This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Sluggish Machine - svchost hogging

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

In explanation, in the past couple of days my machine has bogged down significantly. I has all the symptoms of my resources being hogged up by something unwanted. I checked the task manager and found one of my svchost.exe files to be using over 1G of RAM. I can end process, but it comes back after a while.

HERE is the OTL data.

OTL Extras logfile created on: 2/7/2012 11:29:23 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\mckimc\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.96 Gb Total Physical Memory | 1.15 Gb Available Physical Memory | 58.35% Memory free
5.80 Gb Paging File | 5.05 Gb Available in Paging File | 87.03% Paging File free
Paging file location(s): C:\pagefile.sys 4096 4096 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.79 Gb Total Space | 155.06 Gb Free Space | 66.61% Space Free | Partition Type: NTFS
Drive D: | 31.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 7.45 Gb Total Space | 5.89 Gb Free Space | 79.03% Space Free | Partition Type: FAT32
Drive H: | 203.25 Gb Total Space | 12.67 Gb Free Space | 6.23% Space Free | Partition Type: NTFS
Drive I: | 203.25 Gb Total Space | 12.67 Gb Free Space | 6.23% Space Free | Partition Type: NTFS
Drive J: | 558.37 Gb Total Space | 432.46 Gb Free Space | 77.45% Space Free | Partition Type: NTFS
Drive X: | 298.05 Gb Total Space | 215.52 Gb Free Space | 72.31% Space Free | Partition Type: NTFS
Drive Z: | 461.44 Gb Total Space | 446.87 Gb Free Space | 96.84% Space Free | Partition Type: NTFS

Computer Name: L82-PC40 | User Name: McKimc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with Corel PaintShop Photo Pro X3] – "c:\Program Files\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Corel Paint Shop Pro Photo.exe" "%L" (Corel, Inc.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"4481:TCP" = 4481:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4481:UDP" = 4481:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"4482:TCP" = 4482:TCP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync data transfer
"4482:UDP" = 4482:UDP:LocalSubNet:Enabled:BlackBerry Desktop Software Wireless Music Sync discovery
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"D:\DPCityCodeInstaller_EPHRATAPD.exe" = D:\DPCityCodeInstaller_EPHRATAPD.exe:*:Enabled:DPCityCodeInstaller Change Utility
"C:\WINDOWS\system32\Winet556.Exe" = C:\WINDOWS\system32\Winet556.Exe:*:Enabled:DPPlayer – ()
"C:\Program Files\Symantec AntiVirus\Smc.exe" = C:\Program Files\Symantec AntiVirus\Smc.exe:*:Enabled:SMC Service – (Symantec Corporation)
"C:\Program Files\Symantec AntiVirus\SNAC.EXE" = C:\Program Files\Symantec AntiVirus\SNAC.EXE:*:Enabled:SNAC Service – (Symantec Corporation)
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = C:\Program Files\Common Files\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email – (Symantec Corporation)
"C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc1.exe" = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc1.exe:*:Enabled:Bluetooth Information Exchanger – (TOSHIBA CORPORATION.)
"C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ECCenter1.exe" = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ECCenter1.exe:*:Enabled:Bluetooth Settings – (TOSHIBA CORPORATION.)
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe" = C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe:*:Enabled:BlackBerry Desktop Software – (Research In Motion)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{D1AEB5DB-04FA-489D-94EF-8600898B93EE}" = Corel PaintShop Photo Pro X3
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE 10.3
"{108A39BF-4ED1-4293-B11A-06BD521FB8F7}" = FreeOCR 3.0
"{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}" = BlackBerry Device Software Updater
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2E98C5B7-D64C-4D7E-BFC3-A7D078569F28}" = Broadcom NetXtreme-I Netlink Driver and Management Installer
"{2EFCC193-D915-4CCB-9201-31773A27BC06}" = Symantec Endpoint Protection
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{42C7B7B8-CA45-43A0-8315-57CD453ED9A9}" = NCICDisplay Plug-in 2.4
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D6E6E1A-59A6-46A1-A942-A7F1562BCF1D}" = instALERT Messaging Software
"{4DDC2527-0215-4402-80D8-0E902E0FA55B}" = SPEEDsentry Data Analysis
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{55EAE18D-83F1-4526-86B9-05FD89725AAF}" = BlackBerry Device Software v4.6.1 for the BlackBerry 8350i smartphone
"{58208743-CE87-4F1A-9F24-99EC23024FF9}" = PLC - Client install SQL
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72CD4C5F-AB0B-4814-8780-9A4F26A2086B}" = Presto! PageManager 7.12.10
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{75157F34-02C6-4831-BD66-3BC49E7A8394}" = BlackBerry Desktop Software 6.1
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FD245B2-8709-4D55-BC4A-F3A69EABF360}" = WaveReader Ver 4-2
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9EDA3DD1-130D-4EE1-A3D2-5A3D795CC8C9}" = MFCLOC
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8DD74DC-14C4-4BA0-8DF7-D84524D0B0D2}" = ST Microelectronics TPM Driver Installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC2DFAEA-D9D6-408D-9D49-D3D7E2BD7E09}" = Easy Street Draw Internet ActiveX Control 2.1
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AF7E4468-E364-4991-BC2A-6E8293E1055B}" = BioAPI Framework
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3F1CADF-F92D-4903-A9BD-EEC13A874D8B}" = SPEEDsentry Data Analysis
"{C3FA63E2-AFD3-41FD-B48F-1D942CC71943}" = UPEK TouchChip Fingerprint Reader
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D1612A3D-0DCC-4055-BB6A-0036F31158A0}" = Setup
"{D1AEB5DB-04FA-489D-94EF-8600898B93EE}" = ICA
"{D3BCC13A-E4F2-45EE-846F-D143CEDDDBCB}" = DeviceIO
"{D7D99A66-493F-468B-BCE1-6F88612B89D5}" = Contents
"{D84B7C7E-2E4D-4002-8CA8-EED4EDB333AC}" = MLE
"{D875FFEE-2FCE-4774-902A-749198C00A68}" = PureHD
"{D94ABC2B-5CA9-48B2-9266-15AB78384D3C}" = Share
"{D9C4FA35-7C6B-4C9E-863B-58C4D7472F41}" = VIO
"{DA4A2F61-1E26-4D51-94BB-36D77678BDAD}" = PSPH10Pro
"{DA4BF4BE-3CDC-43B5-BBDA-DDDA73103111}" = Corel PaintShop Photo Pro X3
"{DB286E99-3558-4799-8625-5E2442779D10}" = CAPSIT Open Scheduler
"{DCD941B6-F2E7-4FAF-B102-F7D4DE5FF99A}" = IPM_PSP_Pro
"{DCF1928A-FC01-48E7-A7E6-4651D42EF6A1}" = PSPPRO_DCRAW
"{DDDD0C4B-57F7-4A85-ACF0-DB3FC8F1DBB4}" = Dragon NaturallySpeaking 8
"{DF8B9311-ADE7-4EDE-B121-326CAA3D225D}" = PSPPContent
"{E06285BC-6933-42F6-8794-E3FB7FE4E445}" = DPFinder II
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E5A610D2-FA37-4793-9AA2-03E16D3D3129}" = Microsoft SAPI Redistributable Files
"{E8E75CEF-0783-421F-B939-B59D9087F762}" = OnSiteMSI
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE 10.3
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF1DDCF4-3A28-4F7F-96D8-E3F4BD1C1702}" = Dell Security Device Driver Pack
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"35858E766EFC35B58A45C301DD358D503119A8FA" = Windows Driver Package - STMicroelectronics (stmtpm) System (05/24/2007 1.00.04.15)
"9D57DE505B6D8C710EF3B74BE638DBB936EED8A3" = Windows Driver Package - Dell Inc. PBADRV System (01/07/2008 1.0.1.5)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"BDE" = BDE
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.1
"CommProvider" = CommProvider [removed]
"doPDF 7 printer_is1" = doPDF 7.1 printer
"DVR-Viewer" = DVR-Viewer
"ESD4.0.8.0" = Easy Street Draw 4
"Foxit Reader" = Foxit Reader
"Google Calendar Sync" = Google Calendar Sync
"GPL Ghostscript 8.71" = GPL Ghostscript 8.71
"HDMI" = Intel® Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"IMM4 Codec_is1" = IMM4 VCM Codec [removed]
"InterAct Mobile" = InterAct Mobile - 8.0
"InterAct Mobile State Forms" = InterAct Mobile State Forms
"IrfanView" = IrfanView (remove only)
"LAN-Fax Utilities" = LAN-Fax Utilities
"Lexmark 8300 Series" = Lexmark 8300 Series
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Message Center" = Message Center
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"RMS" = RMS
"SP6" = Logitech SetPoint 6.0
"Stellar Phoenix Photo Recovery_is1" = Stellar Phoenix Photo Recovery
"VLC media player" = VLC media player 1.1.11
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinPatrol" = WinPatrol 2008
"WinRAR archiver" = WinRAR archiver
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"SmartDraw 6" = SmartDraw 6

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/25/2011 4:18:17 PM | Computer Name = L82-PC40 | Source = Microsoft Office 11 | ID = 1000
Description =

Error - 1/27/2012 2:48:14 PM | Computer Name = L82-PC40 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office XP Professional with FrontPage – Error
1706. Setup cannot find the required files. Check your connection to the network,
or CD-ROM drive. For other potential solutions to this problem, see C:\Program
Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 1/27/2012 2:48:14 PM | Computer Name = L82-PC40 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office XP Professional with FrontPage - Update
'{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}' could not be installed. Error code 1603.
Windows Installer can create logs to help troubleshoot issues with installing software
packages. Use the following link for instructions on turning on logging support:
http://go.microsoft.com/fwlink/?LinkId=23127

Error - 2/2/2012 10:37:40 AM | Computer Name = L82-PC40 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office XP Professional with FrontPage – Error
1706. Setup cannot find the required files. Check your connection to the network,
or CD-ROM drive. For other potential solutions to this problem, see C:\Program
Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 2/2/2012 10:37:41 AM | Computer Name = L82-PC40 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office XP Professional with FrontPage - Update
'{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}' could not be installed. Error code 1603.
Windows Installer can create logs to help troubleshoot issues with installing software
packages. Use the following link for instructions on turning on logging support:
http://go.microsoft.com/fwlink/?LinkId=23127

Error - 2/6/2012 4:45:48 PM | Computer Name = L82-PC40 | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Tracking Cookies in File: Unavailable by: Manual
scan. Action: Quarantine failed : Leave Alone failed. Action Description: The
file was deleted successfully.

[ System Events ]
Error - 1/27/2012 10:22:26 AM | Computer Name = L82-PC40 | Source = Service Control Manager | ID = 7000
Description = The System Restore Service service failed to start due to the following
error: %%1079

Error - 1/27/2012 2:48:20 PM | Computer Name = L82-PC40 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8024002d: Office XP Service Pack 3.

Error - 1/30/2012 11:00:13 AM | Computer Name = L82-PC40 | Source = Service Control Manager | ID = 7000
Description = The System Restore Service service failed to start due to the following
error: %%1079

Error - 2/1/2012 4:18:40 AM | Computer Name = L82-PC40 | Source = Service Control Manager | ID = 7000
Description = The System Restore Service service failed to start due to the following
error: %%1079

Error - 2/2/2012 10:38:47 AM | Computer Name = L82-PC40 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8024002d: Office XP Service Pack 3.

Error - 2/6/2012 11:14:32 AM | Computer Name = L82-PC40 | Source = Service Control Manager | ID = 7000
Description = The System Restore Service service failed to start due to the following
error: %%1079

Error - 2/6/2012 12:21:30 PM | Computer Name = L82-PC40 | Source = Service Control Manager | ID = 7000
Description = The System Restore Service service failed to start due to the following
error: %%1079

Error - 2/6/2012 7:18:47 PM | Computer Name = L82-PC40 | Source = DCOM | ID = 10010
Description = The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register
with DCOM within the required timeout.

Error - 2/7/2012 10:35:26 AM | Computer Name = L82-PC40 | Source = Service Control Manager | ID = 7000
Description = The System Restore Service service failed to start due to the following
error: %%1079

Error - 2/7/2012 12:31:57 PM | Computer Name = L82-PC40 | Source = Service Control Manager | ID = 7000
Description = The System Restore Service service failed to start due to the following
error: %%1079


< End of report >


HERE is the second report

OTL logfile created on: 2/7/2012 11:29:23 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\mckimc\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.96 Gb Total Physical Memory | 1.15 Gb Available Physical Memory | 58.35% Memory free
5.80 Gb Paging File | 5.05 Gb Available in Paging File | 87.03% Paging File free
Paging file location(s): C:\pagefile.sys 4096 4096 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.79 Gb Total Space | 155.06 Gb Free Space | 66.61% Space Free | Partition Type: NTFS
Drive D: | 31.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 7.45 Gb Total Space | 5.89 Gb Free Space | 79.03% Space Free | Partition Type: FAT32
Drive H: | 203.25 Gb Total Space | 12.67 Gb Free Space | 6.23% Space Free | Partition Type: NTFS
Drive I: | 203.25 Gb Total Space | 12.67 Gb Free Space | 6.23% Space Free | Partition Type: NTFS
Drive J: | 558.37 Gb Total Space | 432.46 Gb Free Space | 77.45% Space Free | Partition Type: NTFS
Drive X: | 298.05 Gb Total Space | 215.52 Gb Free Space | 72.31% Space Free | Partition Type: NTFS
Drive Z: | 461.44 Gb Total Space | 446.87 Gb Free Space | 96.84% Space Free | Partition Type: NTFS

Computer Name: L82-PC40 | User Name: McKimc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\mckimc\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DoScan.exe (Symantec Corporation)
PRC - C:\Program Files\InterAct\CommProvider_V2\CommProviderConsole.exe (InterAct Public Safety.)
PRC - C:\WINDOWS\RTDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\WINDOWS\system32\lxcjcoms.exe ( )
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe ()
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
PRC - C:\Program Files\Lexmark 8300 Series\ezprint.exe (Lexmark International Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxcjhpec.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxcjflib.dll ()
MOD - C:\WINDOWS\system32\lxcjcnv4.dll ()
MOD - C:\Program Files\Lexmark 8300 Series\iptk.dll ()


========== Win32 Services (SafeList) ==========

SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec AntiVirus\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec AntiVirus\SNAC.EXE (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CommProvider) – C:\Program Files\InterAct\CommProvider_V2\CommProvider.exe (InterAct Public Safety.)
SRV - (LBTServ) – C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (PSI_SVC_2) – c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (lxcj_device) – C:\WINDOWS\System32\lxcjcoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\eengine\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20120206.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20120206.002\NAVENG.SYS (Symantec Corporation)
DRV - (WpsHelper) – C:\WINDOWS\system32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (WPS) – C:\WINDOWS\system32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SysPlant) – C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys (Symantec Corporation)
DRV - (Teefer2) – C:\WINDOWS\system32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (COH_Mon) – C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (k57w2k) Broadcom NetLink ™ – C:\WINDOWS\system32\drivers\k57xp32.sys (Broadcom Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtDHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Blfp) – C:\WINDOWS\system32\drivers\baspxp32.sys (Broadcom Corporation)
DRV - (PBADRV) – C:\WINDOWS\system32\DRIVERS\PBADRV.sys (Dell Inc)
DRV - (tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (TosRfSnd) – C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Help_Page = http://support.dell.com/support/index.aspx…;l=en&s;=gen
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USREL/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/sphome.aspx
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.msn.com/USREL/1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USREL/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/sphome.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "https://webcad.lcwc911.us/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.6.6.99999
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Oracle)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/01/16 10:35:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/19 11:55:54 | 000,000,000 | —D | M]

[2010/03/03 14:24:48 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\mckimc\Application Data\Mozilla\Extensions
[2011/12/28 12:48:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\mckimc\Application Data\Mozilla\Firefox\Profiles\ad2eyrmg.default\extensions
[2010/04/28 14:27:31 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\mckimc\Application Data\Mozilla\Firefox\Profiles\ad2eyrmg.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/12/28 12:48:53 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\mckimc\Application Data\Mozilla\Firefox\Profiles\ad2eyrmg.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/08/19 08:50:07 | 000,000,000 | —D | M] ("Foxit Toolbar") – C:\Documents and Settings\mckimc\Application Data\Mozilla\Firefox\Profiles\ad2eyrmg.default\extensions\[removed]
[2011/11/14 11:13:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\MCKIMC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\AD2EYRMG.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\MCKIMC\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\AD2EYRMG.DEFAULT\EXTENSIONS\[removed]
[2012/01/16 10:35:43 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/06/04 21:44:20 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/04/20 16:00:02 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2012/01/16 10:35:38 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/16 10:35:38 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2010/09/28 14:47:58 | 000,000,764 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 10.1.0.29 PSMobile
O1 - Hosts: 10.1.0.36 PREX
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [CommProviderConsole] C:\Program Files\InterAct\CommProvider_V2\CommProviderConsole.exe (InterAct Public Safety.)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark 8300 Series\ezprint.exe (Lexmark International Inc.)
O4 - HKLM..\Run: [LXCJCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.DLL (Lexmark International Inc.)
O4 - HKLM..\Run: [lxcjmon.exe] C:\Program Files\Lexmark 8300 Series\lxcjmon.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKLM..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKLM..\RunOnce\Setup: [Registering InterVideo Audio Decoder…] C:\WINDOWS\system32\iviaudio.ax (InterVideo Inc.)
O4 - HKLM..\RunOnce\Setup: [Registering MPEG Audio Codec…] C:\WINDOWS\system32\mpgaudio.ax (MyCompanyName)
O4 - HKLM..\RunOnce\Setup: [Registering MS MPEG4 ActiveX filter…] C:\WINDOWS\system32\MPG4ds32.ax (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\mckimc\Start Menu\Programs\Startup\Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} http://www.logitech.com/devicedetector/plu…Detection32.cab (Device Detection)
O16 - DPF: {2C9374C3-016C-48FD-A3BA-2CC2AC061AEF} http://www.dot6.state.pa.us/esdinstall/ESD4/esd4x.cab (ESD Internet Control 4.0)
O16 - DPF: {460324E8-CFB4-4357-85EF-CE3EBFE23A62} https://reports.jnet.state.pa.us/crystalrep…tiveXViewer.cab (Crystal ActiveX Report Viewer Control 11.0)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {B1D475FE-75CD-11D2-8301-0060B0B32E16} https://certificate.jnet.state.pa.us/enroll/vsimport.cab (ImpPKCS12 Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {DF1EF9A5-EF1C-4D58-AC3A-7A060DB99E75} http://www.dot6.state.pa.us/crsapp/esd/esd2xi.cab (ESD Internet Control 2.1)
O16 - DPF: {F77D9241-5122-46D3-9016-C5AAF07BDE23} http://www.ephrataboro.org/ephrataboro/rear…THTMLEditor.cab (HTMLEdit Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ephbo.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA6F8A09-93A1-4589-8EE4-E8005BB4A1A2}: Domain = police.lancco.pa.us
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FAA597B6-36C7-4BC9-BA2C-5AD153602C29}: Domain = police.lancco.pa.us
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FAA597B6-36C7-4BC9-BA2C-5AD153602C29}: NameServer = 10.21.1.10,10.1.0.17,128.2.0.19
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\mckimc\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\mckimc\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 16:29:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/04/09 12:02:40 | 006,252,032 | —- | M] () - Z:\AUTOPOUND.exe – [ NTFS ]
O32 - AutoRun File - [2008/12/09 15:34:22 | 000,068,608 | R— | M] () - Z:\Auto_Auction pulllist.plc – [ NTFS ]
O32 - AutoRun File - [2008/09/05 14:13:34 | 000,047,104 | R— | M] () - Z:\Auto_Auction Salesheet.plc – [ NTFS ]
O32 - AutoRun File - [2010/03/08 11:22:38 | 000,096,908 | R— | M] () - Z:\Auto_CloseOut.plc – [ NTFS ]
O32 - AutoRun File - [2008/08/15 14:28:20 | 000,079,872 | R— | M] () - Z:\Auto_Collection Purpose.plc – [ NTFS ]
O32 - AutoRun File - [2010/03/04 09:53:58 | 000,095,602 | R— | M] () - Z:\Auto_DailySales.plc – [ NTFS ]
O32 - AutoRun File - [2008/08/15 14:28:20 | 000,048,128 | R— | M] () - Z:\Auto_Inventory List.plc – [ NTFS ]
O32 - AutoRun File - [2008/08/15 14:28:20 | 000,061,952 | R— | M] () - Z:\Auto_Location Inventory Report.plc – [ NTFS ]
O32 - AutoRun File - [2010/06/09 12:15:09 | 000,061,440 | R— | M] () - Z:\Auto_Process Report.plc – [ NTFS ]
O32 - AutoRun File - [2010/03/02 09:42:40 | 000,351,744 | R— | M] () - Z:\Auto_Receipt.rpt – [ NTFS ]
O32 - AutoRun File - [2008/09/04 09:18:02 | 000,070,656 | R— | M] () - Z:\Auto_Rmtinv.plc – [ NTFS ]
O32 - AutoRun File - [2008/12/15 14:49:06 | 000,056,832 | R— | M] () - Z:\Auto_Tow Auction Report.plc – [ NTFS ]
O32 - AutoRun File - [2008/08/15 14:28:22 | 000,030,208 | R— | M] () - Z:\Auto_Tow Company Report.plc – [ NTFS ]
O32 - AutoRun File - [2008/08/15 14:28:22 | 000,043,008 | R— | M] () - Z:\Auto_Tow Date Report.plc – [ NTFS ]
O32 - AutoRun File - [2008/08/15 14:28:22 | 000,085,239 | R— | M] () - Z:\Auto_Tow Reason Report.plc – [ NTFS ]
O32 - AutoRun File - [2008/09/24 15:30:02 | 000,297,948 | R— | M] () - Z:\Auto_Tow Slip.plc – [ NTFS ]
O33 - MountPoints2\{1409054e-35f2-11df-9fc9-002564b63e1b}\Shell\AutoRun\command - "" = F:\setupSNK.exe
O33 - MountPoints2\{14090553-35f2-11df-9fc9-002564b63e1b}\Shell - "" = AutoRun
O33 - MountPoints2\{14090553-35f2-11df-9fc9-002564b63e1b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{14090553-35f2-11df-9fc9-002564b63e1b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.dvacm - c:\Program Files\Common Files\Ulead Systems\VIO\DVACM.acm (Corel TW Corp.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.MPEGacm - c:\Program Files\Common Files\Ulead Systems\MPEG\MPEGACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.ulmp3acm - c:\Program Files\Common Files\Ulead Systems\MPEG\ulmp3acm.acm (Ulead systems)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.imm4 - C:\WINDOWS\System32\vcmimm4.dll ()
Drivers32: vidc.imm5 - C:\WINDOWS\System32\vcmimm5.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2012/02/07 09:38:19 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/02/07 09:38:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/02/06 18:21:51 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2012/02/06 18:21:48 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2012/01/17 16:11:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CAPSIT Open Scheduler
[2012/01/17 16:11:06 | 000,000,000 | —D | C] – C:\Program Files\CAPSIT, Inc
[2012/01/11 15:09:21 | 000,176,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winmm.dll
[2012/01/11 15:09:21 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mciseq.dll
[2012/01/11 15:08:41 | 000,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\packager.exe
[2011/09/29 16:19:49 | 000,413,696 | —- | C] ( ) – C:\WINDOWS\System32\lxcjinpa.dll
[2011/09/29 16:19:49 | 000,397,312 | —- | C] ( ) – C:\WINDOWS\System32\lxcjiesc.dll
[2011/09/29 16:19:49 | 000,323,584 | —- | C] ( ) – C:\WINDOWS\System32\lxcjhcp.dll
[2010/03/01 15:04:31 | 001,224,704 | —- | C] ( ) – C:\WINDOWS\System32\lxcjserv.dll
[2010/03/01 15:04:31 | 000,991,232 | —- | C] ( ) – C:\WINDOWS\System32\lxcjusb1.dll
[2010/03/01 15:04:31 | 000,696,320 | —- | C] ( ) – C:\WINDOWS\System32\lxcjhbn3.dll
[2010/03/01 15:04:31 | 000,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxcjpmui.dll
[2010/03/01 15:04:31 | 000,385,968 | —- | C] ( ) – C:\WINDOWS\System32\lxcjih.exe
[2010/03/01 15:04:31 | 000,163,840 | —- | C] ( ) – C:\WINDOWS\System32\lxcjprox.dll
[2010/03/01 15:04:31 | 000,094,208 | —- | C] ( ) – C:\WINDOWS\System32\lxcjpplc.dll
[2010/03/01 15:04:30 | 000,684,032 | —- | C] ( ) – C:\WINDOWS\System32\lxcjcomc.dll
[2010/03/01 15:04:30 | 000,585,728 | —- | C] ( ) – C:\WINDOWS\System32\lxcjlmpm.dll
[2010/03/01 15:04:30 | 000,537,520 | —- | C] ( ) – C:\WINDOWS\System32\lxcjcoms.exe
[2010/03/01 15:04:30 | 000,421,888 | —- | C] ( ) – C:\WINDOWS\System32\lxcjcomm.dll
[2010/03/01 15:04:30 | 000,381,872 | —- | C] ( ) – C:\WINDOWS\System32\lxcjcfg.exe
[2 C:\Documents and Settings\mckimc\My Documents\*.tmp files -> C:\Documents and Settings\mckimc\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/07 11:34:24 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/02/07 11:09:24 | 000,445,972 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/02/07 11:09:24 | 000,073,178 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/02/07 10:24:04 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/07 10:05:44 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/07 10:05:29 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/07 09:34:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/06 18:36:08 | 000,000,012 | —- | M] () – C:\WINDOWS\bthservsdp.dat
[2012/02/06 18:29:41 | 000,019,203 | —- | M] () – C:\Documents and Settings\mckimc\Desktop\76768_10150308911070268_392287630267_15351339_856194_n.jpg
[2012/02/06 15:14:23 | 000,046,080 | —- | M] () – C:\Documents and Settings\mckimc\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/31 16:34:44 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2012/01/31 13:51:21 | 000,046,659 | —- | M] () – C:\Documents and Settings\mckimc\Desktop\SmallJenniJoyce.png
[2012/01/30 15:31:06 | 000,369,668 | —- | M] () – C:\Documents and Settings\mckimc\Desktop\Standing up to dealers _ News _ South Philly Review.pdf
[2012/01/20 10:11:06 | 000,002,641 | —- | M] () – C:\Documents and Settings\mckimc\Desktop\Microsoft Office Word 2003.lnk
[2012/01/19 11:55:54 | 000,001,731 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/01/18 10:20:38 | 000,294,484 | —- | M] () – C:\Documents and Settings\mckimc\My Documents\HRHero booklets.pdf
[2012/01/16 14:06:27 | 000,152,987 | —- | M] () – C:\Documents and Settings\mckimc\Desktop\Policework for dummies.png
[2012/01/13 01:26:17 | 000,019,456 | —- | M] () – C:\Documents and Settings\mckimc\fbchathistory.dat
[2012/01/12 12:15:41 | 000,000,794 | —- | M] () – C:\Documents and Settings\mckimc\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2012/01/12 03:06:31 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2 C:\Documents and Settings\mckimc\My Documents\*.tmp files -> C:\Documents and Settings\mckimc\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/06 18:29:41 | 000,019,203 | —- | C] () – C:\Documents and Settings\mckimc\Desktop\76768_10150308911070268_392287630267_15351339_856194_n.jpg
[2012/01/31 13:51:21 | 000,046,659 | —- | C] () – C:\Documents and Settings\mckimc\Desktop\SmallJenniJoyce.png
[2012/01/30 15:30:09 | 000,369,668 | —- | C] () – C:\Documents and Settings\mckimc\Desktop\Standing up to dealers _ News _ South Philly Review.pdf
[2012/01/19 11:55:54 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2012/01/19 11:55:54 | 000,001,731 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/01/18 10:20:36 | 000,294,484 | —- | C] () – C:\Documents and Settings\mckimc\My Documents\HRHero booklets.pdf
[2012/01/16 14:07:00 | 000,152,987 | —- | C] () – C:\Documents and Settings\mckimc\Desktop\Policework for dummies.png
[2012/01/11 15:09:47 | 000,386,048 | —- | C] () – C:\WINDOWS\System32\dllcache\qdvd.dll
[2011/12/01 06:45:34 | 001,970,176 | —- | C] () – C:\WINDOWS\System32\vcmimm4.dll
[2011/12/01 06:45:34 | 001,572,864 | —- | C] () – C:\WINDOWS\System32\vcmimm5.dll
[2011/12/01 06:45:34 | 000,695,578 | —- | C] () – C:\WINDOWS\unins000.exe
[2011/12/01 06:45:34 | 000,000,834 | —- | C] () – C:\WINDOWS\unins000.dat
[2011/09/29 16:24:08 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\IPPCPUID.DLL
[2011/09/29 16:23:07 | 000,028,672 | —- | C] () – C:\WINDOWS\hookdllX.dll
[2011/09/29 16:22:56 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2011/09/29 16:20:09 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\lxcjcoin.dll
[2011/09/29 16:19:54 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\lxcjcnv4.dll
[2011/09/29 16:19:49 | 000,274,432 | —- | C] () – C:\WINDOWS\System32\lxcjinst.dll
[2011/03/01 12:56:58 | 000,000,000 | —- | C] () – C:\WINDOWS\plclient.INI
[2011/01/31 09:26:40 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/19 12:58:57 | 000,065,536 | —- | C] () – C:\WINDOWS\IFinst27.exe
[2010/11/24 16:03:43 | 001,773,856 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/11/01 15:53:57 | 000,000,097 | —- | C] () – C:\WINDOWS\WirelessFTP.INI
[2010/11/01 15:53:03 | 000,000,000 | —- | C] () – C:\WINDOWS\tosOBEX.INI
[2010/11/01 15:42:41 | 000,000,012 | —- | C] () – C:\WINDOWS\bthservsdp.dat
[2010/06/23 12:01:12 | 000,000,256 | —- | C] () – C:\WINDOWS\System32\pool.bin
[2010/06/10 16:00:23 | 000,000,067 | —- | C] () – C:\WINDOWS\iltwain.ini
[2010/05/17 11:17:55 | 000,962,560 | —- | C] () – C:\WINDOWS\tesseract.exe
[2010/05/04 09:26:56 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2010/04/20 09:28:08 | 000,002,828 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2010/04/20 09:28:08 | 000,000,088 | RHS- | C] () – C:\Documents and Settings\All Users\Application Data\33075CADE7.sys
[2010/03/17 17:33:15 | 000,000,043 | —- | C] () – C:\WINDOWS\gswin32.ini
[2010/03/10 14:30:48 | 000,519,168 | —- | C] () – C:\WINDOWS\System32\AF10.dll
[2010/03/10 14:30:46 | 000,034,816 | —- | C] () – C:\WINDOWS\System32\dbpower.dll
[2010/03/10 14:30:46 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\implode.dll
[2010/03/10 14:30:46 | 000,017,408 | —- | C] () – C:\WINDOWS\System32\delphimm.dll
[2010/03/10 14:30:40 | 000,215,040 | —- | C] () – C:\WINDOWS\System32\PaDbi.dll
[2010/03/10 14:30:39 | 000,260,096 | —- | C] () – C:\WINDOWS\System32\MainFingerPrint.dll
[2010/03/10 14:30:38 | 000,167,734 | —- | C] () – C:\WINDOWS\System32\ILTIF16.DLL
[2010/03/10 14:30:38 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\ILTIF32.DLL
[2010/03/10 14:30:36 | 000,303,104 | —- | C] () – C:\WINDOWS\System32\I3TIF32.DLL
[2010/03/10 14:30:36 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\ILANOT32.DLL
[2010/03/10 14:30:35 | 000,217,088 | —- | C] () – C:\WINDOWS\System32\EFTSInterface.dll
[2010/03/10 14:30:32 | 000,302,592 | —- | C] () – C:\WINDOWS\System32\CR4344.dll
[2010/03/10 14:30:00 | 000,000,278 | —- | C] () – C:\WINDOWS\pcibasew.ini
[2010/03/08 14:05:53 | 000,000,153 | —- | C] () – C:\WINDOWS\winet556.INI
[2010/03/08 10:04:36 | 000,000,129 | —- | C] () – C:\Documents and Settings\mckimc\Local Settings\Application Data\fusioncache.dat
[2010/03/04 16:39:06 | 000,002,506 | —- | C] () – C:\WINDOWS\esd2xi.ini
[2010/03/03 14:24:27 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/03/02 13:16:37 | 000,046,080 | —- | C] () – C:\Documents and Settings\mckimc\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/01 16:05:19 | 000,229,376 | —- | C] () – C:\WINDOWS\System32\wrjpeg.dll
[2010/03/01 16:05:18 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\Lfcmp60n.dll
[2010/03/01 16:05:18 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\MVWav.dll
[2010/03/01 16:05:18 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\Ltimg60n.dll
[2010/03/01 16:05:18 | 000,043,008 | —- | C] () – C:\WINDOWS\System32\Ltfil60n.dll
[2010/03/01 16:05:18 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\MVAudio.dll
[2010/03/01 16:05:18 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\Lfbmp60n.dll
[2010/03/01 15:08:06 | 000,000,000 | —- | C] () – C:\Documents and Settings\mckimc\Local Settings\Application Data\WavXMapDrive.bat
[2010/03/01 15:04:31 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxcjvs.dll
[2010/02/26 17:52:55 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/02/13 23:21:55 | 000,982,196 | —- | C] () – C:\WINDOWS\System32\igkrng500.bin
[2010/02/13 23:21:55 | 000,417,344 | —- | C] () – C:\WINDOWS\System32\igcompkrng500.bin
[2010/02/13 23:21:51 | 000,077,824 | —- | C] () – C:\WINDOWS\setpwr32.exe
[2010/02/13 23:21:01 | 000,001,154 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2010/02/13 21:58:22 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2010/02/13 21:38:16 | 000,080,368 | —- | C] () – C:\WINDOWS\System32\pbadrvdll.dll
[2008/04/25 16:31:41 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/04/25 16:27:18 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/04/25 11:16:24 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/25 11:16:22 | 000,445,972 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/25 11:16:22 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/25 11:16:22 | 000,073,178 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/25 11:16:22 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/25 11:16:22 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/25 11:16:21 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/25 11:16:20 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2008/04/25 11:16:18 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/25 11:16:18 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/25 11:16:13 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/25 11:16:11 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/25 04:22:39 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/04/25 04:21:52 | 000,321,136 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2007/08/10 08:19:38 | 000,001,139 | —- | C] () – C:\WINDOWS\Beast.ini
[2007/06/21 09:49:24 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\TosBtAcc.dll
[2007/01/28 18:48:20 | 000,002,413 | —- | C] () – C:\WINDOWS\esd4de.ini
[2006/12/29 17:29:52 | 001,464,832 | —- | C] () – C:\Program Files\PLCRptV.exe
[2006/12/05 16:54:36 | 000,002,146 | —- | C] () – C:\WINDOWS\esd4x.ini
[2006/06/30 13:58:44 | 000,176,128 | R— | C] () – C:\WINDOWS\System32\bioapi_mds300.dll
[2006/06/30 13:58:44 | 000,126,976 | R— | C] () – C:\WINDOWS\System32\bioapi100.dll
[2006/02/22 16:49:54 | 001,957,888 | —- | C] () – C:\WINDOWS\System32\Winet556.Exe
[2005/07/22 20:30:18 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\TosCommAPI.dll
[2004/07/07 08:24:06 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\AmgBeep.dll
[2003/05/02 09:58:26 | 000,004,375 | —- | C] () – C:\WINDOWS\SigPlus.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/04/11 05:10:00 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\BCFONT32.DLL
[2001/02/03 03:22:08 | 000,307,200 | —- | C] () – C:\Program Files\ExportModeller.dll
[2001/02/02 23:59:28 | 000,049,223 | R— | C] () – C:\Program Files\CRTSLV.DLL

========== LOP Check ==========

[2010/03/22 12:52:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CitrixLogs
[2010/04/20 09:06:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InterVideo
[2010/09/08 12:05:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2011/03/01 12:55:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/01/29 12:06:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2011/12/01 07:51:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/20 09:06:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2010/02/13 21:46:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2010/02/23 17:25:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wave Systems Corp
[2011/04/04 09:06:54 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\Blackberry Desktop
[2010/02/13 21:42:57 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\Broadcom
[2011/01/25 17:45:53 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\Foxit Software
[2010/03/31 09:13:23 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\Leadertech
[2011/10/24 09:54:11 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\NewSoft
[2010/03/17 17:44:21 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\OpenOffice.org
[2010/11/18 14:55:49 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\Research In Motion
[2011/03/01 12:56:53 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\ScanSoft
[2011/02/21 16:54:18 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\SmartDraw
[2010/03/04 15:55:38 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\Softland
[2010/11/01 15:50:06 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\TOSHIBA
[2011/01/21 15:45:21 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\Trancite
[2010/04/20 09:07:45 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\Ulead Systems
[2010/02/13 21:40:36 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\Wave Systems Corp
[2010/02/13 21:36:53 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\Windows Desktop Search
[2010/03/31 09:16:52 | 000,000,000 | —D | M] – C:\Documents and Settings\mckimc\Application Data\WinPatrol

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/08/04 12:23:07 | 040,423,936 | —- | M] () – C:\21-1754-10EK Car 6.AVI
[2008/04/25 16:29:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/08/23 14:02:29 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2008/04/25 16:29:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/02/13 23:23:51 | 000,023,683 | RH– | M] () – C:\dell.sdr
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 07:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 07:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 07:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 07:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 07:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 07:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 07:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 07:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 07:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 07:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 07:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 07:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/04/25 16:29:32 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2012/02/07 10:09:47 | 000,061,464 | —- | M] () – C:\lxcj.log
[2010/03/01 15:04:26 | 000,000,275 | —- | M] () – C:\lxcjfire.csv
[2010/03/01 15:04:38 | 000,000,867 | —- | M] () – C:\lxcjinst.csv
[2012/02/07 10:09:47 | 000,010,542 | —- | M] () – C:\lxcjscan.log
[2008/04/25 16:29:32 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/04/14 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 07:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/02/07 09:34:16 | 4278,190,080 | -HS- | M] () – C:\pagefile.sys
[2012/01/31 16:34:44 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2011/10/03 11:45:19 | 000,000,004 | —- | M] () – C:\USB001
[2007/11/07 07:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 07:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 07:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2010/03/10 14:32:07 | 000,000,000 | —- | M] () – C:\VSIInstallLog.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 22:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 21:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 22:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 21:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/04/25 16:29:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/12/15 17:13:08 | 000,052,080 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\GoToPrintProcessor.dll
[2007/01/30 06:04:41 | 000,118,272 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxcjpp5c.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/03 17:03:28 | 000,088,193 | —- | M] () – C:\Program Files\Beast Police headshot 256x256.ico
[2008/01/03 15:21:50 | 000,161,862 | —- | M] () – C:\Program Files\case viewer.ico
[2009/03/19 14:24:32 | 000,000,372 | —- | M] () – C:\Program Files\CFB.txt
[2001/02/02 23:59:28 | 000,049,223 | R— | M] () – C:\Program Files\CRTSLV.DLL
[2001/02/03 03:22:08 | 000,307,200 | —- | M] () – C:\Program Files\ExportModeller.dll
[2006/12/29 17:29:52 | 001,464,832 | —- | M] () – C:\Program Files\PLCRptV.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/04/25 04:21:09 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/04/25 04:21:09 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/04/25 04:21:09 | 000,905,216 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/04/25 16:29:41 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/02/23 17:16:00 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\mckimc\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/04/25 16:33:01 | 000,000,079 | —- | M] () – C:\Documents and Settings\mckimc\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2006/09/11 09:15:50 | 041,758,863 | —- | M] (Digital Safety Technologies, Inc. ) – C:\Documents and Settings\mckimc\Desktop\DPViewer_Tagging_Setup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-02-02 14:37:42

========== Alternate Data Streams ==========

@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7631EA83

< End of report >


Thanks in advance.
Hi anirishfool and welcome to WhatTheTech forums!
I'm Sunyata and I will be helping you with your computer problems.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.

Please read the following guidelines which will help to make cleaning your machine easier:

  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
  • Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
  • Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
  • PLEASE DO NOT install/uninstall any programs unless asked to.
  • PLEASE DO NOT run any malware scans other than those requested.
  • Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
  • I will reply back shortly with instructions

Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI