 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5650ex0411.dll
[2010/04/30 08:05:23 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi42202ex0804.dll
[2010/04/30 08:05:23 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi42202ex0411.dll
[2010/04/30 08:05:23 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi41202ex0804.dll
[2010/04/30 08:05:23 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi41202ex0411.dll
[2010/04/30 08:05:22 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\fi4530ex.dll
[2010/04/30 08:05:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5750ex0C0A.dll
[2010/04/30 08:05:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5750ex0410.dll
[2010/04/30 08:05:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5750ex040C.dll
[2010/04/30 08:05:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5750ex0407.dll
[2010/04/30 08:05:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5650ex0C0A.dll
[2010/04/30 08:05:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5650ex0410.dll
[2010/04/30 08:05:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5650ex040C.dll
[2010/04/30 08:05:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\fi5650ex0407.dll
[2010/04/30 08:05:22 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5750ex0409.dll
[2010/04/30 08:05:22 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi5650ex0409.dll
[2010/04/30 08:05:22 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4530ex0c0a.dll
[2010/04/30 08:05:22 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4530ex0410.dll
[2010/04/30 08:05:22 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4530ex040C.dll
[2010/04/30 08:05:22 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4530ex0409.dll
[2010/04/30 08:05:22 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4530ex0407.dll
[2010/04/30 08:05:22 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5750ex0804.dll
[2010/04/30 08:05:22 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi5750ex0411.dll
[2010/04/30 08:05:22 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4530ex0804.dll
[2010/04/30 08:05:22 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4530ex0411.dll
[2010/04/30 08:05:21 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\fi4220ex.dll
[2010/04/30 08:05:21 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4220ex0C0A.dll
[2010/04/30 08:05:21 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4220ex0410.dll
[2010/04/30 08:05:21 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4220ex040C.dll
[2010/04/30 08:05:21 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4220ex0409.dll
[2010/04/30 08:05:21 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4220ex0407.dll
[2010/04/30 08:05:21 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4120ex0C0A.dll
[2010/04/30 08:05:21 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4120ex0410.dll
[2010/04/30 08:05:21 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4120ex040C.dll
[2010/04/30 08:05:21 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4120ex0409.dll
[2010/04/30 08:05:21 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\fi4120ex0407.dll
[2010/04/30 08:05:21 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4220ex0804.dll
[2010/04/30 08:05:21 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4220ex0411.dll
[2010/04/30 08:05:21 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4120ex0804.dll
[2010/04/30 08:05:20 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\fi4120ex.dll
[2010/04/30 08:05:20 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\fi4120ex0411.dll
[2010/04/30 05:54:13 | 000,000,314 | —- | C] () – C:\WINDOWS\maxlink.ini
[2010/04/30 05:36:04 | 039,714,912 | —- | C] () – C:\Program Files\isis_050901.exe
[2010/04/29 14:17:34 | 025,146,224 | —- | C] () – C:\Program Files\Ft9i5uX5s.exe
[2010/02/01 07:30:40 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/02/01 07:17:11 | 005,395,536 | —- | C] () – C:\Program Files\SetupAnyDVD6609.exe
[2010/01/26 14:46:08 | 000,009,684 | —- | C] () – C:\Program Files\calendar_2010-08-01_2010-09-30.pdf
[2010/01/22 06:24:45 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/10/19 07:39:08 | 005,154,304 | —- | C] () – C:\Program Files\WindowsDefender.msi
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/28 05:40:31 | 000,219,648 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/07/28 05:40:31 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/07/28 05:40:31 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/07/28 05:40:31 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/04/24 08:12:50 | 002,296,642 | —- | C] () – C:\Program Files\phpBB-3.0.4.zip
[2009/02/27 07:13:20 | 000,000,000 | —- | C] () – C:\WINDOWS\DVEdit.INI
[2009/02/27 07:09:19 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\trc.dll
[2009/02/27 07:09:00 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\IcdSptSvps.dll
[2009/02/27 07:08:59 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\dsp_trc.dll
[2008/08/11 14:26:21 | 000,710,382 | —- | C] () – C:\Program Files\OutlookPH.exe
[2008/01/24 06:46:27 | 000,007,887 | —- | C] () – C:\Documents and Settings\glui\Application Data\pcouffin.cat
[2008/01/24 06:46:27 | 000,001,144 | —- | C] () – C:\Documents and Settings\glui\Application Data\pcouffin.inf
[2008/01/16 07:12:17 | 000,000,117 | —- | C] () – C:\Program Files\default.lfq
[2008/01/16 07:09:18 | 000,018,944 | R— | C] () – C:\WINDOWS\eraser.exe
[2008/01/16 07:09:18 | 000,000,627 | -H– | C] () – C:\Program Files\uninstall.uif
[2007/10/16 05:23:39 | 000,000,052 | —- | C] () – C:\WINDOWS\Relax.ini
[2007/10/08 04:08:05 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/10/08 04:07:28 | 000,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2007/08/07 12:57:42 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2007/06/05 09:57:04 | 000,110,011 | —- | C] () – C:\WINDOWS\hppins06.dat.temp
[2007/06/05 09:57:04 | 000,001,320 | —- | C] () – C:\WINDOWS\hppmdl06.dat.temp
[2007/05/18 07:18:25 | 000,000,668 | R— | C] () – C:\WINDOWS\System32\hppapr05.dat
[2007/05/18 07:18:04 | 000,000,135 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2007/05/18 06:26:40 | 000,000,693 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2007/05/18 06:22:48 | 000,109,384 | —- | C] () – C:\WINDOWS\hppins06.dat
[2007/05/18 06:22:48 | 000,001,320 | —- | C] () – C:\WINDOWS\hppmdl06.dat
[2007/04/17 10:28:25 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4642.dll
[2007/04/17 10:28:24 | 000,348,880 | —- | C] () – C:\WINDOWS\System32\igmedkrn.dll
[2007/04/16 06:41:05 | 000,000,214 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/02/01 10:38:48 | 000,000,931 | —- | C] () – C:\WINDOWS\posteriza.INI
[2007/01/29 22:03:40 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/01/25 03:52:26 | 000,065,536 | —- | C] () – C:\Program Files\Common Files\NMSAccessU.exe
[2006/12/14 07:29:49 | 000,000,040 | —- | C] () – C:\WINDOWS\nero.INI
[2006/12/12 09:24:42 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/11/27 10:40:36 | 000,528,384 | —- | C] () – C:\WINDOWS\System32\BladeEnc.dll
[2006/11/27 10:40:36 | 000,120,832 | —- | C] () – C:\WINDOWS\System32\ShnDll32.dll
[2006/11/26 20:47:28 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\flac.exe
[2006/11/20 21:47:00 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\metaflac.exe
[2006/09/12 06:13:39 | 000,003,978 | —- | C] () – C:\WINDOWS\CDPlayer.ini
[2006/08/10 11:11:01 | 000,001,555 | —- | C] () – C:\Program Files\PC Inspector File Recovery.lnk
[2006/08/01 07:36:04 | 000,124,416 | —- | C] () – C:\Documents and Settings\glui\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/01 07:36:04 | 000,000,127 | —- | C] () – C:\Documents and Settings\glui\Local Settings\Application Data\fusioncache.dat
[2006/07/21 11:54:12 | 000,462,848 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2005/11/18 11:47:26 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/10/31 18:54:27 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/10/31 18:23:06 | 000,001,372 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005/10/31 18:04:56 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2005/10/31 18:04:51 | 000,051,712 | —- | C] () – C:\WINDOWS\System32\JinPanel.dll
[2005/10/31 13:27:03 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/10/27 18:17:06 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/10/27 18:13:31 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/10/27 11:09:04 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/10/27 11:08:14 | 003,642,336 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 05:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 05:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2001/08/23 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 05:00:00 | 000,444,832 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 05:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2001/08/23 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 05:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2001/08/23 05:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2001/08/23 05:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2001/08/23 05:00:00 | 000,072,582 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 05:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/08/23 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2001/07/07 03:00:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/09/08 10:36:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2010/08/31 05:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/06/24 09:11:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Arclab
[2009/12/03 05:58:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2010/06/17 09:03:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\H&M; System Software
[2011/09/21 02:23:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2007/05/21 04:46:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2005/10/27 18:37:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Network Associates
[2010/03/23 05:13:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/02/24 09:58:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/02/01 07:30:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2011/09/20 09:43:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/29 10:36:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/05/06 09:06:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2011/04/05 06:51:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2008/06/05 05:28:20 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\.purple
[2007/10/08 04:10:09 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\acccore
[2006/08/22 07:22:16 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\Aim
[2010/12/13 08:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\AnvSoft
[2009/12/03 06:00:00 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\Ashampoo
[2011/09/21 06:56:06 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\Auslogics
[2011/01/26 12:45:25 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\avidemux
[2008/01/16 06:48:11 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\CoffeeCup Software
[2008/10/15 11:16:34 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\Elluminate
[2011/03/01 12:03:07 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\enchant
[2011/04/04 07:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\Final Draft
[2010/04/30 08:12:56 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\Fujitsu
[2008/06/05 05:24:14 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\gtk-2.0
[2011/01/26 07:00:56 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\ImgBurn
[2011/09/20 14:02:40 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\IObit
[2007/04/24 13:01:06 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\Leadertech
[2008/09/19 07:41:45 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\MailWasherPro
[2011/04/05 08:08:41 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\PeaZip
[2010/06/21 08:56:42 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\PhotoScape
[2008/01/17 06:32:34 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\PushSyncData
[2011/09/20 14:01:57 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\Search Settings
[2007/10/16 05:27:12 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\Snapfish
[2011/02/24 14:23:08 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2009/05/22 08:29:32 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\TeamViewer
[2009/05/22 08:12:38 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\uTorrent
[2009/01/22 09:05:49 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\Vso
[2010/02/22 14:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\glui\Application Data\Xerox
[2011/09/21 07:03:26 | 000,000,268 | —- | M] () – C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2011/09/21 07:08:54 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/09/21 07:00:20 | 000,000,256 | —- | M] () – C:\WINDOWS\Tasks\WGASetup.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/11/16 15:37:07 | 000,001,024 | —- | M] () – C:\.rnd
[2005/10/27 18:15:39 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/04/09 05:57:11 | 000,000,211 | —- | M] () – C:\Boot.bak
[2009/07/28 05:43:14 | 000,000,281 | -HS- | M] () – C:\boot.ini
[2011/09/20 11:12:05 | 000,000,647 | —- | M] () – C:\Bug.txt
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2005/10/27 18:15:39 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/10/27 18:15:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/06/03 10:59:38 | 000,002,858 | -H– | M] () – C:\IPH.PH
[2010/08/04 15:53:03 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2009/01/22 06:48:00 | 002,737,808 | —- | M] (Malwarebytes Corporation ) – C:\mbam-setup.exe
[2005/10/27 18:15:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2005/10/27 18:26:25 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/01/27 06:32:29 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/09/21 07:05:32 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2010/04/26 07:06:21 | 016,205,198 | —- | M] (Mooii) – C:\PhotoScapeSetup_V3.4.exe
[2008/06/02 07:38:56 | 000,002,208 | —- | M] () – C:\soaperr.log
[2011/09/20 11:14:08 | 000,000,233 | —- | M] () – C:\Start_.cmd
[2010/05/23 14:33:05 | 000,000,109 | —- | M] () – C:\WS_FTP.LOG
[2007/03/01 06:07:08 | 000,000,146 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/10/27 18:15:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/04/25 06:07:24 | 000,069,120 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp43e.dll
[2011/07/15 14:16:11 | 000,053,632 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/09/06 13:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/06/29 10:32:47 | 000,415,380 | —- | M] (AOL LLC.) – C:\Program Files\aim6.8.14.6.exe
[2009/06/29 10:35:09 | 013,906,808 | —- | M] (AOL LLC.) – C:\Program Files\aim65111.exe
[2011/09/20 14:00:24 | 030,071,680 | —- | M] (IObit ) – C:\Program Files\asc-setup.exe
[2009/12/03 05:57:42 | 006,008,376 | —- | M] (ashampoo GmbH & Co. KG ) – C:\Program Files\ashampoo_burning_studio_6_free_676_4280.exe
[2009/09/17 06:20:54 | 008,416,452 | —- | M] (AoAMedia.Com ) – C:\Program Files\audioextractor.exe
[2010/01/26 14:46:14 | 000,009,684 | —- | M] () – C:\Program Files\calendar_2010-08-01_2010-09-30.pdf
[2011/09/21 06:49:52 | 000,454,120 | —- | M] (CBS Interactive) – C:\Program Files\cnet_registry-cleaner-setup_exe.exe
[2011/09/21 07:14:26 | 000,625,664 | —- | M] () – C:\Program Files\dds.scr
[2008/04/17 05:52:08 | 000,000,117 | —- | M] () – C:\Program Files\default.lfq
[2009/10/01 12:10:19 | 001,853,922 | —- | M] (Digital Volcano ) – C:\Program Files\DuplicateCleaner.exe
[2008/02/13 06:55:25 | 006,734,904 | —- | M] (Fengtao Software Inc. ) – C:\Program Files\DVDFabPlatinum4062_avangate-689.exe
[2007/07/10 06:37:15 | 028,868,320 | —- | M] (Microsoft Corporation) – C:\Program Files\FileFormatConverters.exe
[2010/01/21 06:16:25 | 008,087,352 | —- | M] (Mozilla) – C:\Program Files\Firefox Setup 3.5.7.exe
[2011/09/19 07:23:52 | 013,983,976 | —- | M] (Mozilla) – C:\Program Files\Firefox Setup 6.0.2.exe
[2010/04/30 07:46:26 | 025,146,224 | —- | M] () – C:\Program Files\Ft9i5uX5s.exe
[2011/09/21 07:09:43 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Program Files\HijackThis.exe
[2011/09/21 07:10:03 | 000,013,702 | —- | M] () – C:\Program Files\hijackthis.log
[2011/09/21 07:09:28 | 001,402,880 | —- | M] () – C:\Program Files\HiJackThis.msi
[2010/09/08 10:34:47 | 007,302,104 | —- | M] (AOL Inc.) – C:\Program Files\Install_AIM.exe
[2010/04/30 05:36:25 | 039,714,912 | —- | M] () – C:\Program Files\isis_050901.exe
[2009/09/17 05:51:35 | 000,714,528 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\JavaSetup6u16.exe
[2009/10/26 04:47:34 | 000,714,528 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\jre-6u16-windows-i586-iftw.exe
[1998/08/01 21:17:04 | 000,000,624 | —- | M] () – C:\Program Files\leechftp.cnt
[1999/04/16 21:40:50 | 000,828,416 | —- | M] (jan debis) – C:\Program Files\Leechftp.exe
[1998/08/01 21:17:32 | 000,094,157 | —- | M] () – C:\Program Files\LEECHFTP.HLP
[2011/09/21 07:12:31 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Program Files\OTL.exe
[2008/08/11 14:26:23 | 000,710,382 | —- | M] () – C:\Program Files\OutlookPH.exe
[2006/08/10 11:11:01 | 000,001,555 | —- | M] () – C:\Program Files\PC Inspector File Recovery.lnk
[2010/06/21 08:55:08 | 017,327,195 | —- | M] (Mooii) – C:\Program Files\PhotoScapeSetup_V3.5.exe
[2009/04/24 08:12:55 | 002,296,642 | —- | M] () – C:\Program Files\phpBB-3.0.4.zip
[1999/04/16 19:37:12 | 000,003,188 | —- | M] () – C:\Program Files\readme.txt
[2010/02/01 07:23:32 | 005,395,536 | —- | M] () – C:\Program Files\SetupAnyDVD6609.exe
[2011/09/20 09:34:06 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Program Files\spybotsd162.exe
[2009/10/19 07:42:23 | 003,012,768 | —- | M] (Javacool Software LLC ) – C:\Program Files\spywareblastersetup42.exe
[2011/09/20 09:41:49 | 003,194,296 | —- | M] (Javacool Software LLC ) – C:\Program Files\spywareblastersetup44.exe
[2010/06/17 08:23:22 | 068,657,152 | —- | M] () – C:\Program Files\StudioLine_PB3.msi
[2010/06/17 09:01:30 | 079,666,688 | —- | M] () – C:\Program Files\StudioLine_PC3.msi
[2008/01/16 07:09:18 | 000,000,627 | -H– | M] () – C:\Program Files\uninstall.uif
[2009/10/19 07:39:18 | 005,154,304 | —- | M] () – C:\Program Files\WindowsDefender.msi
[2009/04/24 05:18:54 | 001,987,853 | —- | M] (Ipswitch, Inc. ) – C:\Program Files\wsftp6.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/10/27 11:07:40 | 000,090,112 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/10/27 11:07:40 | 000,630,784 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/10/27 11:07:40 | 000,413,696 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >
[2010/06/30 06:37:17 | 000,000,000 | —D | M] – C:\Program Files\Advanced SystemCare 3\Bak

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/01/27 06:44:35 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/08/01 07:36:17 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\glui\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/10/27 18:20:41 | 000,000,079 | —- | M] () – C:\Documents and Settings\glui\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/01/22 14:35:36 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\glui\Desktop\ATF-Cleaner.exe
[2009/07/28 05:39:52 | 003,151,504 | R— | M] () – C:\Documents and Settings\glui\Desktop\ComboFix.exe
[2009/01/22 14:37:58 | 005,953,568 | —- | M] () – C:\Documents and Settings\glui\Desktop\SUPERAntiSpyware.exe
[2010/06/24 09:01:36 | 010,294,820 | —- | M] (Arclab Software Technologies ) – C:\Documents and Settings\glui\Desktop\thumb.exe

< %PROGRAMFILES%\Common Files\*.* >
[2007/01/25 03:52:26 | 000,065,536 | —- | M] () – C:\Program Files\Common Files\NMSAccessU.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-09-20 17:36:35

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8CE646EE

< End of report >

OTL Extras logfile created on: 9/21/2011 7:13:51 AM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Program Files
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.57 Gb Available Physical Memory | 78.94% Memory free
3.33 Gb Paging File | 3.08 Gb Available in Paging File | 92.41% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 27.60 Gb Free Space | 37.04% Space Free | Partition Type: NTFS
Drive G: | 350.00 Gb Total Space | 348.60 Gb Free Space | 99.60% Space Free | Partition Type: NTFS
Drive H: | 150.00 Gb Total Space | 93.26 Gb Free Space | 62.17% Space Free | Partition Type: NTFS
Drive M: | 431.51 Gb Total Space | 419.08 Gb Free Space | 97.12% Space Free | Partition Type: NTFS

Computer Name: LB109-001 | User Name: glui | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Add to archive] – "C:\Program Files\PeaZip\PEAZIP.EXE" "-add2multi" "%1" (Giorgio Tani)
Directory [Browse path with PeaZip] – "C:\Program Files\PeaZip\PEAZIP.EXE" "-ext2browsepath" "%1" (Giorgio Tani)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Generate MD5 Signatures] – "c:\gordon's folder\programs\SHN\mkwACT.exe" (Michael K. Weise)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"56695:TCP" = 56695:TCP:*:Enabled:Pando Media Booster
"56695:UDP" = 56695:UDP:*:Enabled:Pando Media Booster

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Gordon's Folder\Programs\AIM\aim.exe" = C:\Gordon's Folder\Programs\AIM\aim.exe:*:Enabled:AOL Instant Messenger – (America Online, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL Inc.)
"C:\Program Files\Leechftp.exe" = C:\Program Files\Leechftp.exe:*:Enabled:LeechFTP – (jan debis)
"C:\Program Files\Java\jre1.5.0_05\bin\javaw.exe" = C:\Program Files\Java\jre1.5.0_05\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary – (Sun Microsystems, Inc.)
"C:\Program Files\WS_FTP\WS_FTP95.exe" = C:\Program Files\WS_FTP\WS_FTP95.exe:*:Enabled:WS_FTP 95 – (Ipswitch, Inc. 10 Maguire Road. Lexington, MA 02421)
"C:\Documents and Settings\glui\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\glui\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – (Google)
"C:\Documents and Settings\glui\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\glui\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL Inc.)
"X:\Programs\iTunes 10\iTunes.exe" = X:\Programs\iTunes 10\iTunes.exe:*:Enabled:iTunes


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0DD140D3-9563-481E-AA75-BA457CBDAEF2}" = PC Inspector File Recovery
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1CF695D9-EF3F-4E34-BA8F-01D7BE70379E}" = StudioLine Photo Basic 3
"{1DA07BCA-FD11-406E-89A8-5B4496F43FC5}" = EZ Label Xpress Lite
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 23
"{2764CA82-DFB9-4498-AF85-719340BF5305}" = Dell Resource CD
"{29D4D03C-F70B-43d9-82E4-6E5696FB0D1D}" = IObit Toolbar v4.6
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{33EFDAD7-1686-465A-AE0A-26F22E380315}" = Product_Min_QFolder
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{395131D0-71C3-4411-8DDD-84E7A4EC8754}" = Intellisync® for Yahoo!
"{39B975A6-93A3-4C71-9EAD-7BE9F9DF3D22}" = Product_Full_QFolder
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{52A73602-D30A-4CAF-A997-D7171C59637F}" = hppCLJCM1017
"{5396E5FA-91D2-46F0-A95B-D055D8077DD8}" = hppTLBXFXCM1017
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{580E9BBC-A51E-4AE9-A977-7B0939BEDAD3}" = Scanner Utility for Microsoft Windows
"{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1" = PeaZip 3.6.2
"{5DF3D1BB-894E-4DCD-8275-159AC9829B43}" = McAfee VirusScan Enterprise
"{5E3293D4-92BF-439B-B69E-0C0B12488DDE}" = StudioLine Photo Classic 3
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66BDF565-6A07-4407-B9D3-229D41A24B0E}" = hppscanCM1017
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.5
"{6A5925BF-AC13-4A9E-A3E7-D2A6F7FBFFD2}" = hppFonts
"{6CCC133E-9A2F-4CAA-8866-75D029CD3AB3}" = Digital Voice Editor 3
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{78CC3BAB-DE2A-4FB4-8FBB-E4DADDC26747}" = Ad-Aware SE Personal
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7E369B27-13E2-41A5-9879-358EE1C8B5AD}" = Broadcom Gigabit Integrated Controller
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{82705358-3BD6-3CD5-AA9A-B8F058BE3A29}" = Google Talk Plugin
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8C82E5F6-2C76-44CF-A23E-1356A022442E}" = hppIOFiles
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8D8024F1-2945-49A5-9B78-5AB7B11D7942}_is1" = Auslogics Registry Cleaner
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{903B0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Project Professional 2003
"{90510409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Visio Professional 2003
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{93C069D4-2F86-4570-A6DF-BFABBA1E4AFD}" = hpzTLBXFX
"{94056AE8-EF0F-45E4-A1B4-D754115F8A28}" = Numedia CD-DVD writing as non-admin user
"{971F3D40-5145-45D3-A5A2-FAAB5DDF07CA}" = Final Draft 6 Viewer
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{997FE3E4-9394-4EA6-8BD0-D58767ADB0A7}" = Final Draft 6
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A1BC7068-C1BA-410F-8B9A-DB807C803DE2}" = Adobe Creative Suite 5 Design Premium
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6AB9F06-41A7-471A-9C4F-FC95F1129E98}" = hppManualsCM1017
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{AE751709-EA28-4148-96D5-A524BBB08F05}" = hppusgCM1017
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B3A31EEE-7C65-4EE6-BB0D-5549FD2D67B9}" = Ipswitch WS_FTP LE
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B80CC46C-5839-4A48-B051-3CACF23A2718}_is1" = Eraser 5.8
"{BA2D4D22-0B99-4D63-BCEE-D2EA4736F27F}" = LogMeIn
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CA567AD5-33A4-403D-86D1-EE2D38251951}_is1" = VDownloader 0.82
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E31E8CDA-7D26-4ec1-9862-5780AF65DA65}_is1" = GizmoRip version 3.007
"{EEE0E494-7023-45A5-ADA6-CE3144E703BF}" = hppScanTo
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Acrobat 8 Professional" = Adobe Acrobat 8.2.0 Professional
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"AIM_7" = AIM 7
"AnyDVD" = AnyDVD
"AoA Audio Extractor_is1" = AoA Audio Extractor 1.0
"AOL Instant Messenger" = AOL Instant Messenger
"Ashampoo Burning Studio 6 FREE_is1" = Ashampoo Burning Studio 6 FREE
"Aspell English Dictionary_is1" = Aspell English Dictionary-0.50-2
"Audacity_is1" = Audacity 1.2.6
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner (remove only)
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DivX Content Uploader" = DivX Content Uploader
"Duplicate Cleaner_is1" = Duplicate Cleaner 1.4.3
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"FLAC" = FLAC Installer 1.1.3b (remove only)
"GNU Aspell_is1" = GNU Aspell 0.50-3
"GTK 2.0" = GTK+ Runtime 2.12.8 rev a (remove only)
"HDD Health_is1" = HDD Health v3.3 Beta
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Color LaserJet CM1015_CM1017" = HP Color LaserJet CM1015/CM1017 MFP 1.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{1DA07BCA-FD11-406E-89A8-5B4496F43FC5}" = EZ Label Xpress Lite
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"MailWasher Free_is1" = MailWasher Free 6.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mkwACT" = mkw Audio Compression Toolkit
"Mozilla Firefox 6.0.2 (x86 en-US)" = Mozilla Firefox 6.0.2 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Ahead Nero Burning ROM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OmniPageWeb1.0DeinstKey" = OmniPage Web Personal Edition 1.0
"Oracle JInitiator [removed]" = Oracle JInitiator [removed]
"Photo Viewer" = Photo Viewer 2.3
"PhotoScape" = PhotoScape
"POSTERIZA" = POSTERIZA 1.1.1
"RealPlayer 6.0" = RealPlayer
"Software Operation Panel" = Software Operation Panel
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SpywareBlaster_is1" = SpywareBlaster 4.4
"SyncBack_is1" = SyncBack
"Thumb Studio_is1" = Arclab Thumb Studio 2.1
"Treodesktop_is1" = Treodesktop 2.0
"Trillian" = Trillian
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 0.9.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 10/29/2009 12:15:23 PM | Computer Name = LB109-001 | Source = avast! | ID = 33554522
Description =

Error - 10/29/2009 12:15:23 PM | Computer Name = LB109-001 | Source = avast! | ID = 33554522
Description =

Error - 10/29/2009 12:15:23 PM | Computer Name = LB109-001 | Source = avast! | ID = 33554522
Description =

Error - 10/29/2009 12:15:24 PM | Computer Name = LB109-001 | Source = avast! | ID = 33554522
Description =

Error - 10/29/2009 12:15:24 PM | Computer Name = LB109-001 | Source = avast! | ID = 33554522
Description =

Error - 10/29/2009 12:15:24 PM | Computer Name = LB109-001 | Source = avast! | ID = 33554522
Description =

Error - 10/29/2009 12:15:24 PM | Computer Name = LB109-001 | Source = avast! | ID = 33554522
Description =

Error - 10/29/2009 12:15:24 PM | Computer Name = LB109-001 | Source = avast! | ID = 33554522
Description =

Error - 10/29/2009 12:15:25 PM | Computer Name = LB109-001 | Source = avast! | ID = 33554522
Description =

Error - 10/29/2009 12:15:25 PM | Computer Name = LB109-001 | Source = avast! | ID = 33554522
Description =

[ Application Events ]
Error - 9/21/2011 9:11:00 AM | Computer Name = LB109-001 | Source = McLogEvent | ID = 1008
Description = The McShield service terminated unexpectedly. Please review event 5019
or 5051 for details. The McShield service will be restarted in 60 seconds;

Error - 9/21/2011 9:24:48 AM | Computer Name = LB109-001 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 9/21/2011 9:38:47 AM | Computer Name = LB109-001 | Source = NMSAccessU | ID = 0
Description =

Error - 9/21/2011 9:41:42 AM | Computer Name = LB109-001 | Source = McLogEvent | ID = 1008
Description = The McShield service terminated unexpectedly. Please review event 5019
or 5051 for details. The McShield service will be restarted in 5 seconds;

Error - 9/21/2011 9:57:36 AM | Computer Name = LB109-001 | Source = NMSAccessU | ID = 0
Description =

Error - 9/21/2011 10:00:23 AM | Computer Name = LB109-001 | Source = McLogEvent | ID = 1008
Description = The McShield service terminated unexpectedly. Please review event 5019
or 5051 for details. The McShield service will be restarted in 5 seconds;

Error - 9/21/2011 10:03:24 AM | Computer Name = LB109-001 | Source = McLogEvent | ID = 1008
Description = The McShield service terminated unexpectedly. Please review event 5019
or 5051 for details. The McShield service will be restarted in 10 seconds;

Error - 9/21/2011 10:03:47 AM | Computer Name = LB109-001 | Source = McLogEvent | ID = 5019
Description = Exception in McShield.Exe! Exception details follow : Build Aug 20
2004 04:46:11 Init 100: Crash address 0x7c812afb Code 0xc06d007e Flags 0x00000000

1 Parameters : 0x0099e5ac 0x0001003f

Error - 9/21/2011 10:03:48 AM | Computer Name = LB109-001 | Source = McLogEvent | ID = 5019
Description = Exception in McShield.Exe! Exception details follow : Build Aug 20
2004 04:46:11 Init 100: Crash address 0x7c812afb Code 0xc06d007e Flags 0x00000000

1 Parameters : 0x0099dc84 0x0001003f

Error - 9/21/2011 10:09:28 AM | Computer Name = LB109-001 | Source = MsiInstaller | ID = 1008
Description = The installation of C:\Program Files\HiJackThis.msi is not permitted
due to an error in software restriction policy processing. The object cannot be
trusted.

[ System Events ]
Error - 9/21/2011 9:46:08 AM | Computer Name = LB109-001 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 9/21/2011 9:47:11 AM | Computer Name = LB109-001 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 aswSnx aswSP aswTdi ElbyCDIO Fips intelppm pavboot SASDIFSV SASKUTIL

Error - 9/21/2011 9:56:39 AM | Computer Name = LB109-001 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 9/21/2011 9:57:38 AM | Computer Name = LB109-001 | Source = Service Control Manager | ID = 7023
Description = The NMSAccessU service terminated with the following error: %%231

Error - 9/21/2011 10:00:23 AM | Computer Name = LB109-001 | Source = Service Control Manager | ID = 7034
Description = The Network Associates McShield service terminated unexpectedly.
It has done this 1 time(s).

Error - 9/21/2011 10:03:23 AM | Computer Name = LB109-001 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.

Error - 9/21/2011 10:03:23 AM | Computer Name = LB109-001 | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053

Error - 9/21/2011 10:03:24 AM | Computer Name = LB109-001 | Source = Service Control Manager | ID = 7034
Description = The Network Associates McShield service terminated unexpectedly.
It has done this 2 time(s).

Error - 9/21/2011 10:06:41 AM | Computer Name = LB109-001 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 9/21/2011 10:07:26 AM | Computer Name = LB109-001 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 aswSnx aswSP aswTdi ElbyCDIO Fips intelppm pavboot SASDIFSV SASKUTIL


< End of report >





Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:10:03 AM, on 9/21/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17099)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\Explorer.EXE
C:\Gordon's Folder\Programs\CCleaner\ccleaner.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://glendale.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.glendale.edu/index.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: IObit Toolbar - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.6\iobitToolbarIE.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IObit Toolbar - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.6\iobitToolbarIE.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: IObit Toolbar - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.6\iobitToolbarIE.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HPUsageTracking] "C:\Program Files\HP\HP UT\bin\hppusg.exe" "C:\Program Files\HP\HP UT\"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [FtLnSOP_setup] C:\WINDOWS\Twain_32\Fjscan32\SOP\FtLnSOP.exe
O4 - HKLM\..\Run: [FJTWAIN Setup] C:\WINDOWS\Twain_32\fjscan32\FjtwSetup.exe /Station
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "X:\Programs\iTunes 10\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [HDDHealth] E:\May 11, 2008\Programs\HDD Health\HDDHealth.exe -wl
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\glui\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Advanced SystemCare 4] "C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: MagicDisc.lnk = H:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Gordon's Folder\Programs\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {332bd5a0-8000-11d7-b657-00c04faedb18} (Oracle JInitiator 1.1.8.22) -
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/49.12/uploader2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1130463694843
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1156470157703
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\StudioLine Photo Basic\NMSAccess32.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\Common Files\NMSAccessU.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 13700 bytes


.
DDS (Ver_11-03-05.01) - NTFSx86 NETWORK
Run by [removed] at 7:26:05.35 on Wed 09/21/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1604 [GMT -7:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://glendale.edu/
uInternet Connection Wizard,ShellNext = hxxp://www.glendale.edu/index.html
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\4.6\iobitToolbarIE.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\4.6\iobitToolbarIE.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\4.6\iobitToolbarIE.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [HDDHealth] e:\may 11, 2008\programs\hdd health\HDDHealth.exe -wl
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
uRun: [Google Update] "c:\documents and settings\glui\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Advanced SystemCare 4] "c:\program files\iobit\advanced systemcare 4\ASCTray.exe"
mRun: [ShStatEXE] "c:\program files\network associates\virusscan\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\network associates\common framework\UpdaterUI.exe" /StartedFromRunKey
mRun: [Network Associates Error Reporting Service] "c:\program files\common files\network associates\talkback\TBMon.exe"
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ToolBoxFX] "c:\program files\hp\toolboxfx\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HPUsageTracking] "c:\program files\hp\hp ut\bin\hppusg.exe" "c:\program files\hp\hp ut\"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [FtLnSOP_setup] c:\windows\twain_32\fjscan32\sop\FtLnSOP.exe
mRun: [FJTWAIN Setup] c:\windows\twain_32\fjscan32\FjtwSetup.exe /Station
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [avast5] c:\progra~1\avast5\avastUI.exe /nogui
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "x:\programs\itunes 10\iTunesHelper.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\glui\startm~1\programs\startup\magicd~1.lnk - h:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\gordon's folder\programs\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: glendale.edu\gccss
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {332bd5a0-8000-11d7-b657-00c04faedb18}
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/49.12/uploader2.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1130463694843
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156470157703
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - hxxp://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\glui\applic~1\mozilla\firefox\profiles\js8gb5gg.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=685749&p;=
FF - plugin: c:\documents and settings\glui\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\glui\application data\move networks\plugins\npqmp071505000011.dll
FF - plugin: c:\documents and settings\glui\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\glui\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\glui\local settings\application data\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\gordon's folder\programs\divx content uploader\npUpload.dll
FF - plugin: c:\gordon's folder\programs\divx player\npDivxPlayerPlugin.dll
FF - plugin: c:\gordon's folder\programs\divx web player\npdivx32.dll
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
.
—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
============= SERVICES / DRIVERS ===============
.
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2005-10-27 58016]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-8-31 116608]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-8-5 28552]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-9-20 442200]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-5-19 320856]
S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-1-15 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-1-15 67664]
S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-9-20 328536]
S2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2011-8-17 402328]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-19 20568]
S2 avast! Antivirus;avast! Antivirus;c:\program files\avast5\AvastSvc.exe [2010-8-31 44768]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2010-10-11 374152]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2007-6-4 12856]
S2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2007-6-4 47640]
S2 McAfeeFramework;McAfee Framework Service;c:\program files\network associates\common framework\FrameworkService.exe [2005-10-27 102463]
S2 McShield;Network Associates McShield;c:\program files\network associates\virusscan\Mcshield.exe [2004-8-18 221191]
S2 McTaskManager;Network Associates Task Manager;c:\program files\network associates\virusscan\VsTskMgr.exe [2004-8-18 28672]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-6-29 24652]
S3 NaiAvFilter1;NaiAvFilter1;c:\windows\system32\drivers\naiavf5x.sys [2005-10-27 108256]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-1-15 12872]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
=============== Created Last 30 ================
.
2011-09-21 14:14:22 625664 —-a-w- c:\program files\dds.scr
2011-09-21 14:12:26 582656 —-a-w- c:\program files\OTL.exe
2011-09-21 14:09:41 388608 —-a-w- c:\program files\HijackThis.exe
2011-09-21 14:09:25 1402880 —-a-w- c:\program files\HiJackThis.msi
2011-09-21 13:54:20 ——– d—–w- c:\docume~1\glui\applic~1\Auslogics
2011-09-21 13:50:20 ——– d—–w- c:\program files\Auslogics
2011-09-21 13:49:49 454120 —-a-w- c:\program files\cnet_registry-cleaner-setup_exe.exe
2011-09-20 21:01:56 ——– d—–w- c:\docume~1\glui\applic~1\Search Settings
2011-09-20 21:01:47 ——– d—–w- c:\program files\IObit Toolbar
2011-09-20 21:01:47 ——– d—–w- c:\program files\Application Updater
2011-09-20 21:00:52 ——– d—–w- c:\program files\IObit
2011-09-20 18:14:08 233 —-a-w- C:\Start_.cmd
2011-09-20 18:13:47 389120 —-a-w- c:\windows\system32\CF13264.exe
2011-09-20 18:11:19 389120 —-a-w- c:\windows\system32\cmd.execf
2011-09-20 16:37:22 3194296 —-a-w- c:\program files\spywareblastersetup44.exe
2011-09-20 16:34:46 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-09-20 16:34:46 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2011-09-20 16:33:56 16409960 —-a-w- c:\program files\spybotsd162.exe
2011-09-20 14:06:11 442200 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-09-20 09:24:31 7152464 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\windows defender\definition updates\{a5b8da16-27f9-4cfc-a31c-d8b289b4e2e7}\mpengine.dll
2011-09-19 14:24:20 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-09-19 14:24:17 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll
2011-09-19 14:24:17 785368 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-09-19 14:24:17 478168 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-09-19 14:24:17 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2011-09-19 14:24:17 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll
2011-09-19 14:24:17 1846232 —-a-w- c:\program files\mozilla firefox\mozjs.dll
2011-09-19 14:24:17 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-09-19 14:23:27 13983976 —-a-w- c:\program files\Firefox Setup 6.0.2.exe
2011-08-23 13:01:01 40960 -c—-w- c:\windows\system32\dllcache\ndproxy.sys
2011-08-23 13:00:04 139656 -c—-w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-23 12:59:59 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-08-23 12:58:06 10496 -c—-w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-23 12:57:57 45568 -c—-w- c:\windows\system32\dllcache\wab.exe
.
==================== Find3M ====================
.
2011-09-20 21:00:24 30071680 —-a-w- c:\program files\asc-setup.exe
2011-09-08 12:45:13 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-06 20:45:29 41184 —-a-w- c:\windows\avastSS.scr
2011-07-15 21:16:12 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-07-15 21:16:11 87424 —-a-w- c:\windows\system32\LMIinit.dll
2011-07-15 21:16:11 53632 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2011-07-15 21:16:11 29568 —-a-w- c:\windows\system32\LMIport.dll
2010-09-08 17:34:47 7302104 —-a-w- c:\program files\Install_AIM.exe
2010-06-21 15:55:08 17327195 —-a-w- c:\program files\PhotoScapeSetup_V3.5.exe
2010-06-17 16:01:30 79666688 —-a-w- c:\program files\StudioLine_PC3.msi
2010-06-17 15:23:22 68657152 —-a-w- c:\program files\StudioLine_PB3.msi
2010-04-30 14:46:26 25146224 —-a-w- c:\program files\Ft9i5uX5s.exe
2010-04-30 12:36:25 39714912 —-a-w- c:\program files\isis_050901.exe
2010-02-01 14:23:32 5395536 —-a-w- c:\program files\SetupAnyDVD6609.exe
2010-01-21 13:16:25 8087352 —-a-w- c:\program files\Firefox Setup 3.5.7.exe
2009-12-03 12:57:42 6008376 —-a-w- c:\program files\ashampoo_burning_studio_6_free_676_4280.exe
2009-10-26 11:47:34 714528 —-a-w- c:\program files\jre-6u16-windows-i586-iftw.exe
2009-10-19 14:42:23 3012768 —-a-w- c:\program files\spywareblastersetup42.exe
2009-10-19 14:39:18 5154304 —-a-w- c:\program files\WindowsDefender.msi
2009-10-01 19:10:19 1853922 —-a-w- c:\program files\DuplicateCleaner.exe
2009-09-17 13:20:54 8416452 —-a-w- c:\program files\audioextractor.exe
2009-09-17 12:51:35 714528 —-a-w- c:\program files\JavaSetup6u16.exe
2009-06-29 17:35:09 13906808 —-a-w- c:\program files\aim65111.exe
2009-06-29 17:32:47 415380 —-a-w- c:\program files\aim6.8.14.6.exe
2009-04-24 12:18:54 1987853 —-a-w- c:\program files\wsftp6.exe
2008-08-11 21:26:23 710382 —-a-w- c:\program files\OutlookPH.exe
2008-02-13 13:55:25 6734904 —-a-w- c:\program files\DVDFabPlatinum4062_avangate-689.exe
2007-07-10 13:37:15 28868320 —-a-w- c:\program files\FileFormatConverters.exe
2007-01-25 10:52:26 65536 —-a-w- c:\program files\common files\NMSAccessU.exe
1999-04-17 04:40:50 828416 —-a-w- c:\program files\Leechftp.exe
.
============= FINISH: 7:31:48.00 ===============

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, greyspace

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

—————————————————————————————————

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


—————————————————————————————————

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI