This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ping.exe infected? google redirect [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So many problems. I was going to reinstall OS but i'd really like to know how to tackle this. Ping.exe is taking over cpu. Google links send me to different sites. Java crashed on me. msconfig shows soooo much junk on startup which is probably why it takes 10 minutes to boot the silly computer. I ran mcafee which found a few trojans. Then someone found it wise to run windows defender as well (why i couldnt say). I would be grateful for any and all help or advice I could get. Thanks so much for your time!

Here are my OTL logs:


OTL logfile created on: 11/28/2011 1:36:37 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Nicole Chaplin\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.22 Gb Total Physical Memory | 0.16 Gb Available Physical Memory | 13.22% Memory free
2.91 Gb Paging File | 1.69 Gb Available in Paging File | 58.11% Paging File free
Paging file location(s): C:\pagefile.sys 1872 3744 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 8.90 Gb Free Space | 23.89% Space Free | Partition Type: NTFS

Computer Name: CHAPLIN1 | User Name: Nicole Chaplin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Nicole Chaplin\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - c:\Program Files\real\realplayer\realplay.exe (RealNetworks, Inc.)
PRC - c:\Program Files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
PRC - C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Toshiba\Power Management\CePMTray.exe (COMPAL ELECTRONIC INC.)
PRC - C:\Program Files\Toshiba\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
PRC - C:\Program Files\Toshiba\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
PRC - C:\WINDOWS\system32\ZoomingHook.exe (TOSHIBA)
PRC - C:\Program Files\Toshiba\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\EzButton\EzButton.EXE (Dritek System Inc.)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe (COMPAL ELECTRONIC INC.)
PRC - C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe ()
PRC - C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Touch and Launch\PadExe.exe (TOSHIBA)
PRC - C:\TOSHIBA\Ivp\ISM\pinger.exe (TOSHIBA Corporation)
PRC - C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
PRC - C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll ()
MOD - C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\avutil-51.dll ()
MOD - C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\avformat-53.dll ()
MOD - C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\avcodec-53.dll ()
MOD - C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Google\Google Desktop Search\gzlib.dll ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\WINDOWS\system32\acs.exe ()
MOD - c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe ()
MOD - C:\Program Files\ArcSoft\Software Suite\PhotoImpression\Share\PIHook.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (mfevtp) – C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()
SRV - (CeEPwrSvc) – C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe (COMPAL ELECTRONIC INC.)
SRV - (CFSvcs) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (Swupdtmr) – c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe ()
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)


========== Driver Services (SafeList) ==========

DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (EPOWER) – C:\WINDOWS\system32\drivers\hkdrv.sys (Compal Electronic Inc.)
DRV - (SrvcEPECioctl) – C:\WINDOWS\system32\drivers\ECioctl.sys ()
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (SrvcSSIOMngr) – C:\WINDOWS\system32\drivers\SSIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcTPIOMngr) – C:\WINDOWS\system32\drivers\TPIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEPIOMngr) – C:\WINDOWS\system32\drivers\EPIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEKIOMngr) – C:\WINDOWS\system32\drivers\EKIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (ESMCR) – C:\WINDOWS\system32\drivers\ESM7SK.sys (ENE Technology Inc.)
DRV - (ESDCR) – C:\WINDOWS\system32\drivers\ESD7SK.sys (ENE Technology Inc.)
DRV - (EMSCR) – C:\WINDOWS\system32\drivers\EMS7SK.sys (ENE Technology Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMSC)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (w22n51) Intel® – C:\WINDOWS\system32\drivers\w22n51.sys (Intel® Corporation)
DRV - ({E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}) – C:\WINDOWS\system32\drivers\wA301a.sys (Intel Corporation)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (RTL8023) – C:\WINDOWS\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (TBiosDrv) – C:\WINDOWS\system32\drivers\tbiosdrv.sys ()
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {F585F650-3957-45E2-B6D1-D7BE84F49BC9}:1.9.1
FF - prefs.js..extensions.enabledItems: {D7A21BDC-1787-415C-9BF6-323F514506AE}:1.9.1
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {F205410D-EF3E-4063-AB7C-A1154ABD66C1}:1.9.1

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.669: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.669: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.669: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.669: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F585F650-3957-45E2-B6D1-D7BE84F49BC9}: C:\Documents and Settings\Richard Chaplin\Local Settings\Application Data\{F585F650-3957-45E2-B6D1-D7BE84F49BC9} [2010/12/23 03:48:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D7A21BDC-1787-415C-9BF6-323F514506AE}: C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\{D7A21BDC-1787-415C-9BF6-323F514506AE} [2010/12/24 02:33:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/03/16 09:19:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F205410D-EF3E-4063-AB7C-A1154ABD66C1}: C:\Documents and Settings\Slicker\Local Settings\Application Data\{F205410D-EF3E-4063-AB7C-A1154ABD66C1} [2011/06/25 04:15:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/10/25 07:04:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2011/11/28 08:11:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/11/20 23:21:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/09 12:24:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/19 19:56:36 | 000,000,000 | —D | M]

[2011/03/23 14:44:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Nicole Chaplin\Application Data\Mozilla\Extensions
[2011/07/06 21:54:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Nicole Chaplin\Application Data\Mozilla\Firefox\Profiles\yvjbkjd6.default\extensions
[2011/07/06 21:53:43 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Nicole Chaplin\Application Data\Mozilla\Firefox\Profiles\yvjbkjd6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/11/09 12:24:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/25 07:04:46 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/12/24 02:33:52 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\NICOLE CHAPLIN\LOCAL SETTINGS\APPLICATION DATA\{D7A21BDC-1787-415C-9BF6-323F514506AE}
[2010/12/23 03:48:26 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\RICHARD CHAPLIN\LOCAL SETTINGS\APPLICATION DATA\{F585F650-3957-45E2-B6D1-D7BE84F49BC9}
[2011/06/25 04:15:18 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\SLICKER\LOCAL SETTINGS\APPLICATION DATA\{F205410D-EF3E-4063-AB7C-A1154ABD66C1}
[2011/11/09 12:24:08 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 13:01:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\mozilla firefox\components\Scriptff.dll
[2011/03/23 15:08:34 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2011/03/23 15:08:36 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol500.dll
[2009/11/19 16:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/02/02 20:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 16:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/04/18 20:15:14 | 000,001,919 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing-zugo.xml
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/09 12:24:08 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: CouponNetwork Coupon Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\plugins\NPcol400.dll
CHR - plugin: CouponNetwork Coupon Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\plugins\NPcol500.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2166.3772\npCIDetect14.dll
CHR - plugin: Motive Plugin (Enabled) = C:\Program Files\Common Files\Motive\npMotive.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: AT_InfectedMushroom = C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dobnnindgjlefbclgkdfgjaikcdiaone\3_0\
CHR - Extension: SiteAdvisor = C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\

Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20111119175327.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5825.1100\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\Toshiba\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [CeEPOWER] C:\Program Files\Toshiba\Power Management\CePMTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [Notebook Maximizer] C:\Program Files\Notebook Maximizer\maximizer_startup.exe ()
O4 - HKLM..\Run: [PadTouch] C:\Program Files\Toshiba\Touch and Launch\PadExe.exe (TOSHIBA)
O4 - HKLM..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TPNF] C:\Program Files\Toshiba\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoomingHook] C:\WINDOWS\system32\ZoomingHook.exe (TOSHIBA)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - Startup: C:\Documents and Settings\Nicole Chaplin\Start Menu\Programs\Startup\AutoMailer.lnk = C:\Troopmaster Software\AutoMailer\AutoMailer.exe ()
O4 - Startup: C:\Documents and Settings\Nicole Chaplin\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pattcw.att.motive.com/wizlet/DSLAct…etInstaller.cab (WebBrowserType Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{634AE888-59B9-4D78-B076-37BBE865503B}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/28 12:48:08 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2011/11/28 08:30:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/11/19 17:53:25 | 000,009,608 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeclnk.sys
[2011/11/19 17:52:37 | 000,089,792 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfetdi2k.sys
[2011/11/19 17:52:37 | 000,083,856 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfendisk.sys
[2011/11/19 17:52:36 | 000,338,176 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfefirek.sys
[2011/11/19 17:52:36 | 000,180,816 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeavfk.sys
[2011/11/19 17:52:36 | 000,087,656 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mferkdet.sys
[2011/11/19 17:52:36 | 000,059,456 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfebopk.sys
[2011/11/19 17:52:35 | 000,057,600 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\cfwids.sys
[2011/11/19 17:51:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2011/11/19 17:50:13 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2011/11/19 17:48:47 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2011/11/19 17:29:11 | 000,150,856 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\mfevtps.exe
[2011/11/10 23:28:54 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Real
[2011/11/10 22:59:24 | 000,000,000 | —D | C] – C:\Program Files\24548
[2011/11/10 22:58:57 | 000,000,000 | —D | C] – C:\Program Files\LP
[2011/11/10 01:45:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Nicole Chaplin\My Documents\school
[2011/11/06 08:12:17 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/11/06 08:12:17 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/11/06 08:12:17 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/07/30 23:43:28 | 000,028,672 | —- | C] ( ) – C:\WINDOWS\System32\ControlACS.exe
[2004/08/19 16:00:02 | 000,036,864 | —- | C] ( ) – C:\WINDOWS\System32\ECioctl.dll
[2004/06/11 03:27:12 | 000,131,072 | —- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll
[53 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/28 13:46:00 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/11/28 13:41:56 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2484699402-2213377390-3129252041-1007.job
[2011/11/28 13:41:51 | 000,000,304 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2484699402-2213377390-3129252041-1007.job
[2011/11/28 13:38:17 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/11/28 13:32:00 | 000,001,018 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2484699402-2213377390-3129252041-1006UA.job
[2011/11/28 13:24:00 | 000,001,014 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2484699402-2213377390-3129252041-1007UA.job
[2011/11/28 13:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At28.job
[2011/11/28 13:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At27.job
[2011/11/28 12:49:00 | 000,000,902 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/28 12:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At26.job
[2011/11/28 12:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At25.job
[2011/11/28 11:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2011/11/28 11:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2011/11/28 10:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2011/11/28 10:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2011/11/28 09:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2011/11/28 09:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2011/11/28 08:25:29 | 000,000,807 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\Desktop\Notebook Maximizer.LNK
[2011/11/28 08:24:19 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/28 08:24:19 | 000,000,298 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2484699402-2213377390-3129252041-1006.job
[2011/11/28 08:24:19 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/11/28 08:24:16 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2484699402-2213377390-3129252041-1009.job
[2011/11/28 08:24:16 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2484699402-2213377390-3129252041-1008.job
[2011/11/28 08:22:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/28 08:22:34 | 1307,017,216 | -HS- | M] () – C:\hiberfil.sys
[2011/11/28 08:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2011/11/28 08:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2011/11/28 07:53:46 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/23 03:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2011/11/23 03:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2011/11/21 22:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At46.job
[2011/11/21 22:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At45.job
[2011/11/21 21:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At44.job
[2011/11/21 21:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At43.job
[2011/11/21 20:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At42.job
[2011/11/21 20:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At41.job
[2011/11/21 19:03:01 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At40.job
[2011/11/21 19:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At39.job
[2011/11/21 18:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At38.job
[2011/11/21 18:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At37.job
[2011/11/21 17:35:25 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/11/21 17:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At36.job
[2011/11/21 17:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At35.job
[2011/11/21 16:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At34.job
[2011/11/21 16:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At33.job
[2011/11/21 15:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At32.job
[2011/11/21 15:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At31.job
[2011/11/21 14:32:00 | 000,000,966 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2484699402-2213377390-3129252041-1006Core.job
[2011/11/21 14:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At30.job
[2011/11/21 14:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At29.job
[2011/11/21 02:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2011/11/21 02:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2011/11/21 01:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/11/21 01:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/11/21 00:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/11/21 00:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/11/20 23:03:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At48.job
[2011/11/20 23:03:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At47.job
[2011/11/20 09:56:01 | 000,002,329 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/11/20 09:56:00 | 000,002,351 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\Desktop\Google Chrome.lnk
[2011/11/19 23:19:43 | 000,000,290 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2484699402-2213377390-3129252041-1008.job
[2011/11/19 22:42:55 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2484699402-2213377390-3129252041-1009.job
[2011/11/19 20:24:01 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/11/19 19:51:36 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/11/19 18:38:20 | 000,000,306 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2484699402-2213377390-3129252041-1006.job
[2011/11/19 17:31:29 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2011/11/19 17:31:29 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2011/11/19 16:45:43 | 000,000,000 | —- | M] () – C:\WINDOWS\Klagis.bin
[2011/11/18 22:32:25 | 000,000,304 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~315IBtHUrdfzSl
[2011/11/18 22:32:25 | 000,000,232 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~315IBtHUrdfzSlr
[2011/11/18 22:32:16 | 000,000,328 | —- | M] () – C:\Documents and Settings\All Users\Application Data\315IBtHUrdfzSl
[2011/11/18 22:31:53 | 000,346,880 | —- | M] () – C:\Documents and Settings\All Users\Application Data\315IBtHUrdfzSl.exe
[2011/11/18 22:12:20 | 000,000,001 | —- | M] () – C:\Documents and Settings\All Users\Application Data\87T8a2b5.exe_.b
[2011/11/18 22:12:20 | 000,000,001 | —- | M] () – C:\Documents and Settings\All Users\Application Data\87T8a2b5.exe.b
[2011/11/17 07:24:00 | 000,000,962 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2484699402-2213377390-3129252041-1007Core.job
[2011/11/17 07:03:06 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2011/11/17 07:03:06 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2011/11/17 06:03:06 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2011/11/17 06:03:06 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2011/11/17 05:03:06 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2011/11/17 05:03:06 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2011/11/17 04:03:06 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2011/11/17 04:03:06 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2011/11/15 14:23:32 | 000,000,112 | —- | M] () – C:\Documents and Settings\All Users\Application Data\0Vh7046.dat
[2011/11/15 11:23:49 | 000,100,702 | —- | M] () – C:\WINDOWS\System32\itusbcore.dat
[2011/11/15 11:23:49 | 000,000,196 | —- | M] () – C:\WINDOWS\System32\itlsvc.dat
[2011/11/15 10:23:29 | 000,100,701 | —- | M] () – C:\WINDOWS\System32\itldvupd.dat
[2011/11/11 20:12:29 | 000,386,040 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/11 20:12:28 | 000,055,200 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/11 20:02:31 | 002,918,912 | —- | M] () – C:\WINDOWS\System32\AV Security 2012v121.exe
[2011/11/10 11:13:19 | 000,492,184 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Amazonhpdeal.pdf
[2011/11/10 02:38:46 | 001,407,645 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\fb jhs.pdf
[2011/11/10 02:36:12 | 002,109,622 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\fb sil.pdf
[2011/11/10 02:30:38 | 001,900,832 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\fb weirdness.pdf
[2011/11/10 02:13:52 | 000,213,866 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\vmcall5.pdf
[2011/11/10 02:13:05 | 000,213,991 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\vmcall4.pdf
[2011/11/10 02:12:09 | 000,213,935 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\vmcall3.pdf
[2011/11/10 02:11:31 | 000,213,901 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\vmlog2.pdf
[2011/11/10 02:10:53 | 000,213,898 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\vmcall1.pdf
[2011/11/10 01:53:51 | 001,062,340 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail gag.pdf
[2011/11/10 01:52:25 | 001,093,661 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail kristen.pdf
[2011/11/10 01:49:43 | 001,392,251 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail denise.pdf
[2011/11/10 01:48:03 | 001,056,077 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail tiger lady.pdf
[2011/11/10 01:46:15 | 001,074,366 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail ick.pdf
[2011/11/10 01:41:29 | 000,853,056 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail.pdf
[2011/11/10 01:40:58 | 001,091,482 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detailmandy.pdf
[2011/11/10 01:40:21 | 000,985,467 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\MyMatch Home _ Match.pdf
[2011/11/10 01:35:26 | 000,441,068 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist _ manage posting5.pdf
[2011/11/10 01:34:58 | 000,439,494 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist _ manage posting4.pdf
[2011/11/10 01:34:09 | 000,440,847 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist _ manage posting3.pdf
[2011/11/10 01:33:45 | 000,440,702 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist _ manage posting2.pdf
[2011/11/10 01:33:27 | 000,442,016 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist _ manage posting.pdf
[2011/11/10 01:32:17 | 000,441,920 | —- | M] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist account.pdf
[53 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/21 22:34:13 | 000,000,296 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2484699402-2213377390-3129252041-1007.job
[2011/11/19 22:34:30 | 000,000,282 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2484699402-2213377390-3129252041-1008.job
[2011/11/19 19:51:33 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/11/19 19:51:32 | 000,002,347 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/11/19 18:34:31 | 000,000,298 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2484699402-2213377390-3129252041-1006.job
[2011/11/18 22:32:25 | 000,000,304 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~315IBtHUrdfzSl
[2011/11/18 22:32:25 | 000,000,232 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~315IBtHUrdfzSlr
[2011/11/18 22:32:16 | 000,000,328 | —- | C] () – C:\Documents and Settings\All Users\Application Data\315IBtHUrdfzSl
[2011/11/18 22:31:53 | 000,346,880 | —- | C] () – C:\Documents and Settings\All Users\Application Data\315IBtHUrdfzSl.exe
[2011/11/18 22:12:20 | 000,000,001 | —- | C] () – C:\Documents and Settings\All Users\Application Data\87T8a2b5.exe_.b
[2011/11/18 22:12:20 | 000,000,001 | —- | C] () – C:\Documents and Settings\All Users\Application Data\87T8a2b5.exe.b
[2011/11/18 16:07:34 | 000,000,288 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/11/18 16:07:34 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/11/15 14:19:01 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\0Vh7046.dat
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At48.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At46.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At44.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At42.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At40.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At38.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At36.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At34.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At32.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At30.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At28.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At26.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At24.job
[2011/11/15 14:18:59 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At22.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At47.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At45.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At43.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At41.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At39.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At37.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At35.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At33.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At31.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At29.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At27.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At25.job
[2011/11/15 14:18:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At23.job
[2011/11/15 14:18:58 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At8.job
[2011/11/15 14:18:58 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At6.job
[2011/11/15 14:18:58 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At4.job
[2011/11/15 14:18:58 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At20.job
[2011/11/15 14:18:58 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At2.job
[2011/11/15 14:18:58 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At18.job
[2011/11/15 14:18:58 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At16.job
[2011/11/15 14:18:58 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At14.job
[2011/11/15 14:18:58 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At12.job
[2011/11/15 14:18:58 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At10.job
[2011/11/15 14:18:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At9.job
[2011/11/15 14:18:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At7.job
[2011/11/15 14:18:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At5.job
[2011/11/15 14:18:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At3.job
[2011/11/15 14:18:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At21.job
[2011/11/15 14:18:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At19.job
[2011/11/15 14:18:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At17.job
[2011/11/15 14:18:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At15.job
[2011/11/15 14:18:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At13.job
[2011/11/15 14:18:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At11.job
[2011/11/15 14:18:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2011/11/15 11:23:49 | 000,100,702 | —- | C] () – C:\WINDOWS\System32\itusbcore.dat
[2011/11/15 10:23:29 | 000,100,701 | —- | C] () – C:\WINDOWS\System32\itldvupd.dat
[2011/11/15 10:23:29 | 000,000,196 | —- | C] () – C:\WINDOWS\System32\itlsvc.dat
[2011/11/10 22:58:28 | 002,918,912 | —- | C] () – C:\WINDOWS\System32\AV Security 2012v121.exe
[2011/11/10 11:13:19 | 000,492,184 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Amazonhpdeal.pdf
[2011/11/10 02:38:45 | 001,407,645 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\fb jhs.pdf
[2011/11/10 02:36:12 | 002,109,622 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\fb sil.pdf
[2011/11/10 02:30:38 | 001,900,832 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\fb weirdness.pdf
[2011/11/10 02:13:52 | 000,213,866 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\vmcall5.pdf
[2011/11/10 02:13:05 | 000,213,991 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\vmcall4.pdf
[2011/11/10 02:12:09 | 000,213,935 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\vmcall3.pdf
[2011/11/10 02:11:31 | 000,213,901 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\vmlog2.pdf
[2011/11/10 02:10:53 | 000,213,898 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\vmcall1.pdf
[2011/11/10 01:53:50 | 001,062,340 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail gag.pdf
[2011/11/10 01:52:25 | 001,093,661 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail kristen.pdf
[2011/11/10 01:49:43 | 001,392,251 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail denise.pdf
[2011/11/10 01:48:03 | 001,056,077 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail tiger lady.pdf
[2011/11/10 01:46:15 | 001,074,366 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail ick.pdf
[2011/11/10 01:41:29 | 000,853,056 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detail.pdf
[2011/11/10 01:40:58 | 001,091,482 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\Message Detailmandy.pdf
[2011/11/10 01:40:20 | 000,985,467 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\MyMatch Home _ Match.pdf
[2011/11/10 01:35:26 | 000,441,068 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist _ manage posting5.pdf
[2011/11/10 01:34:58 | 000,439,494 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist _ manage posting4.pdf
[2011/11/10 01:34:09 | 000,440,847 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist _ manage posting3.pdf
[2011/11/10 01:33:45 | 000,440,702 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist _ manage posting2.pdf
[2011/11/10 01:33:27 | 000,442,016 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist _ manage posting.pdf
[2011/11/10 01:32:16 | 000,441,920 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\My Documents\craigslist account.pdf
[2010/12/29 01:22:35 | 000,000,000 | —- | C] () – C:\WINDOWS\TPTray.INI
[2010/12/23 03:48:30 | 000,000,000 | —- | C] () – C:\WINDOWS\Klagis.bin
[2010/12/23 03:48:28 | 000,000,120 | —- | C] () – C:\WINDOWS\Rneluw.dat
[2010/11/14 19:14:43 | 000,000,000 | —- | C] () – C:\WINDOWS\CePMTray.INI
[2010/10/23 19:52:02 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2010/10/22 15:00:20 | 000,024,064 | —- | C] () – C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/19 03:37:18 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/11 18:30:45 | 000,010,732 | —- | C] () – C:\WINDOWS\hpdj3740.ini
[2010/07/30 23:43:28 | 000,241,664 | —- | C] () – C:\WINDOWS\System32\ControlWZCS.exe
[2010/07/30 23:43:26 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\AegisI5.exe
[2010/07/30 23:43:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\acs.exe
[2010/07/30 23:43:25 | 000,218,003 | —- | C] () – C:\WINDOWS\dssec.dat
[2010/07/30 23:33:19 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2010/07/30 23:32:40 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2010/07/30 23:32:40 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2010/07/30 23:32:40 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2010/07/30 23:32:40 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2010/07/30 23:32:40 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2010/07/30 23:32:40 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2010/07/30 23:32:08 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/07/22 22:25:07 | 000,005,428 | —- | C] () – C:\WINDOWS\hpfmdl_s04_main.dat
[2005/07/22 22:25:07 | 000,000,362 | —- | C] () – C:\WINDOWS\hpfins_s04_main.dat
[2004/08/20 16:50:07 | 000,000,000 | —- | C] () – C:\WINDOWS\CeEKey.INI
[2004/08/20 14:15:42 | 000,000,067 | —- | C] () – C:\WINDOWS\swupdate.INI
[2004/08/19 19:4LS\x00\x00\x00\x00
:welcome:

Please do not start any new topics, just reply to this one by selecting ADD REPLY, all your other posts are duplicates and will be deleted




Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
My computer is running like molasses. Task manager showing ping.exe using up to 87% cpu which is ridiculous. Something is constantly trying to install itself and I cant figure out what it is. msconfig showed a lot of junk going on at startup..I just left it since I'm not sure what most of it even is. Google links send me to bogus sites. I was going to start over but reinstalling this old OS is not fun. Hopefully someone will have some advice for me. I'd appreciate any I can get. Always happy to learn something new. Thanks a lot for your time.

This is the third time I'm trying to post this. Chrome gives me error messages saying my connection reset. that's a new one for me. Fingers crossed :)




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:39:10 PM, on 11/28/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ACS.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\EzButton\EzButton.EXE
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\System32\ZoomingHook.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Skype\Phone\Skype.exe
c:\program files\real\realplayer\RealPlay.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
c:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\ping.exe
C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Nicole Chaplin\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://toshibadirect.com/
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll (file missing)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111119175327.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5825.1100\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [ZoomingHook] c:\WINDOWS\System32\ZoomingHook.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [Notebook Maximizer] C:\Program Files\Notebook Maximizer\maximizer_startup.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Nicole Chaplin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: AutoMailer.lnk = C:\Troopmaster Software\AutoMailer\AutoMailer.exe
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} (WebBrowserType Class) - https://pattcw.att.motive.com/wizlet/DSLAct…etInstaller.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 15913 bytes
Please do not start any new topics, just reply to this one by selecting ADD REPLY, all your other posts are duplicates and will be deleted


I already replied to your topic, see my previous post and run those scans and post the logs by using the ADD REPLY ONLY

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI