This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

System Fix [Closed]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please Help!!!

My icons have dissapered and a system fix starts scaning my pc and a bunch of popups come up. I can not close the system fix or get on the internet. Here is my highjackthis log.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:14:28 PM, on 12/3/2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18639)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Lexmark 7600 Series\lxdwmon.exe
C:\Program Files\Lexmark 7600 Series\ezprint.exe
C:\Program Files\verizon\McciTrayApp.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\ProgramData\GBWXufOsmTrrX.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\ProgramData\5ahi3Vz8hQfzHR.exe
C:\Windows\system32\attrib.exe
C:\Users\Angie\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…amp;m=et1161-07
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…amp;m=et1161-07
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…amp;m=et1161-07
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: YTNavAssist.YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: NetAssistantBHO - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\Freeze.com\NetAssistant\NetAssistant.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [lxdwmon.exe] "C:\Program Files\Lexmark 7600 Series\lxdwmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7600 Series\ezprint.exe"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] "C:\Program Files\Verizon\McciTrayApp.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [RpgHdCGkerKXAj.exe] C:\ProgramData\RpgHdCGkerKXAj.exe
O4 - HKLM\..\Run: [Windows Defragment] C:\Windows\winsett.exe
O4 - HKLM\..\Run: [System Cleanup] C:\Windows\System32\winsett.exe
O4 - HKLM\..\Run: [Windows Auto Config] C:\Users\Angelique\AppData\Local\Temp\winsett.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [OpUJxuKltOTh.exe] C:\ProgramData\OpUJxuKltOTh.exe
O4 - HKLM\..\Run: [GBWXufOsmTrrX.exe] C:\ProgramData\GBWXufOsmTrrX.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Windows Defragment] C:\Windows\winsett.exe
O4 - HKCU\..\Run: [System Cleanup] C:\Windows\System32\winsett.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photo…NPUplden-us.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IHA_MessageCenter - Verizon - C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
O23 - Service: LiveUpdate - Symantec Corporation - c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: lxdwCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdwserv.exe
O23 - Service: lxdw_device - - C:\Windows\system32\lxdwcoms.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 12325 bytes
Hi litenbrite, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

*Do not use any temporary file cleaners*


Open hijackthis, do a system scan only and checkmark these lines, if present

O4 - HKLM\..\Run: [RpgHdCGkerKXAj.exe] C:\ProgramData\RpgHdCGkerKXAj.exe
O4 - HKLM\..\Run: [Windows Defragment] C:\Windows\winsett.exe
O4 - HKLM\..\Run: [System Cleanup] C:\Windows\System32\winsett.exe
O4 - HKLM\..\Run: [Windows Auto Config] C:\Users\Angelique\AppData\Local\Temp\winsett.exe
O4 - HKLM\..\Run: [OpUJxuKltOTh.exe] C:\ProgramData\OpUJxuKltOTh.exe
O4 - HKLM\..\Run: [GBWXufOsmTrrX.exe] C:\ProgramData\GBWXufOsmTrrX.exe
O4 - HKCU\..\Run: [Windows Defragment] C:\Windows\winsett.exe
O4 - HKCU\..\Run: [System Cleanup] C:\Windows\System32\winsett.exe


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.

Reboot the computer.

Can you now access the internet? If so please

Download OTL to your desktop.
  • Right click on OTL.exe and click "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with both OTL logs.
i completed the first step. However when i tried to download the OTL a window popped up saying OTL cannot be run from a temporary folder. PLease download it to your desktop or suitable location. Does not give me any other options. What do i do?
OTL Extras logfile created on: 12/6/2011 10:36:27 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = c:\Users\Xiamara Amezquita\Contacts
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.65 Gb Available Physical Memory | 57.42% Memory free
5.95 Gb Paging File | 4.58 Gb Available in Paging File | 76.88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.09 Gb Total Space | 208.82 Gb Free Space | 72.49% Space Free | Partition Type: NTFS

Computer Name: ANGELIQUE-PC | User Name: Angie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0C3EF1B6-724D-49F2-85CB-5600947C5F1A}" = rport=139 | protocol=6 | dir=out | app=system |
"{280451D1-B01A-4882-B58F-737DB3D3C557}" = rport=138 | protocol=17 | dir=out | app=system |
"{385FD7EA-971D-440D-BF74-1D3D11D562DC}" = lport=137 | protocol=17 | dir=in | app=system |
"{5E57BFF8-39D4-47F7-B61D-D3B410338C79}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{8CD31529-6B98-4905-BA12-9DD1A186A58A}" = lport=139 | protocol=6 | dir=in | app=system |
"{961EA401-471D-4772-9422-5735629983BF}" = rport=445 | protocol=6 | dir=out | app=system |
"{9A9A14F4-8F2F-4188-905A-65CFFE53688F}" = lport=50000 | protocol=17 | dir=in | name=iha_messagecenter |
"{A5212906-2B79-4C04-B36B-3CF7D04BA48B}" = rport=137 | protocol=17 | dir=out | app=system |
"{B0DF3169-1B87-4D2C-8ACA-2DB5ADCD7319}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{C1372987-AA2A-4262-BA29-17B7B412FE92}" = lport=50000 | protocol=17 | dir=in | name=iha_messagecenter |
"{CAC588D9-320F-4301-9BF3-1195B38A93B4}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E649EEF4-1EF8-44A0-AC7A-851C6234D866}" = lport=138 | protocol=17 | dir=in | app=system |
"{E64A7EFD-3EF3-4EC8-A7A3-65936E52AC4C}" = lport=445 | protocol=6 | dir=in | app=system |
"{F7E45190-EF81-495C-AB52-410CB2F371C6}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0099A743-178F-4D4C-A81B-F6335E3D5C16}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{01A48B71-8D8F-4BAF-9CD8-C857F7FD2509}" = protocol=17 | dir=in | app=c:\windows\system32\lxdwcoms.exe |
"{034AE028-F6DA-4FF7-9488-A8E45FD78CB4}" = protocol=17 | dir=in | app=c:\program files\hp\hp officejet pro 8500 a910\bin\devicesetup.exe |
"{0BEFB581-13B2-4EF8-8A88-7D1413B98DAC}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{2BA8B30B-DD60-4348-86A3-7385194DEF83}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{487E99FF-180B-45C2-A6CA-1DFF4F036AB1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{60048967-6489-4A78-9ACE-DFA1F4162623}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdwpswx.exe |
"{79FCD06E-BCE4-4FA9-B452-60D5466DB973}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{7C20106C-B09D-4DB1-AD1A-B44C0732BCB1}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{B6330D39-1DC2-4B0B-BE94-8EC73B8A8D37}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C02A7D17-B644-4588-B803-6AF432422F79}" = protocol=6 | dir=in | app=c:\program files\hp\hp officejet pro 8500 a910\bin\devicesetup.exe |
"{C9280698-0082-4BED-953B-6291667E6928}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdwpswx.exe |
"{E0E8F874-768D-4A15-A07D-40F9CA65FA18}" = protocol=17 | dir=in | app=c:\program files\hp\hp officejet pro 8500 a910\bin\hpnetworkcommunicator.exe |
"{E3FECA20-2BBE-4118-B73F-EDEA4D5385FF}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{E65FDBE2-E0BE-42AA-8A7C-490A3C611BCF}" = protocol=6 | dir=in | app=c:\program files\hp\hp officejet pro 8500 a910\bin\hpnetworkcommunicator.exe |
"{E90A2479-0A3E-4D16-A362-3241C8B7C0DE}" = protocol=6 | dir=in | app=c:\windows\system32\lxdwcoms.exe |
"{FAB831CA-2903-4C63-85AA-E1C240471F18}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"TCP Query User{D8DD82C9-0433-4915-B3D1-3FAD5A0A5721}C:\program files\hp\hp officejet pro 8500 a910\bin\scantopcactivationapp.exe" = protocol=6 | dir=in | app=c:\program files\hp\hp officejet pro 8500 a910\bin\scantopcactivationapp.exe |
"UDP Query User{D19BB211-179C-4A5F-AAFB-CD1A74904BFF}C:\program files\hp\hp officejet pro 8500 a910\bin\scantopcactivationapp.exe" = protocol=17 | dir=in | app=c:\program files\hp\hp officejet pro 8500 a910\bin\scantopcactivationapp.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0BDD3FAD-61CD-4BF3-B9C4-4CEFD43F53F8}" = Norton 360 HTMLHelp
"{0F052922-4BCE-4763-A540-00857554336D}" = Redist
"{13D324E9-9DB1-478D-944C-28BBE1BB80DC}" = HP Officejet Pro 8500 A910 Help
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{206FD69B-F9FE-4164-81BD-D52552BC9C23}" = GearDrvs
"{21829177-4DED-4209-AD08-490B3AC9C01A}" = Norton 360
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24DF7221-644B-4C3A-A478-459502D40522}" = Backup
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2D617065-1C52-4240-B5BC-C0AE12157777}" = Norton 360
"{3018B943-C76C-44B0-B078-790A28CEF67E}" = Microsoft UI Engine
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{40DA9A54-48CA-4A2C-AEAF-F67715BB046E}" = Norton 360
"{45690715-80A6-4445-B61D-ADEC5888E8CD}" = Symantec Technical Support Controls
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{55A6283C-638A-4EE0-B491-51118554BDA2}" = Norton Confidential Core
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{730EF0E8-8B8E-4054-B2CE-5D4BA3BCE510}" = Vz In Home Agent
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = eMachines Recovery Management
"{869D453C-53E8-4DE0-92EA-F574A22E82AE}" = HP Officejet Pro 8500 A910 Basic Device Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91533AC0-24A9-4EC6-9A8B-E05163B913B3}" = SymNet
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61}" = Digital Media Reader
"{BE2DDF55-4C42-44CC-A56E-C8E4A65CB2FF}" = IHA_MessageCenter
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C792A75A-2A1F-4991-9B85-291745478A79}" = NetAssistant
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2C5E510-BE6D-42CC-9F61-E4F939078474}" = Lexmark Printable Web
"{D6E6FA4A-5445-4850-8365-CF216C1CBB7A}" = Symantec Real Time Storage Protection Component
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{E3624DFE-B0AB-410A-9BDC-5D1681E5E388}" = HP Officejet Pro 8500 A910 Product Improvement Study
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FB0C267C-8B4F-4867-8161-A6A3B66D42C1}" = Marketsplash Shortcuts
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Agere Systems Soft Modem" = Agere Systems PCI-SV92PP Soft Modem
"Google Desktop" = Google Desktop
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61}" = Digital Media Reader
"Lexmark 7600 Series" = Lexmark 7600 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"SymSetup.{2D617065-1C52-4240-B5BC-C0AE12157777}" = Norton 360 (Symantec Corporation)
"Verizon Help and Support" = Verizon Help and Support Tool
"Verizon Media Manager" = Verizon Media Manager
"VLC media player" = VLC media player 1.1.4
"WildTangent emachines Master Uninstall" = eMachines Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1787382799-1039356036-4139006242-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{373B1718-8CC5-4567-8EE2-9033AD08A680}" = Roblox for Xiamara Amezquita
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/6/2011 12:23:31 PM | Computer Name = Angelique-PC | Source = Application Error | ID = 1000
Description = Faulting application win4036e0.dat, version 0.0.0.0, time stamp 0x4e57bcae,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x5d5e5fa5, process id 0x13fc, application start time 0x01cc9c0952fbc250.

Error - 11/19/2011 4:14:29 PM | Computer Name = Angelique-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksCal.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/19/2011 4:14:29 PM | Computer Name = Angelique-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/19/2011 4:14:29 PM | Computer Name = Angelique-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/19/2011 4:14:29 PM | Computer Name = Angelique-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/19/2011 4:15:31 PM | Computer Name = Angelique-PC | Source = WinMgmt | ID = 10
Description =

Error - 11/19/2011 4:50:11 PM | Computer Name = Angelique-PC | Source = VSS | ID = 8194
Description =

Error - 11/19/2011 5:10:28 PM | Computer Name = Angelique-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksCal.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/19/2011 5:10:28 PM | Computer Name = Angelique-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 11/19/2011 5:10:28 PM | Computer Name = Angelique-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".
Dependent
Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

[ System Events ]
Error - 12/6/2011 10:59:13 AM | Computer Name = Angelique-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume .

Error - 12/6/2011 11:01:56 AM | Computer Name = Angelique-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume .

Error - 12/6/2011 11:02:03 AM | Computer Name = Angelique-PC | Source = HTTP | ID = 15016
Description =

Error - 12/6/2011 11:02:11 AM | Computer Name = Angelique-PC | Source = Print | ID = 54
Description = Document http://forums.whatthetech.com/index.php?showtopic=121405
failed to print and was deleted because of corruption in the spooled file. The associated
driver is: HP Officejet Pro 8500 A910. Try printing the document again.

Error - 12/6/2011 11:02:15 AM | Computer Name = Angelique-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume .

Error - 12/6/2011 11:02:34 AM | Computer Name = Angelique-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume .

Error - 12/6/2011 11:03:12 AM | Computer Name = Angelique-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume .

Error - 12/6/2011 11:10:47 AM | Computer Name = Angelique-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume .

Error - 12/6/2011 11:11:06 AM | Computer Name = Angelique-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume .

Error - 12/6/2011 11:11:06 AM | Computer Name = Angelique-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume .


< End of report >
OTL logfile created on: 12/6/2011 10:36:27 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = c:\Users\Xiamara Amezquita\Contacts
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.65 Gb Available Physical Memory | 57.42% Memory free
5.95 Gb Paging File | 4.58 Gb Available in Paging File | 76.88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.09 Gb Total Space | 208.82 Gb Free Space | 72.49% Space Free | Partition Type: NTFS

Computer Name: ANGELIQUE-PC | User Name: Angie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - c:\Users\Xiamara Amezquita\Contacts\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe (Verizon)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Microsoft\BingBar\BingBar.exe (Microsoft Corporation.)
PRC - C:\Program Files\Microsoft\BingBar\BingApp.exe (Microsoft Corporation.)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\verizon\McciTrayApp.exe (Alcatel-Lucent)
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
PRC - C:\Program Files\Lexmark 7600 Series\ezprint.exe (Lexmark International Inc.)
PRC - C:\Program Files\Lexmark 7600 Series\lxdwmon.exe ()
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe ()
PRC - C:\Windows\System32\spool\drivers\w32x86\3\lxdwjswx.exe ()
PRC - C:\Windows\System32\spool\drivers\w32x86\3\lxdwpswx.exe ()
PRC - C:\Windows\System32\lxdwcoms.exe ( )
PRC - C:\Windows\System32\spool\drivers\w32x86\3\lxdwserv.exe (Lexmark International, Inc.)
PRC - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Google\Google Desktop Search\gzlib.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwmon.exe ()
MOD - C:\Program Files\Lexmark Printable Web\resource.dll ()
MOD - C:\Program Files\Lexmark Printable Web\bho.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwcaps.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwscw.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwdrs.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\iptk.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwdatr.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwcnv4.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwptp.dll ()


========== Win32 Services (SafeList) ==========

SRV - (IHA_MessageCenter) – C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe (Verizon)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (LiveUpdate Notice) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (LiveUpdate) – c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (ETService) – C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe ()
SRV - (lxdw_device) – C:\Windows\System32\lxdwcoms.exe ( )
SRV - (lxdwCATSCustConnectService) – C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxdwserv.exe ()
SRV - (Automatic LiveUpdate Scheduler) – c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (comHost) – c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20090815.019\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20090815.019\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\ipsdefs\20090811.002\IDSvix86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:\Windows\System32\Drivers\SYMNDISV.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\Windows\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (COH_Mon) – C:\Windows\System32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (int15) – C:\Windows\System32\drivers\int15.sys (Acer, Inc.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (CO_Mon) – C:\Windows\System32\drivers\CO_Mon.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…amp;m=et1161-07
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…amp;m=et1161-07


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…amp;m=et1161-07
IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=SUN3
IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - No CLSID value found
IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…amp;m=et1161-07
IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\2.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyWebSearch\bar\2.bin


O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Reg Error: Value error.) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (NetAssistant) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\Freeze.com\NetAssistant\NetAssistant.dll (W3i, LLC)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\..\Toolbar\WebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\..\Toolbar\WebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 7600 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [lxdwmon.exe] C:\Program Files\Lexmark 7600 Series\lxdwmon.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [osCheck] c:\Program Files\Norton 360\osCheck.exe (Symantec Corporation)
O4 - HKLM..\Run: [P2Go_Menu] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002..\Run: [System Cleanup] C:\Windows\System32\winsett.exe File not found
O4 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002..\Run: [Windows Defragment] C:\Windows\winsett.exe File not found
O4 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O7 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002\..Trusted Ranges: GD ([http] in Local intranet)
O15 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1003\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…NPUplden-us.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B1D990A1-3302-4B1F-B3A2-DB0FC3575EB6}: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O29 - HKLM SecurityProviders - (credssp.dll) -credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/03 22:06:10 | 000,388,608 | -H– | C] (Trend Micro Inc.) – C:\Users\Angie\HijackThis.exe
[2011/12/02 21:19:18 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Malwarebytes
[2011/12/02 16:15:08 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Fix
[2011/12/02 16:12:44 | 000,000,000 | -H-D | C] – C:\Users\Angie\Documents\OneNote Notebooks
[2011/12/02 16:11:57 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Yahoo!
[2011/12/02 15:48:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/12/02 15:48:40 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2011/12/02 15:46:12 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Macromedia
[2011/12/02 15:45:45 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Adobe
[2011/12/02 15:45:32 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Google
[2011/12/02 15:34:11 | 000,000,000 | -H-D | C] – C:\Users\Angie\Documents\My Google Gadgets
[2011/12/02 15:33:54 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Local\Google
[2011/12/02 15:33:53 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Symantec
[2011/12/02 15:33:49 | 000,000,000 | RH-D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/12/02 15:33:49 | 000,000,000 | RH-D | C] – C:\Users\Angie\Searches
[2011/12/02 15:33:49 | 000,000,000 | RH-D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/12/02 15:33:42 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Identities
[2011/12/02 15:33:41 | 000,000,000 | RH-D | C] – C:\Users\Angie\Contacts
[2011/12/02 15:33:15 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Local\VirtualStore
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\AppData\Local\Temporary Internet Files
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Templates
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Start Menu
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\SendTo
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Recent
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\PrintHood
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\NetHood
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Documents\My Videos
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Documents\My Pictures
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Documents\My Music
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\My Documents
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Local Settings
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\AppData\Local\History
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Cookies
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Application Data
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\AppData\Local\Application Data
[2011/12/02 15:33:10 | 000,000,000 | –SD | C] – C:\Users\Angie\AppData\Roaming\Microsoft
[2011/12/02 15:33:10 | 000,000,000 | RH-D | C] – C:\Users\Angie\Videos
[2011/12/02 15:33:10 | 000,000,000 | RH-D | C] – C:\Users\Angie\Saved Games
[2011/12/02 15:33:10 | 000,000,000 | RH-D | C] – C:\Users\Angie\Pictures
[2011/12/02 15:33:10 | 000,000,000 | RH-D | C] – C:\Users\Angie\Music
[2011/12/02 15:33:10 | 000,000,000 | RH-D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/12/02 15:33:10 | 000,000,000 | RH-D | C] – C:\Users\Angie\Links
[2011/12/02 15:33:10 | 000,000,000 | RH-D | C] – C:\Users\Angie\Favorites
[2011/12/02 15:33:10 | 000,000,000 | RH-D | C] – C:\Users\Angie\Downloads
[2011/12/02 15:33:10 | 000,000,000 | RH-D | C] – C:\Users\Angie\Documents
[2011/12/02 15:33:10 | 000,000,000 | RH-D | C] – C:\Users\Angie\Desktop
[2011/12/02 15:33:10 | 000,000,000 | RH-D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/12/02 15:33:10 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Local\Temp
[2011/12/02 15:33:10 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Mozilla
[2011/12/02 15:33:10 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Local\Microsoft Help
[2011/12/02 15:33:10 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Local\Microsoft
[2011/12/02 15:33:10 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Media Center Programs
[2011/12/02 15:33:10 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Power2Go
[2011/12/02 15:33:10 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink LabelPrint
[2011/12/02 15:33:10 | 000,000,000 | -H-D | C] – C:\Users\Angie\AppData
[2011/11/19 16:22:11 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2009/06/13 12:44:06 | 000,438,272 | —- | C] ( ) – C:\Windows\System32\LXDWhcp.dll
[2009/06/13 12:44:04 | 000,364,544 | —- | C] ( ) – C:\Windows\System32\lxdwinpa.dll
[2009/06/13 12:44:04 | 000,339,968 | —- | C] ( ) – C:\Windows\System32\lxdwiesc.dll
[2009/06/13 12:44:03 | 000,851,968 | —- | C] ( ) – C:\Windows\System32\lxdwusb1.dll
[2009/06/13 12:44:02 | 001,069,056 | —- | C] ( ) – C:\Windows\System32\lxdwserv.dll
[2009/06/13 12:44:01 | 000,651,264 | —- | C] ( ) – C:\Windows\System32\lxdwpmui.dll
[2009/06/13 12:44:00 | 000,577,536 | —- | C] ( ) – C:\Windows\System32\lxdwlmpm.dll
[2009/06/13 12:43:58 | 000,328,360 | —- | C] ( ) – C:\Windows\System32\lxdwih.exe
[2009/06/13 12:43:57 | 000,679,936 | —- | C] ( ) – C:\Windows\System32\lxdwhbn3.dll
[2009/06/13 12:43:54 | 000,594,600 | —- | C] ( ) – C:\Windows\System32\lxdwcoms.exe
[2009/06/13 12:43:54 | 000,376,832 | —- | C] ( ) – C:\Windows\System32\lxdwcomm.dll
[2009/06/13 12:43:53 | 000,765,952 | —- | C] ( ) – C:\Windows\System32\lxdwcomc.dll
[2009/06/13 12:43:52 | 000,369,320 | —- | C] ( ) – C:\Windows\System32\lxdwcfg.exe
[76 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[76 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/06 10:10:49 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/06 10:09:37 | 000,604,264 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/12/06 10:09:37 | 000,103,964 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/12/06 10:02:15 | 000,000,000 | —- | M] () – C:\Windows\System32\LogConfigTemp.xml
[2011/12/06 10:02:04 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/06 10:02:04 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/06 10:02:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/06 10:01:56 | 3085,389,824 | -HS- | M] () – C:\hiberfil.sys
[2011/12/05 16:55:01 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/03 21:37:44 | 000,388,608 | -H– | M] (Trend Micro Inc.) – C:\Users\Angie\HijackThis.exe
[2011/12/02 21:03:12 | 000,000,627 | -H– | M] () – C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
[2011/12/02 16:16:15 | 000,000,456 | -H– | M] () – C:\ProgramData\5ahi3Vz8hQfzHR
[2011/12/02 16:15:16 | 000,000,272 | -H– | M] () – C:\ProgramData\~5ahi3Vz8hQfzHR
[2011/12/02 16:15:16 | 000,000,184 | -H– | M] () – C:\ProgramData\~5ahi3Vz8hQfzHRr
[2011/12/02 16:15:08 | 000,000,603 | -H– | M] () – C:\Users\Angie\Desktop\System Fix.lnk
[2011/12/02 16:15:01 | 000,352,904 | -H– | M] () – C:\ProgramData\5ahi3Vz8hQfzHR.exe
[2011/12/02 16:12:44 | 000,001,113 | -H– | M] () – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2011/12/02 16:09:35 | 000,445,576 | -H– | M] () – C:\ProgramData\GBWXufOsmTrrX.exe
[2011/12/02 15:33:50 | 000,000,951 | -H– | M] () – C:\Users\Angie\Desktop\Internet Explorer.lnk
[2011/12/02 15:33:12 | 000,000,632 | RHS- | M] () – C:\Users\Angie\ntuser.pol
[76 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[76 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/02 22:10:47 | 3085,389,824 | -HS- | C] () – C:\hiberfil.sys
[2011/12/02 16:15:16 | 000,000,272 | -H– | C] () – C:\ProgramData\~5ahi3Vz8hQfzHR
[2011/12/02 16:15:16 | 000,000,184 | -H– | C] () – C:\ProgramData\~5ahi3Vz8hQfzHRr
[2011/12/02 16:15:08 | 000,000,627 | -H– | C] () – C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
[2011/12/02 16:15:08 | 000,000,603 | -H– | C] () – C:\Users\Angie\Desktop\System Fix.lnk
[2011/12/02 16:15:07 | 000,000,456 | -H– | C] () – C:\ProgramData\5ahi3Vz8hQfzHR
[2011/12/02 16:15:01 | 000,352,904 | -H– | C] () – C:\ProgramData\5ahi3Vz8hQfzHR.exe
[2011/12/02 16:12:44 | 000,001,113 | -H– | C] () – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2011/12/02 16:12:36 | 000,445,576 | -H– | C] () – C:\ProgramData\GBWXufOsmTrrX.exe
[2011/12/02 15:33:50 | 000,000,951 | -H– | C] () – C:\Users\Angie\Desktop\Internet Explorer.lnk
[2011/12/02 15:33:48 | 000,000,946 | -H– | C] () – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2011/12/02 15:33:41 | 000,000,917 | -H– | C] () – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2011/12/02 15:33:12 | 000,000,632 | RHS- | C] () – C:\Users\Angie\ntuser.pol
[2011/08/13 11:22:41 | 000,001,147 | —- | C] () – C:\Windows\wininit.ini
[2009/08/16 17:39:08 | 000,000,016 | —- | C] () – C:\Windows\popcinfo.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/06/13 12:52:46 | 000,360,448 | —- | C] () – C:\Windows\System32\lxdwcoin.dll
[2009/06/13 12:49:36 | 000,040,960 | —- | C] () – C:\Windows\System32\lxdwvs.dll
[2009/06/13 12:47:36 | 000,081,920 | —- | C] () – C:\Windows\System32\lxdwcaps.dll
[2009/06/13 12:47:35 | 001,036,288 | —- | C] () – C:\Windows\System32\lxdwdrs.dll
[2009/06/13 12:47:35 | 000,069,632 | —- | C] () – C:\Windows\System32\lxdwcnv4.dll
[2009/06/13 12:46:20 | 000,000,044 | —- | C] () – C:\Windows\System32\lxdwrwrd.ini
[2009/06/13 12:44:07 | 000,389,120 | —- | C] () – C:\Windows\System32\LXDWinst.dll
[2009/06/13 12:43:57 | 000,208,896 | —- | C] () – C:\Windows\System32\lxdwgrd.dll
[2009/03/06 02:23:49 | 000,487,424 | —- | C] () – C:\Windows\System32\INT15.dll
[2009/03/06 02:16:19 | 000,003,948 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2009/01/20 01:14:29 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/01/20 01:14:29 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2006/11/22 17:16:18 | 000,003,612 | —- | C] () – C:\Windows\ReaderString.ini
[2006/11/21 13:50:06 | 000,000,037 | —- | C] () – C:\Windows\sunkist.ini
[2006/11/02 07:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,295,896 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,604,264 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,103,964 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2010/11/20 21:37:07 | 000,000,000 | —D | M] – C:\Users\Desiree Amezquita\AppData\Roaming\WildTangent
[2010/05/15 18:26:19 | 000,000,000 | —D | M] – C:\Users\Xiamara Amezquita\AppData\Roaming\Archibald's Adventures
[2010/05/15 17:49:56 | 000,000,000 | —D | M] – C:\Users\Xiamara Amezquita\AppData\Roaming\freshgames
[2010/07/19 13:37:22 | 000,000,000 | —D | M] – C:\Users\Xiamara Amezquita\AppData\Roaming\Gaijin Ent
[2010/01/31 16:59:40 | 000,000,000 | —D | M] – C:\Users\Xiamara Amezquita\AppData\Roaming\Gamelab
[2010/05/15 13:51:07 | 000,000,000 | —D | M] – C:\Users\Xiamara Amezquita\AppData\Roaming\Happyville__
[2009/08/30 19:20:09 | 000,000,000 | —D | M] – C:\Users\Xiamara Amezquita\AppData\Roaming\Ludia
[2010/07/19 13:21:08 | 000,000,000 | —D | M] – C:\Users\Xiamara Amezquita\AppData\Roaming\Mean Hamster Software
[2010/01/30 16:36:57 | 000,000,000 | —D | M] – C:\Users\Xiamara Amezquita\AppData\Roaming\MysteryStudio
[2009/08/16 16:11:11 | 000,000,000 | —D | M] – C:\Users\Xiamara Amezquita\AppData\Roaming\PlayFirst
[2009/06/25 16:33:40 | 000,000,000 | —D | M] – C:\Users\Xiamara Amezquita\AppData\Roaming\WildTangent
[2011/12/06 10:00:28 | 000,032,544 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/20 21:24:42 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2009/01/20 00:45:59 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2006/12/07 14:24:36 | 000,241,664 | —- | M] (Alcor Micro, Corp.) – C:\EMicon.dll
[2011/12/06 10:01:56 | 3085,389,824 | -HS- | M] () – C:\hiberfil.sys
[2009/01/20 02:18:06 | 000,000,165 | —- | M] () – C:\Labelprint.log
[2011/10/28 14:46:13 | 000,000,086 | —- | M] () – C:\lxdwjswx.log
[2011/12/06 10:01:54 | 3399,233,536 | -HS- | M] () – C:\pagefile.sys
[2009/01/20 02:04:11 | 000,000,426 | —- | M] () – C:\RHDSetup.log

< %systemroot%\Fonts\*.com >
[2006/11/02 07:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 07:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 07:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2008/05/16 10:06:55 | 000,121,856 | —- | M] () – C:\Windows\system32\spool\prtprocs\w32x86\lxdwdrpp.dll
[2006/10/26 22:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2008/12/05 01:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 21:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 22:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 22:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 22:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-06 15:12:45

< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2011/12/02 16:14:40 | 000,000,000 | -H-D | M] – C:\Users\Angie\..\Angie\AppData\Local\Temp\smtmp
[2011/12/02 16:14:40 | 000,000,000 | -H-D | M] – C:\Users\Angie\..\Angie\AppData\Local\Temp\smtmp\1
[2011/12/02 21:03:05 | 000,000,000 | -H-D | M] – C:\Users\Angie\..\Angie\AppData\Local\Temp\smtmp\2
[2011/12/02 16:14:40 | 000,000,000 | -H-D | M] – C:\Users\Angie\..\Angie\AppData\Local\Temp\smtmp\4
[2011/11/19 16:08:02 | 000,000,000 | —D | M] – C:\Users\Angie\..\Xiamara Amezquita\AppData\Local\Temp\smtmp
[2011/11/19 16:08:01 | 000,000,000 | —D | M] – C:\Users\Angie\..\Xiamara Amezquita\AppData\Local\Temp\smtmp\1
[2011/11/30 14:31:00 | 000,000,000 | —D | M] – C:\Users\Angie\..\Xiamara Amezquita\AppData\Local\Temp\smtmp\2
[2011/11/19 16:08:02 | 000,000,000 | —D | M] – C:\Users\Angie\..\Xiamara Amezquita\AppData\Local\Temp\smtmp\4

< %temp%\smtmp\*.* /s >
[2011/12/02 15:45:29 | 000,000,221 | -HS- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\2\desktop.ini
[2011/12/02 15:45:22 | 000,000,104 | -H– | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\2\Internet - Shortcut.lnk
[2011/12/02 15:45:29 | 000,000,945 | -H– | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\2\Launch Internet Explorer Browser.lnk
[2008/01/20 21:42:47 | 000,000,258 | -H– | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\2\Shows Desktop.lnk
[2011/12/02 16:15:08 | 000,000,627 | -H– | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\2\System Fix.lnk
[2008/01/20 21:42:47 | 000,000,240 | -H– | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\2\Window Switcher.lnk
[2009/01/20 02:07:42 | 000,000,370 | -HS- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\desktop.ini
[2009/06/12 20:29:48 | 000,001,527 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\eBay.lnk
[2009/06/25 16:33:35 | 000,002,009 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\eMachines Games.lnk
[2011/02/19 09:45:21 | 000,001,803 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\HP ePrintCenter - HP Officejet Pro 8500 A910.lnk
[2011/02/19 09:45:21 | 000,001,087 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\HP Officejet Pro 8500 A910 Scan.lnk
[2011/02/19 09:45:21 | 000,002,129 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\HP Officejet Pro 8500 A910.lnk
[2011/08/27 20:00:33 | 000,000,908 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\Malwarebytes' Anti-Malware.lnk
[2009/01/20 02:07:42 | 000,001,185 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\Microsoft Office - 60 Day Trial.lnk
[2009/06/13 11:24:20 | 000,001,006 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\Microsoft Works.lnk
[2009/01/20 02:12:10 | 000,001,761 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\Norton 360.lnk
[2011/02/19 09:45:21 | 000,001,092 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\Shop for Supplies - HP Officejet Pro 8500 A910.lnk
[2011/08/27 19:33:20 | 000,001,802 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\SUPERAntiSpyware Free Edition.lnk
[2010/11/14 17:59:32 | 000,001,226 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\Verizon Media Manager.lnk
[2010/10/18 17:27:40 | 000,000,861 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\VLC media player.lnk
[2011/08/06 10:02:42 | 000,001,946 | —- | M] () – C:\Users\Angie\AppData\Local\Temp\smtmp\4\Vz In-Home Agent.lnk


< MD5 for: EXPLORER.EXE >
[2008/10/29 01:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 22:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | -H– | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 21:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 21:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 07:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\en-US\explorer.exe.mui
[2006/11/02 07:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2011/12/06 10:11:45 | 000,305,212 | —- | M] () MD5=A8977CA8D8746D510DF04B5CC3F7FCBF – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: IEXPLORE.EXE >
[2010/09/08 12:30:52 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=02FF22F3AF0108DA2A563ABC9867049F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18527_none_2f536bb51a085bcf\iexplore.exe
[2009/10/27 08:11:33 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=03EF289E8F82CBC4E492658864C7C51A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22550_none_2fb594d03344a0e4\iexplore.exe
[2008/04/24 23:22:36 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=07ED775D6DB4BFA96D7CFB09EB228418 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16681_none_2d26424d1d17e8b7\iexplore.exe
[2009/12/18 07:28:58 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=115076DAD84312F3A51698C15BC39D39 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21184_none_2db2bdca3632ff3d\iexplore.exe
[2008/06/26 22:54:09 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=157F8DE991396C536820D7FA5C8DCF7D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16711_none_2d71f3a71cdf2247\iexplore.exe
[2008/02/21 21:44:11 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=182CAF7403705ACCB51211A761080B8F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20777_none_2dc0b0c03628049a\iexplore.exe
[2008/10/01 22:50:01 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=19403B64906C9EAC627E3C10847B0FDA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_2d4cb5b31cfa2a15\iexplore.exe
[2009/07/18 07:16:49 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1D5A01AA2DE47C052AF46D7EBCB003A3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16890_none_2d1a75e31d20e59f\iexplore.exe
[2009/07/18 16:39:09 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1D8163DBFECAEDB9C48C5F55084BC491 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18294_none_2f04b5b11a43dbec\iexplore.exe
[2009/04/24 11:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1F44940EF1D07D0BDAF80E55853DFBD0 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16851_none_2d46b5dd1cff8f32\iexplore.exe
[2010/03/09 11:56:18 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=259E27152180B895DF395ED3E412B90E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.17037_none_2d6231791cea1fc3\iexplore.exe
[2010/05/04 13:56:53 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=29A7F81290165264010B784A7D217561 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18470_none_2f16582d1a3738fc\iexplore.exe
[2009/04/11 01:27:44 | 000,636,080 | -H– | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2010/09/09 10:50:19 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3EF3476EF687FE18856A6148C6082452 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22760_none_2faac8b0334cb723\iexplore.exe
[2010/05/04 13:31:09 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=424CEA5CB5999B2A6A3ED643EA20C97F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22685_none_2f9a286433587091\iexplore.exe
[2010/12/20 10:42:20 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=4319F2A5C725D9E0B9E01744E02D32BE – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18565_none_2f262b711a2a98e5\iexplore.exe
[2008/06/26 20:41:30 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=4DBD95312B1C96C5285D38F1D748CD4D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20868_none_2dcc82dc361eff27\iexplore.exe
[2009/10/27 10:11:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16945_none_2d5588d71cf3d5c4\iexplore.exe
[2008/01/20 21:23:50 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2010/10/20 12:48:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=63E2F08404C9824C6CE6EE4A308B4083 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18542_none_2f38ca6b1a1d14fe\iexplore.exe
[2008/10/01 22:32:01 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=6655B851D9EEF7C83395EE52D551B448 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_2df6c42835ff7333\iexplore.exe
[2010/03/11 11:40:22 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=67C769016A79E6FC65D1755E5D6ADAB3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22653_none_2fb897943341ea10\iexplore.exe
[2009/12/18 10:42:45 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=6C8AC3469BBEFE194BB18B2D84D98252 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18385_none_2f1087cd1a3ad679\iexplore.exe
[2011/04/21 09:34:57 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=6C93AC7C0A8718E2A1543DB1B1B3B19F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22905_none_2ff0ad763317887e\iexplore.exe
[2010/03/09 11:30:03 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=74E60C93D1C9A40354D839776CCF53DF – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18444_none_2f3ac9191a1b4a85\iexplore.exe
[2011/04/21 10:02:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=77B9A891222FB46B13E414B99E1AF842 – C:\Program Files\Internet Explorer\iexplore.exe
[2011/04/21 10:02:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=77B9A891222FB46B13E414B99E1AF842 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18639_none_2f4a9e431a0ea795\iexplore.exe
[2009/10/27 08:24:29 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=79B60CC26404F8FC2B351A7551D93C17 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18349_none_2f3fc8a51a16cc11\iexplore.exe
[2009/07/18 07:16:45 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=7FCF4E704A48D95202F3E7A1E1A21412 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21089_none_2db7bd56362e80c9\iexplore.exe
[2009/10/27 08:22:34 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21148_none_2de1fea2360ef4d5\iexplore.exe
[2010/06/28 11:33:13 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=867D06F3C473F65921F5EDF35866FF14 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22720_none_2fd60860332c475f\iexplore.exe
[2008/02/20 23:43:03 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9437CA21CD48C9B6BFD6F5AC0143D251 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16643_none_2d5382911cf5aba1\iexplore.exe
[2010/03/09 11:32:31 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=97496AA4590CB101EF990060F7055F3D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21242_none_2ddbfecc361459f2\iexplore.exe
[2009/08/27 09:04:53 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=9E45866CD349219784CD5A7620DBEB8A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16916_none_2d76f8e51cda9b48\iexplore.exe
[2008/04/24 21:04:08 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9F1427F203CA078005C9943800929640 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20823_none_2df2c11a360310b0\iexplore.exe
[2009/08/27 08:43:41 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=A76AFC309AA55CD607A28AC41C7D7603 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21116_none_2e006dd235f86e54\iexplore.exe
[2010/12/20 10:29:40 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B021EBF2A5344FF71A641B2EFDAF813E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22816_none_2fe6dbee331ec09f\iexplore.exe
[2010/06/28 11:19:40 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6D7D54B736056991109F169737592C7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18498_none_2f08baa51a403b96\iexplore.exe
[2009/08/27 08:38:13 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=BBF84F317553520BB78AEF7B047325C1 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18319_none_2f60386919fe783e\iexplore.exe
[2011/02/18 10:23:49 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=BECD30E162ACFD7A04B1F87FBBAFF70E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22857_none_2fbc9c88333e49ba\iexplore.exe
[2009/12/18 07:56:05 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=C071905121F6DE5F399550FC70138FEC – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16982_none_2d2748491d16f983\iexplore.exe
[2011/02/18 10:49:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C84ABBF7D7AF2F7D004D800D10430FF5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18602_none_2f640c0119fca261\iexplore.exe
[2009/04/24 11:03:18 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=D5271AC4A06AD9D1E2EA0151B79B2657 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21046_none_2ddffc283610c500\iexplore.exe
[2009/04/24 11:01:36 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=D6157423C117F24D24695866A1D0A93F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22418_none_2fe8d4ea331cfeb1\iexplore.exe
[2009/07/18 06:55:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=EBEE9E4421F35CD861107DDA0266FBB1 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22475_none_2fa4f48433505a52\iexplore.exe
[2010/10/21 13:50:10 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=ED748658B126A4617A4BA4A8F4F10DBE – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22784_none_2f992a0033595461\iexplore.exe
[2009/04/24 11:08:04 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=F294D8EEB05C835EC44A12CE0A1DFE7A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18248_none_2f3ec6751a17b593\iexplore.exe
[2009/12/18 07:27:08 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=F47755101C622AF18EE669ECEB3A97AD – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22585_none_2f9a267e3358736a\iexplore.exe
[2009/08/27 08:19:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=FE2DFF83B7753AC47C553EF7D5289BEE – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22508_none_2ff3a6bc3314dfe7\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2006/11/02 07:41:15 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2006/11/02 07:41:15 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-908C99F8.PF >
[2011/12/06 10:33:16 | 000,248,684 | —- | M] () MD5=4D81FE4E3D3CE19884C15810A2D74A54 – C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf

< MD5 for: WINLOGON.EXE >
[2009/04/11 01:28:13 | 000,314,368 | -H– | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 21:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\System32\winlogon.exe
[2008/01/20 21:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2008/01/20 21:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/20 21:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2006/11/02 07:40:50 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui

< MD5 for: WINLOGON.EXE-B020DC41.PF >
[2011/12/06 10:14:57 | 000,030,712 | —- | M] () MD5=5BBCA22FFFEE51F96FF0921B150EEFD6 – C:\Windows\Prefetch\WINLOGON.EXE-B020DC41.pf

< MD5 for: WINLOGON.MOF >
[2006/09/18 16:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\System32\wbem\winlogon.mof
[2006/09/18 16:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof

< >

< End of report >




my browser is windows 7
Hi litenbrite,

After these fixes make sure your icons are back and you can access your programs through start > all programs

Download RogueKiller to your desktop

  • Quit all running programs
  • right click roguekiller.ex and click "run as Administrator" to run it
  • When prompted, type 6 and validate
Your icons back?

Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O4 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002..\Run: [System Cleanup] C:\Windows\System32\winsett.exe File not found
O4 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002..\Run: [Windows Defragment] C:\Windows\winsett.exe File not found

:Files
xcopy "C:\Users\Angie\..\Xiamara Amezquita\AppData\Local\Temp\smtmp\1" "C:\ProgramData\Microsoft\Windows\Start Menu" /H /I /S /Y /C
xcopy "C:\Users\Angie\..\Xiamara Amezquita\AppData\Local\Temp\smtmp\2" "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C
xcopy "C:\Users\Angie\..\Xiamara Amezquita\AppData\Local\Temp\smtmp\4" "C:\Users\Public\Desktop" /H /I /S /Y /C
xcopy %Temp%\smtmp\1 "C:\ProgramData\Microsoft\Windows\Start Menu" /H /I /S /Y /C
xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C
xcopy %Temp%\smtmp\4 "C:\Users\Public\Desktop" /H /I /S /Y /C
C:\Windows\winsett.exe
C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
C:\ProgramData\5ahi3Vz8hQfzHR
C:\ProgramData\~5ahi3Vz8hQfzHR
C:\ProgramData\~5ahi3Vz8hQfzHRr
C:\Users\Angie\Desktop\System Fix.lnk
C:\ProgramData\5ahi3Vz8hQfzHR.exe
C:\ProgramData\GBWXufOsmTrrX.exe

:Commands
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log and the RogueKilller log.

Thanks
RogueKiller V6.1.12 [12/02/2011] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Started in : Normal mode
User: Angie [Admin rights]
Mode: Shortcuts HJfix – Date : 12/08/2011 20:32:46

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 3 / Fail 0
Quick launch: Success 6 / Fail 0
Programs: Success 78527 / Fail 2
Start menu: Success 37 / Fail 0
User folder: Success 2605 / Fail 0
My documents: Success 36 / Fail 0
My favorites: Success 23 / Fail 0
My pictures: Success 2 / Fail 0
My music: Success 2 / Fail 0
My videos: Success 2 / Fail 0
Local drives: Success 11171 / Fail 1
Backup: [FOUND] Success 21 / Fail 0

Drives:
[C:] \Device\HarddiskVolume2 – 0x3 –> Restored
[D:] \Device\CdRom0 – 0x5 –> Skipped
[F:] \Device\HarddiskVolume4 – 0x2 –> Restored
[G:] \Device\HarddiskVolume5 – 0x2 –> Restored
[H:] \Device\HarddiskVolume6 – 0x2 –> Restored
[I:] \Device\HarddiskVolume7 – 0x2 –> Restored

¤¤¤ Infection : Rogue.FakeHDD ¤¤¤

Finished : << RKreport[1].txt >>
RKreport[1].txt
OTL logfile created on: 12/8/2011 8:36:34 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = c:\Users\Xiamara Amezquita\Contacts
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.18 Gb Available Physical Memory | 41.08% Memory free
5.95 Gb Paging File | 4.22 Gb Available in Paging File | 70.87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.09 Gb Total Space | 210.55 Gb Free Space | 73.09% Space Free | Partition Type: NTFS

Computer Name: ANGELIQUE-PC | User Name: Angie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - c:\Users\Xiamara Amezquita\Contacts\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe (Verizon)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Microsoft\BingBar\BingBar.exe (Microsoft Corporation.)
PRC - C:\Program Files\Microsoft\BingBar\BingApp.exe (Microsoft Corporation.)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\verizon\McciTrayApp.exe (Alcatel-Lucent)
PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
PRC - C:\Program Files\Lexmark 7600 Series\ezprint.exe (Lexmark International Inc.)
PRC - C:\Program Files\Lexmark 7600 Series\lxdwmon.exe ()
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe ()
PRC - C:\Windows\System32\spool\drivers\w32x86\3\lxdwjswx.exe ()
PRC - C:\Windows\System32\spool\drivers\w32x86\3\lxdwpswx.exe ()
PRC - C:\Windows\System32\lxdwcoms.exe ( )
PRC - C:\Windows\System32\spool\drivers\w32x86\3\lxdwserv.exe (Lexmark International, Inc.)
PRC - c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Google\Google Desktop Search\gzlib.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwmon.exe ()
MOD - C:\Program Files\Lexmark Printable Web\resource.dll ()
MOD - C:\Program Files\Lexmark Printable Web\bho.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwcaps.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwscw.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwdrs.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\iptk.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwdatr.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwcnv4.dll ()
MOD - C:\Program Files\Lexmark 7600 Series\lxdwptp.dll ()


========== Win32 Services (SafeList) ==========

SRV - (IHA_MessageCenter) – C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe (Verizon)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (LiveUpdate Notice) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (LiveUpdate) – c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (ETService) – C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe ()
SRV - (lxdw_device) – C:\Windows\System32\lxdwcoms.exe ( )
SRV - (lxdwCATSCustConnectService) – C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxdwserv.exe ()
SRV - (Automatic LiveUpdate Scheduler) – c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (comHost) – c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20090815.019\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20090815.019\NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\ipsdefs\20090811.002\IDSvix86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (SYMNDISV) – C:\Windows\System32\Drivers\SYMNDISV.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMFW) – C:\Windows\System32\Drivers\SYMFW.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMDNS) – C:\Windows\System32\Drivers\SYMDNS.SYS (Symantec Corporation)
DRV - (COH_Mon) – C:\Windows\System32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (int15) – C:\Windows\System32\drivers\int15.sys (Acer, Inc.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (CO_Mon) – C:\Windows\System32\drivers\CO_Mon.sys (Symantec Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…amp;m=et1161-07
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…amp;m=et1161-07

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…amp;m=et1161-07
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\2.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyWebSearch\bar\2.bin


O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Reg Error: Value error.) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (NetAssistant) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\Freeze.com\NetAssistant\NetAssistant.dll (W3i, LLC)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 7600 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [lxdwmon.exe] C:\Program Files\Lexmark 7600 Series\lxdwmon.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [osCheck] c:\Program Files\Norton 360\osCheck.exe (Symantec Corporation)
O4 - HKLM..\Run: [P2Go_Menu] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKLM..\RunOnce: [*WerKernelReporting] C:\Windows\System32\WerFault.exe (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…NPUplden-us.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B1D990A1-3302-4B1F-B3A2-DB0FC3575EB6}: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O29 - HKLM SecurityProviders - (credssp.dll) -credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

[CREATERESTOREPOINT]
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/08 20:30:11 | 000,000,000 | —D | C] – C:\Users\Angie\Desktop\RK_Quarantine
[2011/12/03 22:06:10 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Angie\HijackThis.exe
[2011/12/02 21:19:18 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Roaming\Malwarebytes
[2011/12/02 16:12:44 | 000,000,000 | —D | C] – C:\Users\Angie\Documents\OneNote Notebooks
[2011/12/02 16:11:57 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Roaming\Yahoo!
[2011/12/02 15:48:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/12/02 15:48:40 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2011/12/02 15:46:12 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Roaming\Macromedia
[2011/12/02 15:45:45 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Roaming\Adobe
[2011/12/02 15:45:32 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Roaming\Google
[2011/12/02 15:34:11 | 000,000,000 | —D | C] – C:\Users\Angie\Documents\My Google Gadgets
[2011/12/02 15:33:54 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Local\Google
[2011/12/02 15:33:53 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Roaming\Symantec
[2011/12/02 15:33:49 | 000,000,000 | R–D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/12/02 15:33:49 | 000,000,000 | R–D | C] – C:\Users\Angie\Searches
[2011/12/02 15:33:49 | 000,000,000 | R–D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/12/02 15:33:42 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Roaming\Identities
[2011/12/02 15:33:41 | 000,000,000 | R–D | C] – C:\Users\Angie\Contacts
[2011/12/02 15:33:15 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Local\VirtualStore
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\AppData\Local\Temporary Internet Files
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Templates
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Start Menu
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\SendTo
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Recent
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\PrintHood
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\NetHood
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Documents\My Videos
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Documents\My Pictures
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Documents\My Music
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\My Documents
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Local Settings
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\AppData\Local\History
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Cookies
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\Application Data
[2011/12/02 15:33:11 | 000,000,000 | -HSD | C] – C:\Users\Angie\AppData\Local\Application Data
[2011/12/02 15:33:10 | 000,000,000 | –SD | C] – C:\Users\Angie\AppData\Roaming\Microsoft
[2011/12/02 15:33:10 | 000,000,000 | R–D | C] – C:\Users\Angie\Videos
[2011/12/02 15:33:10 | 000,000,000 | R–D | C] – C:\Users\Angie\Saved Games
[2011/12/02 15:33:10 | 000,000,000 | R–D | C] – C:\Users\Angie\Pictures
[2011/12/02 15:33:10 | 000,000,000 | R–D | C] – C:\Users\Angie\Music
[2011/12/02 15:33:10 | 000,000,000 | R–D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/12/02 15:33:10 | 000,000,000 | R–D | C] – C:\Users\Angie\Links
[2011/12/02 15:33:10 | 000,000,000 | R–D | C] – C:\Users\Angie\Favorites
[2011/12/02 15:33:10 | 000,000,000 | R–D | C] – C:\Users\Angie\Downloads
[2011/12/02 15:33:10 | 000,000,000 | R–D | C] – C:\Users\Angie\Documents
[2011/12/02 15:33:10 | 000,000,000 | R–D | C] – C:\Users\Angie\Desktop
[2011/12/02 15:33:10 | 000,000,000 | R–D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/12/02 15:33:10 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Local\Temp
[2011/12/02 15:33:10 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Roaming\Mozilla
[2011/12/02 15:33:10 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Local\Microsoft Help
[2011/12/02 15:33:10 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Local\Microsoft
[2011/12/02 15:33:10 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Roaming\Media Center Programs
[2011/12/02 15:33:10 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Power2Go
[2011/12/02 15:33:10 | 000,000,000 | —D | C] – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink LabelPrint
[2011/12/02 15:33:10 | 000,000,000 | —D | C] – C:\Users\Angie\AppData
[2011/11/19 16:22:11 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2009/06/13 12:44:06 | 000,438,272 | —- | C] ( ) – C:\Windows\System32\LXDWhcp.dll
[2009/06/13 12:44:04 | 000,364,544 | —- | C] ( ) – C:\Windows\System32\lxdwinpa.dll
[2009/06/13 12:44:04 | 000,339,968 | —- | C] ( ) – C:\Windows\System32\lxdwiesc.dll
[2009/06/13 12:44:03 | 000,851,968 | —- | C] ( ) – C:\Windows\System32\lxdwusb1.dll
[2009/06/13 12:44:02 | 001,069,056 | —- | C] ( ) – C:\Windows\System32\lxdwserv.dll
[2009/06/13 12:44:01 | 000,651,264 | —- | C] ( ) – C:\Windows\System32\lxdwpmui.dll
[2009/06/13 12:44:00 | 000,577,536 | —- | C] ( ) – C:\Windows\System32\lxdwlmpm.dll
[2009/06/13 12:43:58 | 000,328,360 | —- | C] ( ) – C:\Windows\System32\lxdwih.exe
[2009/06/13 12:43:57 | 000,679,936 | —- | C] ( ) – C:\Windows\System32\lxdwhbn3.dll
[2009/06/13 12:43:54 | 000,594,600 | —- | C] ( ) – C:\Windows\System32\lxdwcoms.exe
[2009/06/13 12:43:54 | 000,376,832 | —- | C] ( ) – C:\Windows\System32\lxdwcomm.dll
[2009/06/13 12:43:53 | 000,765,952 | —- | C] ( ) – C:\Windows\System32\lxdwcomc.dll
[2009/06/13 12:43:52 | 000,369,320 | —- | C] ( ) – C:\Windows\System32\lxdwcfg.exe
[78 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[78 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/08 19:55:04 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/08 19:47:45 | 000,604,264 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/12/08 19:47:45 | 000,103,964 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/12/08 19:46:59 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/08 19:40:42 | 000,000,000 | —- | M] () – C:\Windows\System32\LogConfigTemp.xml
[2011/12/08 19:40:36 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/08 19:40:36 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/08 19:40:30 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/08 19:40:26 | 3085,406,208 | -HS- | M] () – C:\hiberfil.sys
[2011/12/03 21:37:44 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Angie\HijackThis.exe
[2011/12/02 16:16:15 | 000,000,456 | —- | M] () – C:\ProgramData\5ahi3Vz8hQfzHR
[2011/12/02 16:15:16 | 000,000,272 | -H– | M] () – C:\ProgramData\~5ahi3Vz8hQfzHR
[2011/12/02 16:15:16 | 000,000,184 | -H– | M] () – C:\ProgramData\~5ahi3Vz8hQfzHRr
[2011/12/02 16:15:08 | 000,000,627 | —- | M] () – C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
[2011/12/02 16:12:44 | 000,001,113 | —- | M] () – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2011/12/02 16:09:35 | 000,445,576 | —- | M] () – C:\ProgramData\GBWXufOsmTrrX.exe
[2011/12/02 15:45:29 | 000,000,945 | —- | M] () – C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/02 15:45:22 | 000,000,104 | —- | M] () – C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet - Shortcut.lnk
[2011/12/02 15:33:50 | 000,000,951 | —- | M] () – C:\Users\Angie\Desktop\Internet Explorer.lnk
[2011/12/02 15:33:12 | 000,000,632 | R-S- | M] () – C:\Users\Angie\ntuser.pol
[78 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[78 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/08 20:30:54 | 000,002,129 | —- | C] () – C:\Users\Public\Desktop\HP Officejet Pro 8500 A910.lnk
[2011/12/08 20:30:54 | 000,002,009 | —- | C] () – C:\Users\Public\Desktop\eMachines Games.lnk
[2011/12/08 20:30:54 | 000,001,946 | —- | C] () – C:\Users\Public\Desktop\Vz In-Home Agent.lnk
[2011/12/08 20:30:54 | 000,001,803 | —- | C] () – C:\Users\Public\Desktop\HP ePrintCenter - HP Officejet Pro 8500 A910.lnk
[2011/12/08 20:30:54 | 000,001,802 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/12/08 20:30:54 | 000,001,761 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2011/12/08 20:30:54 | 000,001,527 | —- | C] () – C:\Users\Public\Desktop\eBay.lnk
[2011/12/08 20:30:54 | 000,001,226 | —- | C] () – C:\Users\Public\Desktop\Verizon Media Manager.lnk
[2011/12/08 20:30:54 | 000,001,185 | —- | C] () – C:\Users\Public\Desktop\Microsoft Office - 60 Day Trial.lnk
[2011/12/08 20:30:54 | 000,001,092 | —- | C] () – C:\Users\Public\Desktop\Shop for Supplies - HP Officejet Pro 8500 A910.lnk
[2011/12/08 20:30:54 | 000,001,087 | —- | C] () – C:\Users\Public\Desktop\HP Officejet Pro 8500 A910 Scan.lnk
[2011/12/08 20:30:54 | 000,001,006 | —- | C] () – C:\Users\Public\Desktop\Microsoft Works.lnk
[2011/12/08 20:30:54 | 000,000,945 | —- | C] () – C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/08 20:30:54 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/08 20:30:54 | 000,000,861 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2011/12/08 20:30:54 | 000,000,627 | —- | C] () – C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
[2011/12/08 20:30:54 | 000,000,258 | —- | C] () – C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/12/08 20:30:54 | 000,000,240 | —- | C] () – C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/12/08 20:30:54 | 000,000,104 | —- | C] () – C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet - Shortcut.lnk
[2011/12/02 22:10:47 | 3085,406,208 | -HS- | C] () – C:\hiberfil.sys
[2011/12/02 16:15:16 | 000,000,272 | -H– | C] () – C:\ProgramData\~5ahi3Vz8hQfzHR
[2011/12/02 16:15:16 | 000,000,184 | -H– | C] () – C:\ProgramData\~5ahi3Vz8hQfzHRr
[2011/12/02 16:15:07 | 000,000,456 | —- | C] () – C:\ProgramData\5ahi3Vz8hQfzHR
[2011/12/02 16:12:44 | 000,001,113 | —- | C] () – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
[2011/12/02 16:12:36 | 000,445,576 | —- | C] () – C:\ProgramData\GBWXufOsmTrrX.exe
[2011/12/02 15:33:50 | 000,000,951 | —- | C] () – C:\Users\Angie\Desktop\Internet Explorer.lnk
[2011/12/02 15:33:48 | 000,000,946 | —- | C] () – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2011/12/02 15:33:41 | 000,000,917 | —- | C] () – C:\Users\Angie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2011/12/02 15:33:12 | 000,000,632 | R-S- | C] () – C:\Users\Angie\ntuser.pol
[2011/08/13 11:22:41 | 000,001,147 | —- | C] () – C:\Windows\wininit.ini
[2009/08/16 17:39:08 | 000,000,016 | —- | C] () – C:\Windows\popcinfo.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/06/13 12:52:46 | 000,360,448 | —- | C] () – C:\Windows\System32\lxdwcoin.dll
[2009/06/13 12:49:36 | 000,040,960 | —- | C] () – C:\Windows\System32\lxdwvs.dll
[2009/06/13 12:47:36 | 000,081,920 | —- | C] () – C:\Windows\System32\lxdwcaps.dll
[2009/06/13 12:47:35 | 001,036,288 | —- | C] () – C:\Windows\System32\lxdwdrs.dll
[2009/06/13 12:47:35 | 000,069,632 | —- | C] () – C:\Windows\System32\lxdwcnv4.dll
[2009/06/13 12:46:20 | 000,000,044 | —- | C] () – C:\Windows\System32\lxdwrwrd.ini
[2009/06/13 12:44:07 | 000,389,120 | —- | C] () – C:\Windows\System32\LXDWinst.dll
[2009/06/13 12:43:57 | 000,208,896 | —- | C] () – C:\Windows\System32\lxdwgrd.dll
[2009/03/06 02:23:49 | 000,487,424 | —- | C] () – C:\Windows\System32\INT15.dll
[2009/03/06 02:16:19 | 000,003,948 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2009/01/20 01:14:29 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/01/20 01:14:29 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2006/11/22 17:16:18 | 000,003,612 | —- | C] () – C:\Windows\ReaderString.ini
[2006/11/21 13:50:06 | 000,000,037 | —- | C] () – C:\Windows\sunkist.ini
[2006/11/02 07:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,295,896 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,604,264 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,103,964 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== Custom Scans ==========


< :Services >

< >

< :OTL >

< O4 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002..\Run: [System Cleanup] C:\Windows\System32\winsett.exe File not found >

< O4 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002..\Run: [Windows Defragment] C:\Windows\winsett.exe File not found >

< >

< :Files >

< xcopy "C:\Users\Angie\..\Xiamara Amezquita\AppData\Local\Temp\smtmp\1" "C:\ProgramData\Microsoft\Windows\Start Menu" /H /I /S /Y /C >
0 File(s) copied

< xcopy "C:\Users\Angie\..\Xiamara Amezquita\AppData\Local\Temp\smtmp\2" "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C >
0 File(s) copied

< xcopy "C:\Users\Angie\..\Xiamara Amezquita\AppData\Local\Temp\smtmp\4" "C:\Users\Public\Desktop" /H /I /S /Y /C >
0 File(s) copied

< xcopy %Temp%\smtmp\1 "C:\ProgramData\Microsoft\Windows\Start Menu" /H /I /S /Y /C >
0 File(s) copied

< xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C >
C:\Users\Angie\AppData\Local\Temp\SMTMP\2\desktop.ini
C:\Users\Angie\AppData\Local\Temp\SMTMP\2\Internet - Shortcut.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\2\Launch Internet Explorer Browser.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\2\Shows Desktop.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\2\System Fix.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\2\Window Switcher.lnk
6 File(s) copied

< xcopy %Temp%\smtmp\4 "C:\Users\Public\Desktop" /H /I /S /Y /C >
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\desktop.ini
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\eBay.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\eMachines Games.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\HP ePrintCenter - HP Officejet Pro 8500 A910.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\HP Officejet Pro 8500 A910 Scan.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\HP Officejet Pro 8500 A910.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\Malwarebytes' Anti-Malware.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\Microsoft Office - 60 Day Trial.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\Microsoft Works.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\Norton 360.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\Shop for Supplies - HP Officejet Pro 8500 A910.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\SUPERAntiSpyware Free Edition.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\Verizon Media Manager.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\VLC media player.lnk
C:\Users\Angie\AppData\Local\Temp\SMTMP\4\Vz In-Home Agent.lnk
15 File(s) copied

< C:\Windows\winsett.exe >

< C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk >
[2011/12/02 16:15:08 | 000,000,627 | —- | M] () – C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk

< C:\ProgramData\5ahi3Vz8hQfzHR >
[2011/12/02 16:16:15 | 000,000,456 | —- | M] () – C:\ProgramData\5ahi3Vz8hQfzHR
[78 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

< C:\ProgramData\~5ahi3Vz8hQfzHR >
[2011/12/02 16:15:16 | 000,000,272 | -H– | M] () – C:\ProgramData\~5ahi3Vz8hQfzHR
[78 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

< C:\ProgramData\~5ahi3Vz8hQfzHRr >
[2011/12/02 16:15:16 | 000,000,184 | -H– | M] () – C:\ProgramData\~5ahi3Vz8hQfzHRr
[78 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

< C:\Users\Angie\Desktop\System Fix.lnk >

< C:\ProgramData\5ahi3Vz8hQfzHR.exe >

< C:\ProgramData\GBWXufOsmTrrX.exe >
[2011/12/02 16:09:35 | 000,445,576 | —- | M] () – C:\ProgramData\GBWXufOsmTrrX.exe
[78 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

< >

< :Commands >

< >

< End of report >
Hi litenbrite,

Looks like you clicked the Run Scan button instead of the Run Fix button. Please run this fix.



Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O4 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002..\Run: [System Cleanup] C:\Windows\System32\winsett.exe File not found
O4 - HKU\S-1-5-21-1787382799-1039356036-4139006242-1002..\Run: [Windows Defragment] C:\Windows\winsett.exe File not found

:Files
C:\Windows\winsett.exe
C:\Users\Angie\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
C:\ProgramData\5ahi3Vz8hQfzHR
C:\ProgramData\~5ahi3Vz8hQfzHR
C:\ProgramData\~5ahi3Vz8hQfzHRr
C:\Users\Angie\Desktop\System Fix.lnk
C:\ProgramData\5ahi3Vz8hQfzHR.exe
C:\ProgramData\GBWXufOsmTrrX.exe

:Commands
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Are you able to access your programs from start > all programs?

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI