This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Keep getting error message 'AOLSP Scheduler.exe – Unable to locate

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, can anyone help me, please? I keep getting this error message 'AOLSP Scheduler.exe – Unable to locate component' on start up and afterwards, when I am trying to work on my laptop. I am not even using AOL at the time, but IE or Mozilla Firefox. It's driving me crazy. :smack:

I have scanned it with Malwarebytes - nothing. Also scanned it with Panda and Bitdefender and both said that I was clean, but the message still keeps popping up. Am I infected or is it a registry error (how do I fix it?).

Many thanks in advance for help. :)
Hijack this log below:




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:26:03, on 29/02/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Aine\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/?rd=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://acegates.com/gatevc.php?pn=srch0p1total7s2
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SynTPStart] "C:\Program Files\Synaptics\SynTP\SynTPStart.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1167595886\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Philips Device Listener] "C:\Program Files\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus D92 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE /FU "C:\WINDOWS\TEMP\E_S2A7.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [CrossRiderPlugin] C:\Program Files\CrossriderWebApps\Crossrider.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Sign on to AOL Now.lnk = C:\Program Files\AOL 9.0\aol.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=presario&pf=laptop
O15 - Trusted Zone: http://a248.e.akamai.net
O15 - Trusted Zone: http://*.bitdefender.com
O15 - Trusted Zone: http://uk.msn.com
O15 - Trusted Zone: http://ssi-hints.netflame.cc
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru…cat-no-eula.cab
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} (BitDefender QuickScan Control) - http://quickscan.bitdefender.com/qsax/qsax.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/…can8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos-beta/OnlineScanner.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…739/mcfscan.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 9106 bytes
Hi, and welcome to our malware removal forum!

My name is Richard and I'll be happy to help you with your computer problems.

Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies.

Please note the following:
  • The cleaning process is not instant as logs can take time to research. Sit tight and please be patient.
  • I will be working on your malware issues. This may or may not solve other issues you may have with your system.
  • While we are fixing your problems, do NOT install/re-install any programs or run any fixes or scanners unless told to do so.
  • Ensure that your anti-virus definitions are up-to-date.
  • I would advise backing up all your important documents, personal data files and photos to a CD or DVD drive.
  • Do not back up any Applications (programs). These should be re-installed from the original source CD(s) or website(s).
  • During the course of our cleanup, please do not do any additional online work or surfing until we have verified that your system is clean.
  • I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier.
  • Be sure to follow the directions and run tools/scans in the order listed.
  • If you do not reply to your topic, it will be closed after 3 days.
I will return as soon as possible with more instructions.



Regards,

Richard :wavey:
AOLSP Scheduler.exe is related to AOL's spyware protection program.

Let's run OTL and GMER to see if anything comes up :thumbup:

Please follow these steps in normal mode:

OTL
————-
  • Download OTL to your Desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post both logs with your next reply. You may need two posts to fit them both in.
Next

GMER Rootkit Scanner
—————
Download GMER Rootkit Scanner from here to to your Desktop. It will be a randomly named executable.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. uncheck the following:
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your Desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Next

Resident Anti-Spyware Programs Notice

I would recommend leaving some of them turned off and using the disabled antispyware program(s) to scan manually. You should only have one antispyware utility running resident.


In your next reply, please provide the following:
  • OTL log.
  • GMER log.



Regards,

Richard :wavey:
Hi Richard,

Thanks. Really appreciate your help.

First of all, here is the OTL text log below:


OTL logfile created on: 02/03/2012 08:13:19 - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = C:\Documents and Settings\Aine\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1014.05 Mb Total Physical Memory | 491.27 Mb Available Physical Memory | 48.45% Memory free
2.38 Gb Paging File | 1.94 Gb Available in Paging File | 81.36% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 66.78 Gb Total Space | 37.70 Gb Free Space | 56.46% Space Free | Partition Type: NTFS
Drive D: | 7.73 Gb Total Space | 1.03 Gb Free Space | 13.33% Space Free | Partition Type: FAT32

Computer Name: PC194765792715 | User Name: Aine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/03/02 08:10:39 | 000,584,704 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Aine\Desktop\OTL.exe
PRC - [2012/02/23 16:23:24 | 004,031,368 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2012/02/23 16:23:21 | 000,044,768 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/02/19 19:03:57 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/01/17 11:48:55 | 000,380,416 | —- | M] () – C:\Program Files\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe
PRC - [2011/08/11 23:38:07 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASCore.exe
PRC - [2011/05/15 22:01:44 | 000,478,720 | —- | M] (Crossrider) – C:\Program Files\CrossriderWebApps\Crossrider.exe
PRC - [2008/04/14 00:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/12/30 19:53:07 | 000,026,112 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Real\RealPlayer\realplay.exe
PRC - [2006/11/17 13:21:49 | 000,050,736 | —- | M] (America Online, Inc.) – C:\Program Files\Common Files\AOL\1167595886\ee\aolsoftware.exe
PRC - [2006/10/23 12:50:35 | 000,046,640 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
PRC - [2005/12/24 04:44:26 | 000,491,606 | —- | M] () – C:\Program Files\HPQ\Shared\HpqToaster.exe
PRC - [2005/06/06 23:46:24 | 000,057,344 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
PRC - [2003/08/27 10:29:46 | 000,065,536 | —- | M] (America Online, Inc.) – C:\WINDOWS\wanmpsvc.exe


========== Modules (No Company Name) ==========

MOD - [2012/03/02 06:34:52 | 001,721,344 | —- | M] () – C:\Program Files\AVAST Software\Avast\defs\12030200\algo.dll
MOD - [2012/02/19 19:03:57 | 001,911,768 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/01/17 11:48:55 | 000,380,416 | —- | M] () – C:\Program Files\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe
MOD - [2011/11/03 15:28:36 | 001,292,288 | —- | M] () – C:\WINDOWS\system32\quartz.dll
MOD - [2011/02/04 17:48:30 | 000,291,840 | —- | M] () – C:\WINDOWS\system32\sbe.dll
MOD - [2008/10/05 03:24:02 | 003,695,008 | —- | M] () – C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2008/04/14 00:11:59 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 00:11:51 | 000,059,904 | —- | M] () – C:\WINDOWS\system32\devenum.dll
MOD - [2007/01/06 15:39:47 | 000,043,520 | —- | M] () – C:\WINDOWS\system32\CmdLineExt03.dll
MOD - [2006/06/23 13:42:46 | 000,172,032 | —- | M] () – C:\Program Files\HP\QuickPlay\Kernel\common\CLDataSync.dll
MOD - [2005/12/24 04:44:26 | 000,491,606 | —- | M] () – C:\Program Files\HPQ\Shared\HpqToaster.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (CaCCProvSP)
SRV - [2012/02/23 16:23:21 | 000,044,768 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV - [2011/08/11 23:38:07 | 000,116,608 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE – (!SASCORE)
SRV - [2006/10/23 12:50:35 | 000,046,640 | —- | M] (AOL LLC) [Auto | Running] – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe – (AOL ACS)
SRV - [2006/05/08 09:49:02 | 000,098,304 | —- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe – (AddFiltr)
SRV - [2003/08/27 10:29:46 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Running] – C:\WINDOWS\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)


========== Driver Services (SafeList) ==========

DRV - [2012/02/23 16:12:28 | 000,610,648 | —- | M] (AVAST Software) [File_System | System | Running] – C:\WINDOWS\System32\drivers\aswSnx.sys – (aswSnx)
DRV - [2012/02/23 16:12:16 | 000,337,112 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswSP.sys – (aswSP)
DRV - [2012/02/23 16:10:46 | 000,035,672 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswRdr.sys – (aswRdr)
DRV - [2012/02/23 16:10:39 | 000,053,848 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswTdi.sys – (aswTdi)
DRV - [2012/02/23 16:10:25 | 000,095,704 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\WINDOWS\System32\drivers\aswmon2.sys – (aswMon2)
DRV - [2012/02/23 16:10:16 | 000,020,696 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\WINDOWS\System32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2012/02/23 16:07:33 | 000,024,920 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aavmker4.sys – (Aavmker4)
DRV - [2011/07/22 16:27:02 | 000,012,880 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2011/07/12 21:55:22 | 000,067,664 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2009/06/30 10:37:16 | 000,028,552 | —- | M] (Panda Security, S.L.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\pavboot.sys – (pavboot)
DRV - [2008/12/02 06:05:34 | 000,118,656 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtnicxp.sys – (RTL8023xp)
DRV - [2008/10/23 01:58:36 | 001,391,104 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2008/05/08 14:02:52 | 000,203,136 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\rmcast.sys – (RMCAST)
DRV - [2008/04/28 20:22:10 | 000,009,344 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\CPQBttn.sys – (HBtnKey)
DRV - [2008/04/13 18:56:06 | 000,088,320 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnkipx.sys – (NwlnkIpx)
DRV - [2008/04/13 18:39:44 | 000,092,544 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mqac.sys – (MQAC)
DRV - [2007/11/26 19:09:46 | 000,024,960 | —- | M] (America Online) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\atwpkt2.sys – (ATWPKT2)
DRV - [2007/05/01 02:11:54 | 000,630,272 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\CHDAud.sys – (HdAudAddService)
DRV - [2006/12/30 19:53:11 | 000,008,552 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM)
DRV - [2006/03/16 04:00:00 | 000,063,232 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnknb.sys – (NwlnkNb)
DRV - [2006/03/16 04:00:00 | 000,055,936 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnkspx.sys – (NwlnkSpx)
DRV - [2005/09/19 13:24:20 | 000,005,760 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\EabUsb.sys – (eabusb)
DRV - [2005/09/19 13:23:52 | 000,007,808 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\eabfiltr.sys – (eabfiltr)
DRV - [2005/08/22 00:07:00 | 001,035,008 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DPV.sys – (HSF_DPV)
DRV - [2005/08/22 00:06:16 | 000,201,600 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWAZL.sys – (HSFHWAZL)
DRV - [2005/08/22 00:06:10 | 000,718,464 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2004/08/04 06:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2003/01/10 21:13:04 | 000,033,588 | R— | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}


IE - HKU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.msn.com/?st=1 [binary data]
IE - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/?rd=1
IE - HKU\..\SearchScopes,DefaultScope = {350FA6CD-C95D-432C-9F3C-BBFEE5E09375}
IE - HKU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\..\SearchScopes\{350FA6CD-C95D-432C-9F3C-BBFEE5E09375}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7HPEB
IE - HKU\..\SearchScopes\{AA4800C4-30CC-4968-B347-7042C7183732}: "URL" = http://uk.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security, S.L.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D4FC204-33C1-4027-891B-BC96FCA1B5E7}: C:\Documents and Settings\Aine\Local Settings\Application Data\{6D4FC204-33C1-4027-891B-BC96FCA1B5E7} [2009/01/03 09:23:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Documents and Settings\All Users\Application Data\CodecCheck\firefox [2011/12/22 21:46:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/02/25 08:12:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/19 19:03:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/19 19:31:15 | 000,000,000 | —D | M]

[2011/12/31 16:05:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Aine\Application Data\Mozilla\Extensions
[2009/02/20 19:55:20 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Aine\Application Data\Mozilla\Extensions\[removed]
[2011/12/31 16:05:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Aine\Application Data\Mozilla\Extensions\[removed]
[2012/02/29 14:43:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Aine\Application Data\Mozilla\Firefox\Profiles\l7nu7fra.default\extensions
[2008/12/11 21:00:07 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Aine\Application Data\Mozilla\Firefox\Profiles\l7nu7fra.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2012/02/04 09:11:28 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Aine\Application Data\Mozilla\Firefox\Profiles\l7nu7fra.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/02/29 14:43:06 | 000,000,000 | —D | M] (Bitdefender QuickScan) – C:\Documents and Settings\Aine\Application Data\Mozilla\Firefox\Profiles\l7nu7fra.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/01/23 08:48:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/02/25 08:12:51 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2009/07/27 10:26:48 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/09/02 20:57:00 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/02/19 19:03:58 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/02/19 19:03:53 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/02/19 19:03:53 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/19 19:03:53 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/02/19 19:03:53 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/02/19 19:03:53 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/11/03 08:59:04 | 000,000,000 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {A33FA729-D155-4B23-842B-2C665ECABDB6} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {A33FA729-D155-4B23-842B-2C665ECABDB6} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe (AOL LLC)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\CHDAudPropShortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1167595886\ee\aolsoftware.exe (America Online, Inc.)
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Philips Device Listener] C:\Program Files\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe ()
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [RecGuard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005..\Run: [CrossRiderPlugin] C:\Program Files\CrossriderWebApps\Crossrider.exe (Crossrider)
O4 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005..\Run: [EPSON Stylus D92 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Documents and Settings\Aine\Start Menu\Programs\StartUp\Sign on to AOL Now.lnk = C:\Program Files\AOL 9.0\aol.exe (America Online, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found
O15 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\..Trusted Domains: akamai.net ([a248.e] http in Trusted sites)
O15 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\..Trusted Domains: bitdefender.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\..Trusted Domains: msn.com ([uk] http in Trusted sites)
O15 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\..Trusted Domains: netflame.cc ([ssi-hints] http in Trusted sites)
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB (Hewlett-Packard Online Support Services)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab (F-Secure Online Scanner Launcher)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} http://a516.g.akamai.net/f/516/25175/7d/ru…cat-no-eula.cab (Citrix ICA Client)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (Reg Error: Key error.)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…739/mcfscan.cab (McFreeScan Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{00B3C245-0264-4E65-81ED-4CDBA28C196E}: DhcpNameServer = 192.168.1.1 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Aine\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Aine\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 14:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/03/02 08:10:34 | 000,584,704 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Aine\Desktop\OTL.exe
[2012/02/29 15:24:40 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Aine\Desktop\HiJackThis.exe
[2012/02/29 15:23:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Aine\My Documents\Downloads
[2012/02/27 17:30:27 | 000,028,552 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\pavboot.sys
[2012/02/27 17:30:23 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2012/02/27 17:23:30 | 000,000,000 | —D | C] – C:\Program Files\ProcessExplorer
[2012/02/27 17:19:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/02/27 17:07:14 | 000,071,680 | —- | C] (Option^Explicit Software [removed]) – C:\Program Files\KillBox.exe
[2012/02/26 09:25:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Aine\Application Data\QuickScan
[2012/02/23 16:11:01 | 000,000,000 | -H-D | C] – C:\Program Files\Uninstall Information
[2012/02/20 07:41:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Aine\My Documents\Adrian's folder
[2012/01/23 08:47:03 | 015,113,064 | —- | C] (Mozilla) – C:\Program Files\Firefox Setup 9.0.1.exe
[18 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/03/02 08:19:22 | 000,302,592 | —- | M] () – C:\Documents and Settings\Aine\Desktop\GMER rootkit scanner.exe
[2012/03/02 08:10:39 | 000,584,704 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Aine\Desktop\OTL.exe
[2012/03/02 08:03:10 | 000,000,313 | -HS- | M] () – C:\hpqp.ini
[2012/03/02 08:03:08 | 000,000,041 | —- | M] () – C:\XP_TV.ini
[2012/03/02 08:02:54 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/03/02 08:02:50 | 000,000,262 | —- | M] () – C:\WINDOWS\tasks\RegistryBooster.job
[2012/03/02 07:56:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/29 15:24:40 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Aine\Desktop\HiJackThis.exe
[2012/02/27 17:13:52 | 001,857,786 | —- | M] () – C:\Program Files\ProcessExplorer.zip
[2012/02/27 17:07:14 | 000,071,680 | —- | M] (Option^Explicit Software [removed]) – C:\Program Files\KillBox.exe
[2012/02/27 11:54:25 | 000,201,798 | —- | M] () – C:\Documents and Settings\Aine\My Documents\PK13521 Further Particulars.pdf
[2012/02/25 08:12:54 | 000,002,625 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2012/02/23 16:23:26 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2012/02/23 16:23:21 | 000,201,352 | —- | M] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2012/02/23 16:12:28 | 000,610,648 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/02/23 16:12:16 | 000,337,112 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2012/02/23 16:10:46 | 000,035,672 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/02/23 16:10:39 | 000,053,848 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/02/23 16:10:25 | 000,095,704 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/02/23 16:10:22 | 000,089,048 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2012/02/23 16:10:16 | 000,020,696 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/02/23 16:07:33 | 000,024,920 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/02/21 18:55:53 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2012/02/19 20:15:44 | 000,001,422 | —- | M] () – C:\Documents and Settings\Aine\Desktop\DivX Movies.lnk
[2012/02/19 09:49:43 | 008,650,752 | —- | M] () – C:\Documents and Settings\Aine\ntuser.bak
[2012/02/18 07:54:14 | 000,473,670 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/02/18 07:54:14 | 000,081,854 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/02/17 08:11:40 | 000,288,496 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/17 08:08:18 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[18 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/27 17:13:43 | 001,857,786 | —- | C] () – C:\Program Files\ProcessExplorer.zip
[2012/02/27 11:54:24 | 000,201,798 | —- | C] () – C:\Documents and Settings\Aine\My Documents\PK13521 Further Particulars.pdf
[2012/02/26 08:29:58 | 000,000,041 | —- | C] () – C:\XP_TV.ini
[2012/02/16 15:27:06 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/16 15:27:06 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2011/12/31 16:04:33 | 000,011,264 | —- | C] () – C:\WINDOWS\System32\rockusbCoInstaller.dll
[2011/09/14 10:34:17 | 000,001,652 | —- | C] () – C:\WINDOWS\System32\.ini
[2011/01/05 11:22:07 | 000,021,064 | —- | C] () – C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/11/01 07:58:38 | 001,474,832 | —- | C] () – C:\WINDOWS\System32\drivers\sfi.dat

========== LOP Check ==========

[2008/05/24 10:58:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Adrian\Application Data\Viewpoint
[2011/01/11 13:59:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\ElevatedDiagnostics
[2007/05/09 12:41:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\ICAClient
[2007/02/06 18:16:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\Leadertech
[2009/04/11 17:28:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\LimeWire
[2011/12/31 16:25:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\Philips
[2011/12/31 16:05:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\Philips-Songbird
[2012/02/26 09:26:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\QuickScan
[2011/06/24 19:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\Sammsoft
[2007/01/05 19:23:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\Template
[2009/10/15 15:48:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\TuneUp Software
[2008/05/21 09:12:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\Viewpoint
[2009/01/13 14:15:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\Windows Desktop Search
[2009/01/22 18:50:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\Windows Search
[2012/01/10 18:25:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Aine\Application Data\Wise Registry Cleaner
[2010/09/04 09:48:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/09/14 11:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2009/07/27 12:49:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2011/12/22 21:46:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CodecCheck
[2008/04/01 09:57:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2009/07/15 17:35:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2011/07/18 19:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2011/12/22 21:46:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallMate
[2010/02/12 17:01:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Max Secure
[2009/07/27 15:37:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2008/11/10 18:53:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2011/12/22 21:44:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Premium
[2009/04/10 15:20:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2010/03/27 13:15:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2010/03/27 14:27:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/06/21 19:06:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/15 15:47:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2006/12/30 19:53:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/12/23 17:14:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2009/10/15 15:45:41 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2011/12/31 16:03:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{F0489EF2-D393-4114-85BA-A94D71D89543}
[2012/03/02 08:02:50 | 000,000,262 | —- | M] () – C:\WINDOWS\Tasks\RegistryBooster.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2007/01/06 14:09:42 | 021,822,168 | —- | M] ( ) – C:\AdbeRdr80_en_US.exe
[2007/01/06 12:24:50 | 007,050,552 | —- | M] (Adobe Systems, Inc. ) – C:\psa30se_en_us.exe
[2004/08/04 01:56:58 | 000,028,672 | RH– | M] (Microsoft Corporation) – C:\setupSNK.exe


< MD5 for: EXPLORER.EXE >
[2008/04/14 00:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 00:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/14 00:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 00:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/04/14 00:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 00:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008/04/14 00:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 00:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
[2008/04/14 00:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WPA Saved\winlogon.exe

< %systemroot%\*. /rp /s >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Aine\My Documents\PPQUK.rtf:SummaryInformation
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >



And here is the Extras txt log you requested:



OTL Extras logfile created on: 02/03/2012 08:13:19 - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = C:\Documents and Settings\Aine\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1014.05 Mb Total Physical Memory | 491.27 Mb Available Physical Memory | 48.45% Memory free
2.38 Gb Paging File | 1.94 Gb Available in Paging File | 81.36% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 66.78 Gb Total Space | 37.70 Gb Free Space | 56.46% Space Free | Partition Type: NTFS
Drive D: | 7.73 Gb Total Space | 1.03 Gb Free Space | 13.33% Space Free | Partition Type: FAT32

Computer Name: PC194765792715 | User Name: Aine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = aolfile_HTM] – C:\Program Files\AOL 9.0\aol.exe (America Online, Inc.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htafile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – Reg Error: Value error.
https [open] – Reg Error: Value error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\AOL 9.0\waol.exe" = C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL – (America Online, Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1167595886\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1167595886\ee\aolsoftware.exe:*:Enabled:AOL Services – (America Online, Inc.)
"C:\Program Files\AOL 9.0\waol.exe" = C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL – (America Online, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{1CB34CE9-0E6B-493F-BB66-3425E5DF76E5}" = CP_CalendarTemplates1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{23B35809-5E4A-4F14-8332-1CDEDDFAC089}" = CP_Package_Variety2
"{24BEBF2E-73F3-4599-840B-EDC612CCDD0D}" = Destinations
"{26A24AE4-039D-4CA4-87B4-2F83216014F0}" = Java™ 6 Update 14
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 20
"{2A548002-9042-4083-A270-B67473DE1073}" = SkinsHP1
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.10 A1
"{34F3FCF1-817B-4D61-B6AF-19D9486AFEA0}" = Unload
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FE0CFAB-584A-4AA5-B8CD-C32284CFA308}" = RandMap
"{4041C245-7099-4C96-9738-5EBC23827B3C}" = BufferChm
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant 2.00 G2
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 2.3
"{494D17B5-3369-4905-8C4B-80C972C5E0FF}" = CP_Panorama1Config
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4DA4012B-39AF-48c2-B23B-A4D570D233A6}" = cp_LightScribeConfig
"{522D1D79-9C0A-4361-91F8-2AFF8EC6C2E1}" = CP_Package_Variety1
"{52FBAE98-D389-4281-8C14-21B4046CCB4E}" = SonicAC3Encoder
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{54F0998F-73C8-4b51-8286-FE903C231BED}" = cp_PosterPrintConfig
"{552E6DA4-A0F9-41AC-8473-E825D60674EA}" = HP User Guides 0037
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{766633B3-1AFA-44B6-A3FC-1DE991CD9C52}" = CP_Package_Basic1
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{79F8E1D4-36C1-439C-95FA-F695050B5B07}" = Sonic_PrimoSDK
"{80AE27BA-B0ED-4288-A8B9-D8194BCF4115}" = cp_UpdateProjectsConfig
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{838A1BC9-95CA-4880-9BE3-2A7D23600A2B}" = Macromedia Shockwave Player
"{869C3062-4745-4949-B6C9-98AF24D89030}" = PhotoGallery
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{901B0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word 2003
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{939F8208-C8CE-4AFF-B7BA-ACEB2E74A6CB}" =
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D4ABB0C-F60B-44A6-956C-A4A63D5495C9}" = CueTour
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{B11E71BA-498C-42D4-9F1A-9D7A89D9DA61}" = CP_AtenaShokunin1Config
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B16AF568-A644-483C-A6DA-5028CD019C8C}" = SonicMPEGEncoder
"{B57F2FF0-5A25-4332-B503-4592B370C02F}" = CP_Package_Variety3
"{BBD3BF67-5B89-4CBB-BA58-5818ED5F3290}" = cp_OnlineProjectsConfig
"{BC96BBA7-C634-460E-AD18-A0A994213F80}" = HP User Guides–System Recovery
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{FC8D25A7-FF1B-41BB-BB3B-9A06C0A60AE0}" = InstantShareDevices
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"America Online uk" = AOL UK (Choose which version to remove)
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOLCoach uk" = AOL Coach Version 1.0(Build:20040229.1 uk)
"avast" = avast! Free Antivirus
"Citrix ICA Web Client" = MetaFrame Presentation Server Web Client for Win32
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_CPL30A5m" = HDAUDIO Soft Data Fax Modem with SmartCP
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Stylus C90_91_D92 User’s Guide" = EPSON Stylus C90_91_D92 Manual
"HP Imaging Device Functions" = HP Imaging Device Functions 6.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 10.0.2 (x86 en-GB)" = Mozilla Firefox 10.0.2 (x86 en-GB)
"Philips Songbird" = Philips Songbird
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"SPVOD Player1.8" = SPVOD Player1.8
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 6.14

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 02/03/2012 03:31:45 | Computer Name = PC194765792715 | Source = Windows Search Service | ID = 3100
Description = Unable to initialize the filter host process. Terminating. Details:
The
system cannot find the file specified. (0x80070002)

Error - 02/03/2012 03:33:10 | Computer Name = PC194765792715 | Source = Windows Search Service | ID = 3100
Description = Unable to initialize the filter host process. Terminating. Details:
The
system cannot find the file specified. (0x80070002)

Error - 02/03/2012 03:33:30 | Computer Name = PC194765792715 | Source = Windows Search Service | ID = 3100
Description = Unable to initialize the filter host process. Terminating. Details:
The
system cannot find the file specified. (0x80070002)

Error - 02/03/2012 03:36:41 | Computer Name = PC194765792715 | Source = MsiInstaller | ID = 11402
Description = Product: Microsoft Office Word 2003 – Error 1402. Setup cannot open
the registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS.
Verify that you have sufficient permissions to access the registry or contact
your computer manufacturer's product support for assistance.

Error - 02/03/2012 03:36:44 | Computer Name = PC194765792715 | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Application, SystemIndex
Catalog

Error - 02/03/2012 03:37:21 | Computer Name = PC194765792715 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office Word 2003 - Update 'Update for Office 2003
(KB2539581): RICHED20' could not be installed. Error code 1603. Windows Installer
can create logs to help troubleshoot issues with installing software packages.
Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Error - 02/03/2012 03:39:25 | Computer Name = PC194765792715 | Source = MsiInstaller | ID = 11402
Description = Product: Microsoft Office Word 2003 – Error 1402. Setup cannot open
the registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS.
Verify that you have sufficient permissions to access the registry or contact
your computer manufacturer's product support for assistance.

Error - 02/03/2012 03:39:27 | Computer Name = PC194765792715 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office Word 2003 - Update 'Security Update for
Office 2003 (KB2584052): MSO' could not be installed. Error code 1603. Windows Installer
can create logs to help troubleshoot issues with installing software packages.
Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Error - 02/03/2012 03:56:44 | Computer Name = PC194765792715 | Source = Media Center Extender Services | ID = 36864
Description = ERROR: Device Service Initialization - Unable to create or initialize
Device Table. Error code 0x80004005.

Error - 02/03/2012 04:16:35 | Computer Name = PC194765792715 | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Application, SystemIndex
Catalog

[ System Events ]
Error - 02/03/2012 03:24:06 | Computer Name = PC194765792715 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.2 for the Network Card with network
address 0014A5FA325F has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 02/03/2012 03:24:56 | Computer Name = PC194765792715 | Source = Service Control Manager | ID = 7024
Description = The Media Center Extender Service service terminated with service-specific
error 2147500037 (0x80004005).

Error - 02/03/2012 03:37:31 | Computer Name = PC194765792715 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Update for Microsoft Office 2003 (KB2539581).

Error - 02/03/2012 03:42:05 | Computer Name = PC194765792715 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office 2003 (KB2584052).

Error - 02/03/2012 03:45:33 | Computer Name = PC194765792715 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 02/03/2012 03:46:46 | Computer Name = PC194765792715 | Source = Service Control Manager | ID = 7001
Description = The Message Queuing service depends on the Distributed Transaction
Coordinator service which failed to start because of the following error: %%1068

Error - 02/03/2012 03:46:46 | Computer Name = PC194765792715 | Source = Service Control Manager | ID = 7001
Description = The Message Queuing Triggers service depends on the Message Queuing
service which failed to start because of the following error: %%1068

Error - 02/03/2012 03:46:46 | Computer Name = PC194765792715 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 aswSnx aswSP aswTdi Fips intelppm pavboot SASDIFSV SASKUTIL

Error - 02/03/2012 03:55:13 | Computer Name = PC194765792715 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 02/03/2012 03:56:53 | Computer Name = PC194765792715 | Source = Service Control Manager | ID = 7024
Description = The Media Center Extender Service service terminated with service-specific
error 2147500037 (0x80004005).


< End of report >


Will let you have the GMER results shortly.
Hi again, Richard. Sorry, it took ages for the GMER thing to scan. I have posted the results (saved on Notepad on my desktop) as an attachment, because it was so long. I was a bit confused about your instructions re the antispyware. Do you want me to disable Superantispyware and try to use the AOL antispyware that is not working properly? Thanks again. Aine B)

Attachments:

Thanks for the information :thumbup:

The Anti-Spyware Programs Notice is there just to let you know that only one antispyware utility should be running resident in case you have both SUPERAntiSpyware and AOL's spyware protection program turned on. Would you like to keep or remove AOL's spyware protection program?

Before we start: The following steps involve modifying the registry. Modifying the registry can be dangerous (and can render your system unbootable) so it's advisable that you make a backup of the registry before proceeding.

First, please backup your Registry with ERUNT.
  • Please go here to download ERUNT.
  • For version with the Installer: Use the setup program to install ERUNT on your computer.
  • For the zipped version: Unzip all the files into a folder of your choice.
Run Erunt.exe to backup your registry to the folder of your choice.

Note: To restore your registry, go to the folder and start ERDNT.exe

Next

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present 
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present 
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present 
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present 
    O7 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O15 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\..Trusted Domains: akamai.net ([a248.e] http in Trusted sites)
    O15 - HKU\S-1-5-21-3884127898-2894485505-1830640542-1005\..Trusted Domains: netflame.cc ([ssi-hints] http in Trusted sites) 
    @Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
    @Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
    @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
    
    :Services
    CaCCProvSP 
    
    :Reg 
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" =dword:0
    "AntiVirusOverride" =dword:0
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
    "DisableMonitoring" =dword:0
      
    :Commands
    [purity]
    [emptyflash]
    [resethosts]
    [emptytemp]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • When the computer has rebooted, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date/time of the tool run.
  • Copy and paste the contents of that report in your next reply.
Next

Please go to VirusTotal.
  • Click Browse and browse to the file listed below in bold and click Send File.

    C:\WINDOWS\System32\.ini

  • There might be a short wait.
  • Select Reanalyse file and post back with the results of the scan.
In your next reply, please provide the following:
  • OTL log.
  • VirusTotal results.
  • Update on how your PC is running.



Regards,

Richard :wavey:
Hi Richard,

Thanks for quick reply.

Here is the OTL log below:[/b :thumbup:




All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\control panel\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\restrictions\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel\ not found.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions\ not found.
Registry key HKEY_USERS\S-1-5-21-3884127898-2894485505-1830640542-1005\Software\Policies\Microsoft\Internet Explorer\control panel\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3884127898-2894485505-1830640542-1005\Software\Policies\Microsoft\Internet Explorer\restrictions\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3884127898-2894485505-1830640542-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\akamai.net\a248.e\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3884127898-2894485505-1830640542-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\netflame.cc\ssi-hints\ deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8 deleted successfully.
========== SERVICES/DRIVERS ==========
Service CaCCProvSP stopped successfully!
Service CaCCProvSP deleted successfully!
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"FirstRunDisabled" |dword:0 /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"AntiVirusOverride" |dword:0 /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\\"DisableMonitoring" |dword:0 /E : value set successfully!
========== COMMANDS ==========

[EMPTYFLASH]

User: Administrator

User: Adrian
->Flash cache emptied: 19983 bytes

User: Aine
->Flash cache emptied: 3803576 bytes

User: All Users

User: Default User

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 4.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes

User: Adrian
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 134 bytes
->Java cache emptied: 3620882 bytes
->FireFox cache emptied: 5797162 bytes
->Flash cache emptied: 0 bytes

User: Aine
->Temp folder emptied: 4746051 bytes
->Temporary Internet Files folder emptied: 8085555 bytes
->Java cache emptied: 258231 bytes
->FireFox cache emptied: 29087104 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 68160 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 469 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 9512960 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 839565 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 186074954 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 456755 bytes
RecycleBin emptied: 623698 bytes

Total Files Cleaned = 238.00 mb


OTL by OldTimer - Version 3.2.34.0 log created on 03032012_101019

Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
File\Folder C:\WINDOWS\temp\usgthrsvc\Perflib_Perfdata_848.dat not found!

Registry entries deleted on Reboot...



And here are the Virustotal results below:
Hope I scanned the right file. Any idea what is wrong? :unsure: Also, I have always had more than one antispyware utility resident and have never had the annoying pop up notification of 'AOLSP Scheduler.exe - Unable to locate' come up before. Is this actually to do with AOL antispyware or something :wacko: else? And if I turn it off (how?), will it stop this message from appearing all the time? Many thanks for your help. :)

Regards,
Aine


SHA256: 67d8baff12f34dc1e24db04d6f3ae60206a7d47f96c8b40f20ded4a8640c2d18
File name: .ini
Detection ratio: 0 / 43
Analysis date: 2012-03-03 10:42:21 UTC ( 1 minute ago )
0
0
Antivirus Result Update
AhnLab-V3 - 20120302
AntiVir - 20120302
Antiy-AVL - 20120303
Avast - 20120303
AVG - 20120302
BitDefender - 20120303
ByteHero - None
CAT-QuickHeal - 20120302
ClamAV - 20120303
Commtouch - 20120302
Comodo - 20120303
DrWeb - 20120303
Emsisoft - 20120303
eSafe - 20120229
eTrust-Vet - 20120302
F-Prot - 20120302
F-Secure - 20120303
Fortinet - 20120303
GData - 20120303
Ikarus - 20120303
Jiangmin - 20120301
K7AntiVirus - 20120302
Kaspersky - 20120303
McAfee - 20120301
McAfee-GW-Edition - 20120302
Microsoft - 20120303
NOD32 - 20120303
Norman - 20120302
nProtect - 20120303
Panda - 20120302
PCTools - 20120228
Prevx - 20120303
Rising - 20120302
Sophos - 20120303
SUPERAntiSpyware - 20120302
Symantec - 20120303
TheHacker - 20120303
TrendMicro - 20120303
TrendMicro-HouseCall - 20120303
VBA32 - 20120302
VIPRE - 20120303
ViRobot - 20120303
VirusBuster - 20120303

Comments
Additional information

ssdeep
12:WMkXXJLsg0gqclVj/ErtVj/E0c/vIcPyuc3kXcXkc10H/vIHPyuH3kXHXkH1CZj/:WXHHbVItVRJjudBfoKu0URjWhk/tO
TrID
Unknown!
First seen by VirusTotal
2012-03-03 10:42:21 UTC ( 3 minutes ago )
Last seen by VirusTotal
2012-03-03 10:42:21 UTC ( 3 minutes ago )
File names (max. 25)

.ini
That is the correct file :thumbup:

Thanks for the logs! ^_^

AOL Spyware Protection could have been corrupted or there are programs running that conflict or interfere with it.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
  • Double-click the SystemLook and copy/paste the following into the box:
    :dir
    C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
  • Click the Look button. Let it finish the scan.
  • When finished, a notepad window will open with the results of the scan. Post the content of the log here in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Next

Please uninstall AOL Spyware Protection and then re-install it (only if you wish to keep it).

Instructions can be found here:
http://info.aol.co.uk/help/asp/uninstall_asp.html

To re-install: Please sign on to AOL, go to Keyword: Spyware and click the Install Now button to begin installation.

Next

Registry Cleaner Advisory

Wise Registry Cleaner 6.14 is installed on your computer.

Registry Cleaners are not recommended because removing the wrong entries could render your system unbootable.

If you would like to remove the Registry Cleaner(s), follow these steps:
  • Click on Start > Control Panel.
  • Click on Add or Remove Programs.
  • Select the following from the list:


    Wise Registry Cleaner 6.14

  • Click the Remove button.
Next

Viewpoint Media Player is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". Read Viewpoint to Plunge Into Adware

I recommend that you remove the Viewpoint products; however, decide for yourself. To remove it, uninstall the following from Add or Remove Programs, if they exist: Viewpoint, Viewpoint Manager, Viewpoint Media Player.

In your next reply, please provide the following:
  • SystemLook log.
  • Update on how your PC is running.



Regards,

Richard :wavey:
Hi Richard,

I have uninstalled AOL Spyware Protection, Wise Registry Cleaner and ViewPoint Media Player (which I didn't even know I had) - the AOL erro message has stopped appearing! Hurrah! :woot:

Here is my SystemLook txt log:

SystemLook 30.07.11 by jpshortstuff
Log created at 11:40 on 04/03/2012 by Aine
Administrator - Elevation successful

========== dir ==========

C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357} - Parameters: "(none)"

—Files—
{692B257B-FEB9-484B-BFED-A87ADA014698}.msi –a—- 17618432 bytes [15:45 15/10/2009] [15:45 15/10/2009]

—Folders—
None found.

-= EOF =-




The error message has gone (for good, I think), so I am very happy. I may reinstall AOL Spyware Protection at some point, but I will leave it off for now. Thank you so much for all your help. :clap:
There are lots of other issues with my laptop (first one, so have had to learn a lot the hard way), such as no space to defrag, but I will leave those for another time. If you notice any other issues that have arisen from the SystemLook txt log, let me know.

Thanks again, Richard,

All the best,
Aine :wavey:
Nice work! :thumbup: and you're very welcome :D

Reconfigure Windows XP to show hidden files and folders:
  • Click Start and open My Computer.
  • Select the Tools menu and click Folder Options then select the View tab.
  • Under the Hidden files and folders heading select "Show hidden files and folders".
  • Uncheck the "Hide protected operating system files (recommended)" option.
  • Uncheck the "Hide file extensions for known file types" option.
  • Click Yes to confirm then click OK.
Next

Please go to VirusTotal.
  • Click Browse and browse to the file listed below in bold and click Send File.

    C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}\{692B257B-FEB9-484B-BFED-A87ADA014698}.msi

  • There might be a short wait.
  • Select Reanalyse file and post back with the results of the scan.
In your next reply, please provide the following:
  • VirusTotal results.



Regards,

Richard :wavey:
Hi Richard, Hope you're well. :thumbup: Here are the latest Virus Total results below: SHA256: 48d62c38eacfbc89f732d416ca4bc2cc0c0ae01b90480bca0b51d39e8bba0bec File name: {692B257B-FEB9-484B-BFED-A87ADA014698}.msi Detection ratio: 0 / 41 Analysis date: 2012-03-06 09:34:49 UTC ( 1 minute ago ) 0 0 Antivirus Result Update AhnLab-V3 - 20120305 AntiVir - 20120305 Antiy-AVL - 20120305 Avast - 20120305 AVG - 20120305 BitDefender - 20120306 ByteHero - 20120305 CAT-QuickHeal - 20120305 ClamAV - 20120306 Commtouch - 20120306 Comodo - 20120306 Emsisoft - 20120306 eSafe - 20120305 eTrust-Vet - 20120306 F-Prot - 20120305 F-Secure - 20120306 Fortinet - 20120305 GData - 20120306 Ikarus - 20120306 Jiangmin - 20120301 K7AntiVirus - 20120305 Kaspersky - 20120305 McAfee - 20120305 McAfee-GW-Edition - 20120304 Microsoft - 20120306 NOD32 - 20120306 nProtect - 20120306 Panda - 20120305 PCTools - 20120228 Prevx - 20120306 Rising - 20120305 Sophos - 20120306 SUPERAntiSpyware - 20120305 Symantec - 20120305 TheHacker - 20120306 TrendMicro - 20120305 TrendMicro-HouseCall - 20120305 VBA32 - 20120305 VIPRE - 20120306 ViRobot - 20120306 VirusBuster - 20120304 Comments Additional information No comments I am away for a few days for a family birthday, but I will take the laptop with me and try to access this site whilst I am away. Cheers, Aine :wavey:
Hi Aine,

How are you doing? :)

Thanks for the information :thumbup:

MALWAREBYTES' ANTI-MALWARE
——————————————-
Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Next

ESET ONLINE SCANNER
—————————-
I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the green ESET Online Scanner button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps):
    • Click on Download to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the esetsmartinstaller_enu.exe icon on your desktop.
  • Check YES, I accept the Terms of Use.
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check Scan archives.
  • Ensure that the option "Remove found threats" is Unchecked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push List of found threats.
  • Push Export to text file…, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    Note - when ESET doesn't find any threats, no report will be created.
  • Push the Back button.
  • Push Finish.
Next

Please post a fresh OTL log so I can review it.

In your next reply, please provide the following:
  • MBAM log.
  • ESET log.
  • OTL log.
  • Update on how your PC is running.



Regards,

Richard :wavey:
Hi Richard, Sorry for the delay. I ran Malwarebytes and Eset and they found nothing malicious, so I have not sent the logs. How do I do the OTL scan again? Do I need to copy and paste anything in the command box? Regards, Aine B)
No worries :) and thanks for the information :thumbup:

OTL
————-
  • Double click the OTL.exe on your Desktop to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post both logs with your next reply. You may need two posts to fit them both in.
In your next reply, please provide the following:
  • OTL log.
  • Update on how your PC is running.



Regards,

Richard :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI