This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE has reset your search provider- but actually hasn't

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Friends asked me to install XP service pack 3 on their computer which I did. I can't get rid of a stubborn message that gets in the way every time I open IE8. It tells me a program has corrupted my original search provider and it has been reset to Live Search. Actually, Bing is stuck as the provide and I can't select Google is my default or delete Bing. I tried resetting all IE settings but that didn't help. I couldn't run dds in any of its forms to post, so I wonder if there is malware on the computer. Malware Bytes and Trend Micro show it to be totally clean. I would really appreciate your help. Ms Magoo

Here are my OTL scans:

OTL Extras logfile created on: 10/31/2011 3:08:33 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Randy\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.44 Gb Available Physical Memory | 72.48% Memory free
2.58 Gb Paging File | 2.19 Gb Available in Paging File | 85.05% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

OTL logfile created on: 10/31/2011 3:08:33 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Randy\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.44 Gb Available Physical Memory | 72.48% Memory free
2.58 Gb Paging File | 2.19 Gb Available in Paging File | 85.05% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.74 Gb Total Space | 0.57 Gb Free Space | 1.48% Space Free | Partition Type: NTFS
Drive D: | 12.00 Gb Total Space | 11.87 Gb Free Space | 98.89% Space Free | Partition Type: NTFS

Computer Name: INSPIRON6400 | User Name: Randy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Randy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
PRC - C:\Program Files\Lexmark 3600-4600 Series\lxdxmsdmon.exe ()
PRC - C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\lxdxcoms.exe ( )
PRC - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE (Logitech Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\Program Files\Trend Micro\Internet Security\UfPack.dll ()
MOD - C:\Program Files\Trend Micro\Internet Security\sqlite3.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxmsdmon.exe ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxcaps.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxscw.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxdrs.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\lxdxcnv4.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdxdrpp.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdxdatr.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdxcats.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\app4r.monitor.core.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\app4r.monitor.common.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\app4r.devmons.mcmdevmon.dll ()
MOD - C:\Program Files\Lexmark 3600-4600 Series\app4r.devmons.mcmdevmon.autoplayutil.dll ()
MOD - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEDialogs.dll ()
MOD - C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL\Program\clntutil.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (TmProxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (lxdx_device) – C:\WINDOWS\System32\lxdxcoms.exe ( )
SRV - (lxdxCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdxserv.exe ()
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)


========== Driver Services (SafeList) ==========

DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (tmactmon) – C:\WINDOWS\system32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmevtmgr) – C:\WINDOWS\system32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (Tcpip6) – C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTSERIAL) – C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTSLBCSP) – C:\WINDOWS\system32\drivers\btslbcsp.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (LHidKe) – C:\WINDOWS\system32\drivers\LHidKE.Sys (Logitech, Inc.)
DRV - (LMouKE) – C:\WINDOWS\system32\drivers\LMouKE.Sys (Logitech, Inc.)
DRV - (LHidUsbK) – C:\WINDOWS\system32\drivers\LHidUsbK.sys (Logitech, Inc.)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (U2SP) OEM USB to Serial Converter Driver(Philips) – C:\WINDOWS\system32\drivers\u2s2kxp.sys (Magic Control Technology Corp.)
DRV - (sonypvf2) – C:\WINDOWS\System32\drivers\sonypvf2.sys (Sony Corporation)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (sonypvt2) – C:\WINDOWS\System32\drivers\sonypvt2.sys (Sony Corporation)
DRV - (sonypvl2) – C:\WINDOWS\System32\drivers\sonypvl2.sys (Sony Corporation)
DRV - (sonypvd2) – C:\WINDOWS\system32\drivers\sonypvd2.sys (Sony Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: C:\Documents and Settings\Randy\Application Data\nprhapengine.dll File not found



O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup File not found
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe (HP)
O4 - HKLM..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless File not found
O4 - HKLM..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" File not found
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [lxdxamon] C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe ()
O4 - HKLM..\Run: [lxdxmon.exe] C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" File not found
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER File not found
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\Randy\Start Menu\Programs\StartUp\MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe (Smith Micro Software, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Send To &Bluetooth; - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: nissan.biz ([webmail.na] https in Trusted sites)
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} http://www.logitech.com/devicedetector/plu…Detection32.cab (Device Detection)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1319933713281 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7D3CA141-D7F0-4243-9225-34A0C0366740}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Randy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Randy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{aa572124-fee8-11dd-b8d0-001638bf42ad}\Shell - "" = AutoRun
O33 - MountPoints2\{aa572124-fee8-11dd-b8d0-001638bf42ad}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{aa572124-fee8-11dd-b8d0-001638bf42ad}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{f133b8fe-c83d-11dc-b862-0013029902ae}\Shell\AutoRun\command - "" = F:\Autorun.exe /run
O33 - MountPoints2\{f133b8fe-c83d-11dc-b862-0013029902ae}\Shell\Shell00\Command - "" = F:\Autorun.exe /run
O33 - MountPoints2\{f133b8fe-c83d-11dc-b862-0013029902ae}\Shell\Shell01\Command - "" = F:\Autorun.exe /action
O33 - MountPoints2\{f133b8fe-c83d-11dc-b862-0013029902ae}\Shell\Shell02\Command - "" = F:\Autorun.exe /uninstall
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/10/31 15:07:17 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Randy\Desktop\OTL.exe
[2011/10/30 23:37:40 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\Randy\Desktop\dds1.scr
[2011/10/30 21:44:28 | 000,954,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40.dll
[2011/10/30 21:44:28 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2011/10/30 21:01:54 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/10/30 20:15:30 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2011/10/30 20:13:33 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/10/30 20:09:03 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/10/30 20:07:12 | 000,105,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mup.sys
[2011/10/30 19:58:56 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/10/30 19:57:15 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2011/10/30 12:56:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Randy\Desktop\computer stuff
[2011/10/30 12:55:44 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Randy\Desktop\HiJackThis.exe
[2011/10/29 22:45:19 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2011/10/29 22:45:13 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2011/10/29 22:45:00 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2011/10/29 22:44:16 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2011/10/29 22:44:16 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2011/10/29 22:44:16 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2011/10/29 22:44:16 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2011/10/29 22:44:16 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2011/10/29 22:44:16 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2011/10/29 21:18:40 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2011/10/29 21:17:52 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2011/10/29 21:05:27 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/10/29 20:48:29 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2011/10/29 20:41:28 | 001,372,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2011/10/29 20:41:28 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml6r.dll
[2011/10/29 20:41:28 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2011/10/29 20:41:23 | 001,888,992 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3duag.dll
[2011/10/29 20:41:23 | 000,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3d1ag.dll
[2011/10/29 20:41:23 | 000,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvaa.dll
[2011/10/29 20:41:23 | 000,229,376 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2cqag.dll
[2011/10/29 20:41:23 | 000,201,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvag.dll
[2011/10/29 20:41:23 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2011/10/29 20:41:23 | 000,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativmvxx.ax
[2011/10/29 20:41:23 | 000,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativdaxx.ax
[2011/10/29 20:41:22 | 000,516,768 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ativvaxx.dll
[2011/10/29 20:41:22 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2011/10/29 20:41:22 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2011/10/29 20:41:22 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2011/10/29 20:41:22 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2011/10/29 20:41:22 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2011/10/29 20:41:22 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2011/10/29 20:41:22 | 000,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativtmxx.dll
[2011/10/29 20:41:22 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2011/10/29 20:41:21 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2011/10/29 20:41:21 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2011/10/29 20:41:21 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2011/10/29 20:41:21 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2011/10/29 20:41:21 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2011/10/29 20:41:21 | 000,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\hsfcisp2.dll
[2011/10/29 20:41:20 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ieencode.dll
[2011/10/29 20:41:20 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2011/10/29 20:41:20 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2011/10/29 20:41:20 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2011/10/29 20:41:19 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2011/10/29 20:41:19 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2011/10/29 20:41:19 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2011/10/29 20:41:19 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2011/10/29 20:41:19 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2011/10/29 20:41:19 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2011/10/29 20:41:18 | 001,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\mtxparhd.dll
[2011/10/29 20:41:18 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2011/10/29 20:41:18 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2011/10/29 20:41:18 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2011/10/29 20:41:18 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2011/10/29 20:41:18 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2011/10/29 20:41:17 | 000,412,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\photometadatahandler.dll
[2011/10/29 20:41:17 | 000,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\s3gnb.dll
[2011/10/29 20:41:17 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2011/10/29 20:41:17 | 000,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\slextspk.dll
[2011/10/29 20:41:17 | 000,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\slgen.dll
[2011/10/29 20:41:17 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2011/10/29 20:41:17 | 000,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\slcoinst.dll
[2011/10/29 20:41:17 | 000,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\slserv.exe
[2011/10/29 20:41:17 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2011/10/29 20:41:17 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\slrundll.exe
[2011/10/29 20:41:17 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2011/10/29 20:41:16 | 000,346,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\windowscodecsext.dll
[2011/10/29 20:41:16 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2011/10/29 20:41:16 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vidcap.ax
[2011/10/29 20:41:15 | 000,276,992 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmphoto.dll
[2011/10/29 20:41:15 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2011/10/29 20:41:11 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\slrundll.exe
[2011/10/29 20:41:08 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2011/10/29 20:41:07 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2011/10/29 20:41:05 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2011/10/29 20:41:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/10/29 20:32:53 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2011/10/29 20:28:00 | 000,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv01nt5.dll
[2011/10/29 20:28:00 | 000,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv02nt5.dll
[2011/10/29 20:28:00 | 000,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv11nt5.dll
[2011/10/29 20:28:00 | 000,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv09nt5.dll
[2011/10/29 20:28:00 | 000,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv07nt5.dll
[2011/10/29 20:28:00 | 000,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv05nt5.dll
[2011/10/29 20:28:00 | 000,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv08nt5.dll
[2011/10/29 20:27:59 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2011/10/29 20:27:59 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2011/10/29 20:27:59 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2011/10/29 20:27:59 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2011/10/29 20:27:59 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2011/10/29 20:27:59 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2011/10/29 20:27:59 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2011/10/29 20:27:59 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2011/10/29 20:27:59 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2011/10/29 20:27:59 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2011/10/29 20:27:58 | 000,701,440 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtag.sys
[2011/10/29 20:27:58 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2011/10/29 20:27:58 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinrvxx.sys
[2011/10/29 20:27:58 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atintuxx.sys
[2011/10/29 20:27:58 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinbtxx.sys
[2011/10/29 20:27:58 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinraxx.sys
[2011/10/29 20:27:58 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinsnxx.sys
[2011/10/29 20:27:58 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinpdxx.sys
[2011/10/29 20:27:58 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinttxx.sys
[2011/10/29 20:27:58 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinmdxx.sys
[2011/10/29 20:27:57 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxsxx.sys
[2011/10/29 20:27:57 | 000,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2011/10/29 20:27:57 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxbxx.sys
[2011/10/29 20:27:57 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv04nt5.dll
[2011/10/29 20:27:57 | 000,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv01nt5.dll
[2011/10/29 20:27:57 | 000,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv10nt5.dll
[2011/10/29 20:27:57 | 000,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2011/10/29 20:27:57 | 000,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv06nt5.dll
[2011/10/29 20:27:57 | 000,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv02nt5.dll
[2011/10/29 20:27:55 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2011/10/29 20:27:54 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2011/10/29 20:27:54 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\drivers\mtxparhm.sys
[2011/10/29 20:27:54 | 000,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2011/10/29 20:27:53 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2011/10/29 20:27:53 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\drivers\s3gnbm.sys
[2011/10/29 20:27:53 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2011/10/29 20:27:52 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnt7554.sys
[2011/10/29 20:27:52 | 000,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\siint5.dll
[2011/10/29 20:27:51 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slntamr.sys
[2011/10/29 20:27:51 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnthal.sys
[2011/10/29 20:27:51 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slwdmsup.sys
[2011/10/29 20:27:51 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2011/10/29 20:27:50 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2011/10/29 20:27:50 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2011/10/29 20:27:50 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2011/10/29 20:27:50 | 000,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\vchnt5.dll
[2011/10/29 20:27:50 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2011/10/29 20:27:49 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2011/10/29 20:27:49 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2011/10/29 20:21:50 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2011/10/29 20:21:47 | 000,000,000 | —D | C] – C:\WINDOWS\EHome
[2011/10/29 20:09:06 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srv.sys
[2011/10/29 20:06:12 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2011/10/29 20:05:00 | 000,456,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2011/10/29 20:04:17 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\t2embed.dll
[2011/10/29 20:04:17 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fontsub.dll
[2011/10/29 20:04:15 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2011/10/29 20:02:25 | 000,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2011/10/29 20:02:15 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2011/10/29 20:01:32 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2011/10/29 19:57:14 | 002,148,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2011/10/29 19:57:13 | 002,192,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2011/10/29 19:57:12 | 002,027,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2011/10/29 19:50:16 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\netapi32.dll
[2011/10/29 19:50:10 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml3.dll
[2011/10/29 16:27:20 | 000,163,408 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/10/29 16:27:20 | 000,059,472 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmactmon.sys
[2011/10/29 16:27:20 | 000,051,792 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2011/10/29 16:26:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Trend Micro Internet Security
[2011/10/29 16:26:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Trend Micro
[2011/10/29 16:23:12 | 000,661,808 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\UfWSC.cpl
[2011/10/29 16:23:07 | 001,405,720 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\vsapint.sys
[2011/10/29 16:23:06 | 000,339,984 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\TM_CFW.sys
[2011/10/29 16:23:06 | 000,262,416 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmxpflt.sys
[2011/10/29 16:23:06 | 000,089,872 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmtdi.sys
[2011/10/29 16:23:06 | 000,036,624 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmpreflt.sys
[2011/10/29 16:13:39 | 000,000,000 | —D | C] – C:\Program Files\Downloads
[2011/10/29 15:27:11 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Randy\Desktop\ATF-Cleaner.exe
[2011/10/29 15:17:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Randy\Application Data\Malwarebytes
[2011/10/29 15:16:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/29 15:16:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/10/29 15:16:42 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/10/29 15:16:42 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/10 09:34:57 | 000,438,272 | —- | C] ( ) – C:\WINDOWS\System32\LXDXhcp.dll
[2009/03/10 09:34:56 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxdxinpa.dll
[2009/03/10 09:34:56 | 000,339,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdxiesc.dll
[2009/03/10 09:34:55 | 000,843,776 | —- | C] ( ) – C:\WINDOWS\System32\lxdxusb1.dll
[2009/03/10 09:34:54 | 001,105,920 | —- | C] ( ) – C:\WINDOWS\System32\lxdxserv.dll
[2009/03/10 09:34:53 | 000,647,168 | —- | C] ( ) – C:\WINDOWS\System32\lxdxpmui.dll
[2009/03/10 09:34:53 | 000,569,344 | —- | C] ( ) – C:\WINDOWS\System32\lxdxlmpm.dll
[2009/03/10 09:34:53 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\lxdxprox.dll
[2009/03/10 09:34:51 | 000,663,552 | —- | C] ( ) – C:\WINDOWS\System32\lxdxhbn3.dll
[2009/03/10 09:34:51 | 000,320,168 | —- | C] ( ) – C:\WINDOWS\System32\lxdxih.exe
[2009/03/10 09:34:48 | 000,594,600 | —- | C] ( ) – C:\WINDOWS\System32\lxdxcoms.exe
[2009/03/10 09:34:48 | 000,376,832 | —- | C] ( ) – C:\WINDOWS\System32\lxdxcomm.dll
[2009/03/10 09:34:47 | 000,851,968 | —- | C] ( ) – C:\WINDOWS\System32\lxdxcomc.dll
[2009/03/10 09:34:47 | 000,365,224 | —- | C] ( ) – C:\WINDOWS\System32\lxdxcfg.exe
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/31 15:07:24 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Randy\Desktop\OTL.exe
[2011/10/31 15:02:53 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/31 14:59:21 | 2137,456,640 | -HS- | M] () – C:\hiberfil.sys
[2011/10/31 14:59:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/30 23:39:35 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\Randy\Desktop\dds1.scr
[2011/10/30 22:13:09 | 000,446,124 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/10/30 22:13:09 | 000,073,164 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/10/30 22:06:59 | 000,368,896 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/30 21:57:32 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/10/30 20:56:49 | 000,002,495 | —- | M] () – C:\Documents and Settings\Randy\Desktop\Microsoft Office Excel 2003.lnk
[2011/10/30 12:58:22 | 000,000,104 | —- | M] () – C:\Documents and Settings\Randy\Desktop\Internet.lnk
[2011/10/30 12:55:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Randy\Desktop\HiJackThis.exe
[2011/10/29 20:27:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/10/29 16:26:27 | 000,001,703 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Trend Micro Internet Security.lnk
[2011/10/29 16:23:12 | 000,661,808 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\UfWSC.cpl
[2011/10/29 16:23:06 | 000,339,984 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\TM_CFW.sys
[2011/10/29 16:23:06 | 000,089,872 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmtdi.sys
[2011/10/29 15:16:46 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/13 22:16:20 | 000,000,812 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2011/10/03 03:35:11 | 005,971,456 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/30 23:30:39 | 2137,456,640 | -HS- | C] () – C:\hiberfil.sys
[2011/10/30 12:58:22 | 000,000,104 | —- | C] () – C:\Documents and Settings\Randy\Desktop\Internet.lnk
[2011/10/29 20:27:57 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2011/10/29 20:27:57 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2011/10/29 20:27:54 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2011/10/29 16:26:27 | 000,001,703 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Trend Micro Internet Security.lnk
[2011/10/29 15:16:46 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/10 09:45:13 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxdxvs.dll
[2009/03/10 09:45:11 | 000,360,448 | —- | C] () – C:\WINDOWS\System32\lxdxcoin.dll
[2009/03/10 09:44:19 | 000,782,336 | —- | C] () – C:\WINDOWS\System32\lxdxdrs.dll
[2009/03/10 09:44:19 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\lxdxcaps.dll
[2009/03/10 09:44:18 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\lxdxcnv4.dll
[2009/03/10 09:35:24 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\lxdxrwrd.ini
[2009/03/10 09:34:58 | 000,348,160 | —- | C] () – C:\WINDOWS\System32\LXDXinst.dll
[2009/03/10 09:34:50 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxdxgrd.dll
[2009/02/01 17:11:42 | 000,001,255 | -H– | C] () – C:\Documents and Settings\Randy\Application Data\hpothb07.tif
[2009/02/01 17:11:42 | 000,000,899 | -H– | C] () – C:\Documents and Settings\Randy\Application Data\hpothb07.dat
[2008/12/17 22:16:54 | 000,000,734 | —- | C] () – C:\WINDOWS\PSTUDIO.INI
[2008/12/12 07:24:28 | 000,000,488 | —- | C] () – C:\WINDOWS\ULead32.ini
[2008/12/11 21:44:19 | 000,000,072 | —- | C] () – C:\WINDOWS\Pex.INI
[2008/08/21 19:41:31 | 000,000,000 | —- | C] () – C:\WINDOWS\CompanionApp.INI
[2008/08/21 19:40:51 | 000,002,508 | —- | C] () – C:\Documents and Settings\Randy\Application Data\$_hpcst$.hpc
[2008/05/23 14:39:45 | 000,215,144 | R— | C] () – C:\WINDOWS\patchw32.dll
[2008/05/23 14:38:42 | 000,215,144 | R— | C] () – C:\WINDOWS\pw32a.dll
[2008/03/27 19:23:26 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\VZWDLManager.dll
[2008/03/15 22:05:56 | 000,005,632 | —- | C] () – C:\Documents and Settings\Randy\Application Data\DMX.bmk
[2008/03/14 12:40:32 | 000,000,237 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/03/13 08:39:46 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/03/12 12:08:33 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Randy.ini
[2008/02/11 22:49:48 | 000,000,287 | —- | C] () – C:\WINDOWS\hpqcopy.INI
[2007/04/14 08:06:06 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2007/04/11 19:46:01 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/30 19:22:28 | 000,000,042 | —- | C] () – C:\WINDOWS\TSMLite.ini
[2007/03/11 11:44:23 | 000,000,302 | —- | C] () – C:\WINDOWS\System32\gmsblist.dll
[2007/01/22 19:47:31 | 000,007,812 | —- | C] () – C:\WINDOWS\System32\visorusb.dll
[2007/01/02 09:07:40 | 000,000,233 | —- | C] () – C:\WINDOWS\qwimp.ini
[2007/01/02 09:06:56 | 000,000,022 | —- | C] () – C:\WINDOWS\INTUPREM.DAT
[2007/01/02 09:01:40 | 000,000,812 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2007/01/02 09:01:40 | 000,000,431 | —- | C] () – C:\WINDOWS\intuprof.ini
[2007/01/01 23:07:44 | 000,061,678 | —- | C] () – C:\Documents and Settings\Randy\Application Data\PFP120JPR.{PB
[2007/01/01 23:07:44 | 000,012,358 | —- | C] () – C:\Documents and Settings\Randy\Application Data\PFP120JCM.{PB
[2007/01/01 13:01:00 | 000,001,785 | —- | C] () – C:\WINDOWS\VIEWER.INI
[2007/01/01 13:00:51 | 000,000,232 | —- | C] () – C:\WINDOWS\BTW.INI
[2007/01/01 09:30:31 | 000,038,452 | —- | C] () – C:\Documents and Settings\Randy\Application Data\Microsoft Excel.ADR
[2006/09/18 21:52:16 | 000,000,056 | RHS- | C] () – C:\WINDOWS\System32\E94A951F03.sys
[2006/07/14 08:47:26 | 000,000,050 | —- | C] () – C:\WINDOWS\System32\gr6rlzay.dll
[2006/07/03 19:51:12 | 000,118,784 | R— | C] () – C:\WINDOWS\bwUnin-7.2.0.157-8876480SL.exe
[2006/07/03 18:56:54 | 000,000,420 | —- | C] () – C:\WINDOWS\PCPHOTO.INI
[2006/06/18 11:52:00 | 000,165,376 | —- | C] () – C:\Documents and Settings\Randy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/06/18 10:30:49 | 000,118,784 | R— | C] () – C:\WINDOWS\bwUnin-7.2.0.137-8876480SL.exe
[2006/06/17 10:32:57 | 000,004,184 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/06/17 10:32:57 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\031F954AE9.sys
[2006/06/16 09:35:49 | 000,000,128 | —- | C] () – C:\Documents and Settings\Randy\Local Settings\Application Data\fusioncache.dat
[2006/06/16 09:10:36 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/06/16 08:18:44 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/06/07 19:33:22 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/07 19:26:13 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/06/07 19:24:20 | 000,712,704 | —- | C] () – C:\WINDOWS\System32\DellSystemRestore.dll
[2006/06/07 19:20:15 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/06/07 19:16:17 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/06/07 19:10:24 | 000,000,004 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/06/07 18:43:20 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/06/07 18:43:11 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2006/06/07 18:41:50 | 000,000,391 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/07/07 16:07:58 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2004/08/10 13:12:05 | 000,000,890 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 13:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 12:57:15 | 000,368,896 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 12:51:35 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/08/10 12:51:35 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/10 12:51:35 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/08/10 12:51:35 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/10 12:51:35 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/08/10 12:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 12:51:20 | 000,446,124 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 12:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 12:51:20 | 000,073,164 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 12:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 12:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 12:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 12:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 12:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 12:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 12:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 12:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2009/07/27 17:21:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2008/12/10 17:40:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/19 14:26:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2010/01/30 15:48:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/02/04 17:24:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Randy\Application Data\Ceedo
[2008/09/25 20:33:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Randy\Application Data\GARMIN
[2008/03/14 10:15:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Randy\Application Data\Leadertech
[2009/09/01 17:29:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Randy\Application Data\Lexmark Productivity Studio
[2009/07/27 17:19:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Randy\Application Data\NCH Swift Sound
[2008/12/12 07:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Randy\Application Data\Ulead Systems

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/08/20 09:14:36 | 000,000,212 | RHS- | M] () – C:\boot.ini
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/06/07 18:50:58 | 000,005,843 | RH– | M] () – C:\dell.sdr
[2011/10/31 14:59:21 | 2137,456,640 | -HS- | M] () – C:\hiberfil.sys
[2009/03/09 12:24:17 | 000,173,022 | —- | M] () – C:\hpfr5550.log
[2006/06/18 10:23:08 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/06/07 19:18:00 | 000,000,823 | -H– | M] () – C:\IPH.PH
[2007/12/26 14:51:57 | 000,005,201 | —- | M] () – C:\logfile
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/10/29 20:27:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/10/31 14:59:19 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2008/06/13 06:14:09 | 000,000,281 | —- | M] () – C:\Shortcut to Backup (D).lnk
[2007/01/01 17:08:32 | 000,523,058 | —- | M] () – C:\sweb_install.log
[2006/06/07 19:18:15 | 000,000,071 | —- | M] () – C:\SystemInfo.ini

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 13:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/02/27 19:15:28 | 000,115,200 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdxdrpp.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2006/06/16 18:31:22 | 000,106,496 | —- | M] (Nova Development.) – C:\WINDOWS\UPSCR.Scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2008/12/31 22:00:31 | 000,001,610 | -H– | M] () – C:\Documents and Settings\Randy\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 12:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/10 12:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/10 12:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/10/29 20:42:08 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/06/12 18:49:10 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Randy\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 13:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Randy\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/06/04 09:20:02 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Randy\Desktop\ATF-Cleaner.exe
[2011/10/30 12:55:58 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Randy\Desktop\HiJackThis.exe
[2011/10/31 15:07:24 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Randy\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-10-31 02:57:52

========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C39E55C5

< End of report >

Drive C: | 38.74 Gb Total Space | 0.57 Gb Free Space | 1.48% Space Free | Partition Type: NTFS
Drive D: | 12.00 Gb Total Space | 11.87 Gb Free Space | 98.89% Space Free | Partition Type: NTFS

Computer Name: INSPIRON6400 | User Name: Randy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" %*
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech Inc.)
"C:\Program Files\Logitech\Harmony Remote\HarmonyClient" = C:\Program Files\Logitech\Harmony Remote\HarmonyClient:*:Enabled:Logitech Harmony Remote Software
"C:\Program Files\Logitech\Harmony Remote\PatchHelper.exe" = C:\Program Files\Logitech\Harmony Remote\PatchHelper.exe:*:Enabled:Remote Control Software Patch Helper – ()
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger – (Logitech Inc.)
"C:\Program Files\Logitech\Harmony Remote\HarmonyClient" = C:\Program Files\Logitech\Harmony Remote\HarmonyClient:*:Enabled:Logitech Harmony Remote Software
"C:\Program Files\Logitech\Harmony Remote\PatchHelper.exe" = C:\Program Files\Logitech\Harmony Remote\PatchHelper.exe:*:Enabled:Remote Control Software Patch Helper – ()
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare
"C:\Program Files\SmartFTP Client\SmartFTP.exe" = C:\Program Files\SmartFTP Client\SmartFTP.exe:*:Enabled:SmartFTP Client 2.5 – (SmartSoft Ltd.)
"C:\WINDOWS\system32\lxdxcoms.exe" = C:\WINDOWS\system32\lxdxcoms.exe:*:Enabled:Lexmark Communications System – ( )
"C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe" = C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe:*:Enabled:Lexmark Device Monitor – ()
"C:\Program Files\Lexmark 3600-4600 Series\frun.exe" = C:\Program Files\Lexmark 3600-4600 Series\frun.exe:*:Enabled:Lexmark Productivity Studio – ()
"C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe" = C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:*:Enabled:ABBYY FineReader
"C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe" = C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe:*:Enabled:Printer Device Monitor – ()
"C:\Documents and Settings\Randy\Local Settings\Temp\lxdx\wireless\lxdxwpss.exe" = C:\Documents and Settings\Randy\Local Settings\Temp\lxdx\wireless\lxdxwpss.exe:*:Enabled:
"C:\WINDOWS\system32\lxdxcfg.exe" = C:\WINDOWS\system32\lxdxcfg.exe:*:Enabled:Printer Communication System – ( )
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdxpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdxpswx.exe:*:Enabled:Printer Status Window Interface – ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdxtime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdxtime.exe:*:Enabled:Lexmark Connect Time Executable – (Lexmark International, Inc.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdxjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdxjswx.exe:*:Enabled:Job Status Window Interface – ()
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0456ebd7-5f67-4ab6-852e-63781e3f389c}" = Macromedia Flash Player
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{28F451B0-44E5-48C0-8706-84114249F5B4}" = LightScribe [removed]
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
"{414A373B-59DF-4102-94CA-9FE9A74CBDDA}" = Garmin Trip and Waypoint Manager v5
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6F845B05-8B76-4302-A808-7FB21E2BC5E6}" = Sony DVD Handycam USB Driver
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7CDA2B02-E0A4-4EB5-8533-050D535BA43A}" = Media Converter for Philips
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{888B3583-C689-44FD-9573-DAB8B7F8A0AA}" = MapSource - MetroGuide USA
"{8A6AD979-8170-49ED-8529-14174317B281}" = SA60xx Device Manager
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{996EC44B-38E1-4898-8E47-3EE3D15F2712}" = Garmin WebUpdater
"{9D2B0322-44AE-460E-9283-4D2D7A9205AE}" = Trend Micro Internet Security
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B208806F-A231-4FA0-AB3F-5C1B8979223E}" = Microsoft ActiveSync 4.0
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc
"{B702CCCE-3176-4DBF-B932-D1B8F402F330}" = Digital Content Portal
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C169D3BB-9A27-43F5-9979-09A0D65FE95C}" = SmartFTP Client
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{FD350FC2-A972-427D-800B-A2D200ACFF41}" = ImageMixer for Sony DVD Handycam
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFA&SUBSYS;_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"exPressit S.E. 3.0" = exPressit S.E. 3.0
"GSAK" = GSAK 6.6.2 Build 25 (Final)
"GSAK_is1" = GSAK [removed] (Final)
"hp print screen utility" = hp print screen utility
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Lexmark 3600-4600 Series" = Lexmark 3600-4600 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MP3MMS" = USB MP3 Player Music Manage System
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PSNPMONV1" = Network Print Monitor for Windows 2000/XP
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SmartFTP Client 2.5 Setup Files" = SmartFTP Client 2.5 Setup Files (remove only)
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Switch" = Switch Sound File Converter
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VCast Music Essentials Manager" = V CAST Music Manager
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WebPost" = Microsoft Web Publishing Wizard 1.52
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/29/2011 6:36:08 PM | Computer Name = INSPIRON6400 | Source = Application Error | ID = 1000
Description = Faulting application _entice2.exe, version 1.0.0.0, faulting module
_entice2.exe, version 1.0.0.0, fault address 0x000663e4.

Error - 10/29/2011 6:37:41 PM | Computer Name = INSPIRON6400 | Source = Application Error | ID = 1001
Description = Fault bucket 01858624.

Error - 10/29/2011 7:06:56 PM | Computer Name = INSPIRON6400 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office XP Professional with FrontPage – Error
1706. Setup cannot find the required files. Check your connection to the network,
or CD-ROM drive. For other potential solutions to this problem, see C:\Program
Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 10/29/2011 7:06:58 PM | Computer Name = INSPIRON6400 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office XP Professional with FrontPage - Update
'{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}' could not be installed. Error code 1603.
Windows Installer can create logs to help troubleshoot issues with installing software
packages. Use the following link for instructions on turning on logging support:
http://go.microsoft.com/fwlink/?LinkId=23127

Error - 10/29/2011 10:43:08 PM | Computer Name = INSPIRON6400 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office XP Professional with FrontPage – Error
1706. Setup cannot find the required files. Check your connection to the network,
or CD-ROM drive. For other potential solutions to this problem, see C:\Program
Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 10/29/2011 10:43:10 PM | Computer Name = INSPIRON6400 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office XP Professional with FrontPage - Update
'{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}' could not be installed. Error code 1603.
Windows Installer can create logs to help troubleshoot issues with installing software
packages. Use the following link for instructions on turning on logging support:
http://go.microsoft.com/fwlink/?LinkId=23127

Error - 10/30/2011 1:32:03 PM | Computer Name = INSPIRON6400 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/30/2011 1:32:13 PM | Computer Name = INSPIRON6400 | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.

Error - 10/30/2011 1:48:02 PM | Computer Name = INSPIRON6400 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office XP Professional with FrontPage – Error
1706. Setup cannot find the required files. Check your connection to the network,
or CD-ROM drive. For other potential solutions to this problem, see C:\Program
Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 10/30/2011 1:48:03 PM | Computer Name = INSPIRON6400 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office XP Professional with FrontPage - Update
'{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}' could not be installed. Error code 1603.
Windows Installer can create logs to help troubleshoot issues with installing software
packages. Use the following link for instructions on turning on logging support:
http://go.microsoft.com/fwlink/?LinkId=23127

[ System Events ]
Error - 10/30/2011 11:49:50 PM | Computer Name = INSPIRON6400 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/31/2011 12:31:02 AM | Computer Name = INSPIRON6400 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdxCATSCustConnectService
service to connect.

Error - 10/31/2011 12:31:02 AM | Computer Name = INSPIRON6400 | Source = Service Control Manager | ID = 7000
Description = The lxdxCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 10/31/2011 2:47:53 PM | Computer Name = INSPIRON6400 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.254.101 for the Network Card with network
address 0015C51C7F6D has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 10/31/2011 2:48:13 PM | Computer Name = INSPIRON6400 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdxCATSCustConnectService
service to connect.

Error - 10/31/2011 2:48:13 PM | Computer Name = INSPIRON6400 | Source = Service Control Manager | ID = 7000
Description = The lxdxCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 10/31/2011 3:46:54 PM | Computer Name = INSPIRON6400 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdxCATSCustConnectService
service to connect.

Error - 10/31/2011 3:46:54 PM | Computer Name = INSPIRON6400 | Source = Service Control Manager | ID = 7000
Description = The lxdxCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 10/31/2011 3:59:43 PM | Computer Name = INSPIRON6400 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdxCATSCustConnectService
service to connect.

Error - 10/31/2011 3:59:43 PM | Computer Name = INSPIRON6400 | Source = Service Control Manager | ID = 7000
Description = The lxdxCATSCustConnectService service failed to start due to the
following error: %%1053


< End of report >
Hi MsMagoo,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Sorry that you have waited so long. :(

Do you still need help?

If so…. I'm not seeing anything in your log. Let's get an online scan:

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
TomK, I am very appreciative of your help and still need it. Logs today are sooo huge compared to Hijackthis. There is so much for you folks at WTT to process for each case. I ran ESET as you requested and it came back clean. ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=fb55c02d0d1e8b42bdb617551bc9eea1 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-11-07 05:02:07 # local_time=2011-11-06 11:02:07 (-0600, Central Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=513 16777125 100 100 0 49657709 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=67008 # found=0 # cleaned=0 # scan_time=3760 I await your recommendations. MsMagoo
Tomk, I'm glad to hear that malware does not appear to be the root cause. Mr. Fix-It did not fix it. Seems like the user account might be corrupted. I've been successful at setting up a better functioning IE on a Guest account and a new admin account. Also installed Firefox. I'm now looking into ways to reset IE8. -Ms. Magoo
MsMagoo,

At this point, I'm thinking you will be better served by the Tech Team over in the Browser forum.

When you post there… it wouldn't hurt for you to post a link back to this thread in case anything in your logs will be helpful to them.

Meanwhile:
Log looks good :D


Time for some housekeeping

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved (at least as far as malware is concerned). :thumbup:
:) Thanks for your help Tomk. I didn't use OTL so I won't have to clean up from it. Thanks for the reminders and pointing me to Browsers. I am ready for you to close this case. MsMagoo

I didn't use OTL so I won't have to clean up from it.


Uhm… the log you provided in your first post is an OTL log. :popcorn:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI