This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

01 showing up in OTL and Hijacklog [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 05/17/2012 6:01:01 PM - Run 6
OTL by OldTimer - Version 3.2.33.2 Folder = C:\Documents and Settings\Compaq_Administrator\Desktop\Computer Tools
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

958.48 Mb Total Physical Memory | 352.59 Mb Available Physical Memory | 36.79% Memory free
2.26 Gb Paging File | 1.78 Gb Available in Paging File | 79.04% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.68 Gb Total Space | 184.74 Gb Free Space | 82.22% Space Free | Partition Type: NTFS
Drive D: | 8.18 Gb Total Space | 0.54 Gb Free Space | 6.63% Space Free | Partition Type: FAT32
Drive F: | 93.37 Gb Total Space | 15.08 Gb Free Space | 16.15% Space Free | Partition Type: NTFS

Computer Name: COMPAQ-PRESARIO | User Name: Compaq_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Macrium\Reflect\ReflectService.exe ()
PRC - C:\Documents and Settings\Compaq_Administrator\Desktop\Computer Tools\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\UPHClean\uphclean.exe (Windows ® Codename Longhorn DDK provider)
PRC - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\arservice.exe (Microsoft)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Macrium\Reflect\ReflectService.exe ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\Program Files\WOT\WOT.dll ()
MOD - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\nvshell.dll ()
MOD - C:\WINDOWS\system32\pdfcmnnt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (ReflectService.exe) – C:\Program Files\Macrium\Reflect\ReflectService.exe ()
SRV - (BBUpdate) – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (SpyHunter 4 Service) – C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (UPHClean) – C:\Program Files\UPHClean\uphclean.exe (Windows ® Codename Longhorn DDK provider)
SRV - (CLDTVHNService) – C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
SRV - (ARSVC) – C:\WINDOWS\arservice.exe (Microsoft)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (mbamchameleon) – C:\WINDOWS\system32\drivers\mbamchameleon.sys ()
DRV - (pssnap) – C:\WINDOWS\system32\DRIVERS\pssnap.sys (Macrium Software)
DRV - (PSMounter) – C:\WINDOWS\system32\drivers\psmounter.sys (Macrium Software)
DRV - (DrvAgent32) – C:\WINDOWS\system32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (esgiguard) – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ()
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Almico Software)
DRV - (ntk_dtv) – C:\Program Files\DirecTV\DirecTV\Kernel\DMP\ntk_dtv.sys (Cyberlink Corp.)
DRV - (USB_RNDIS_XP) – C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (MCSTRM) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (PCD5SRVC{8A863ACB-F5F6CC6A-05010003}) – C:\Program Files\PC-Doctor 5 for Windows\pcd5srvc.pkms (PC-Doctor, Inc.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?AF=109221&babsrc=HP_ss&mntrId=5415158c0000000000000017319e0782"
FF - prefs.js..keyword.URL: "http://search.babylon.com/?AF=109221&babsrc=adbartrp&mntrId=5415158c0000000000000017319e0782&q="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/31 15:27:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/05/13 12:59:29 | 000,000,000 | —D | M]

[2011/12/31 15:28:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Extensions
[2012/04/23 22:32:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\788pfasp.default\extensions
[2011/12/31 15:27:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/07/03 01:06:59 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2
() (No name found) – C:\DOCUMENTS AND SETTINGS\COMPAQ_ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\788PFASP.DEFAULT\EXTENSIONS\[removed]
[2011/12/21 03:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/03/18 14:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/11/24 17:22:52 | 000,611,224 | —- | M] (Oracle Corporation) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 14:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/04/23 22:32:08 | 000,002,310 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/12/21 00:30:41 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/21 00:30:41 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/05/16 21:14:47 | 000,442,026 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 -h-n7y15mc.firoli-sys.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-domains-registrations.com
O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 15213 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No CLSID value found.
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O2 - BHO: (hpWebHelper Class) - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll (TODO: )
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No CLSID value found.
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\AutorunsDisabled [2010/09/14 08:43:53 | 000,000,000 | -H-D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EditLevel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} http://download.microsoft.com/download/viz…N-US/msorun.cab (Reg Error: Key error.)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} http://www.photodex.com/pxplay.cab (Photodex Presenter AX control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D}: DhcpNameServer = [removed] [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DE6A30FD-221E-48A6-B77C-0C5CE0CB4B3E}: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 15:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (SDEarlyDelete \??)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/05/17 11:13:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Administrator\My Documents\Contacts
[2012/05/17 09:23:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\DiskInternals
[2012/05/17 09:22:58 | 000,000,000 | —D | C] – C:\Program Files\DiskInternals
[2012/05/16 20:47:32 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Compaq_Administrator\Desktop\HijackThis.exe
[2012/05/13 12:45:14 | 000,419,488 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/05/10 11:00:27 | 000,501,248 | —- | C] ( datenhaus GmbH) – C:\WINDOWS\System32\dhRichClient3.dll
[2012/05/08 20:29:37 | 000,000,000 | —D | C] – C:\sh4ldr
[2012/05/08 20:29:37 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/05/08 14:33:54 | 000,000,000 | —D | C] – C:\Program Files\Common Files\MSDMine
[2012/05/08 14:33:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\529C53B162EB920D5ABF230BD151FC4E
[2012/04/23 22:31:07 | 000,000,000 | —D | C] – C:\Program Files\1ClickDownload
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/05/17 18:02:00 | 000,000,452 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job
[2012/05/17 17:54:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/17 17:45:09 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/05/17 17:34:50 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/05/17 15:09:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/05/17 13:13:11 | 000,159,809 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\flomaster pump sprayer.pdf
[2012/05/17 12:21:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/05/17 11:45:17 | 000,018,560 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\SCHEDULE. TXT
[2012/05/17 11:38:45 | 000,018,351 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\SCHEDULE
[2012/05/17 11:14:59 | 000,000,250 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Download undelete software. NTFS Recovery.url
[2012/05/17 02:54:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/16 21:14:47 | 000,442,026 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/05/16 20:47:36 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Compaq_Administrator\Desktop\HijackThis.exe
[2012/05/16 16:13:24 | 000,000,228 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\New Account created via Safe Mode - Windows XP.url
[2012/05/14 18:23:02 | 000,458,446 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/05/14 18:23:02 | 000,078,716 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/05/13 12:45:14 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/05/13 12:45:14 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/05/12 11:40:43 | 020,447,232 | -H– | M] () – C:\Documents and Settings\Compaq_Administrator\ntuser.bak
[2012/05/12 08:36:17 | 000,116,224 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/05/11 03:12:49 | 000,322,728 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/05/11 03:09:08 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/05/10 11:00:47 | 000,000,135 | —- | M] () – C:\Documents and Settings\All Users\Application Data\avalon2.2_WIPE2012.ini
[2012/05/10 09:03:39 | 000,014,992 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Application Data\wklnhst.dat
[2012/05/10 09:03:13 | 000,012,288 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Letter to Scientific Turf 3.wps
[2012/05/08 23:01:25 | 000,032,072 | —- | M] () – C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2012/05/08 23:01:12 | 000,000,679 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20120508_2301.reg
[2012/05/08 20:04:03 | 000,049,362 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2012/05/08 20:02:37 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20120516-211447.backup
[2012/05/08 14:44:43 | 000,003,075 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20120508_1444.reg
[2012/05/06 12:55:02 | 000,002,294 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Canadian Pharmacy, Online Prescription Drugs Store, Canada Pharmacies - Pharmacy RX World.url
[2012/05/05 18:19:48 | 000,002,568 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20120505_1819.reg
[2012/05/05 11:12:33 | 000,000,242 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Buy cheap train tickets - UK train times & train fares - MyTrainTicket.url
[2012/05/04 08:23:22 | 000,001,557 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Video Gallery Martin Clunes.url
[2012/05/02 18:16:13 | 002,367,118 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Suggested Route.bmp
[2012/05/01 03:01:21 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2012/04/28 12:05:23 | 000,006,217 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\William and Mary Series 1, Ep 2, Part 2.url
[2012/04/27 13:42:03 | 000,000,299 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\William and Mary - Series 1, Ep 1, Part 1-3 - YouTube.url
[2012/04/27 13:39:48 | 000,000,299 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\William and Mary - Series 1, Ep 1, Part 2-3 - YouTube.url
[2012/04/26 10:37:28 | 000,000,340 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\TechSpot - Technology News, Reviews and Analysis.url
[2012/04/24 10:57:15 | 000,002,950 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20120424_1057.reg
[2012/04/24 10:54:58 | 000,000,306 | RHS- | M] () – C:\boot.ini
[2012/04/21 19:00:17 | 000,001,825 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Search results for properties in United Kingdom Holiday Cottage Search Results cottages4you.url
[2012/04/21 18:23:18 | 000,000,235 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\National Rail Enquiries - Official source for UK train times and timetables.url
[2012/04/21 18:22:32 | 000,000,222 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Cornwall County Bus Services (2).url
[2012/04/21 18:21:35 | 000,000,256 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Traveline South West - Contact Details Display - English.url
[2012/04/21 18:11:07 | 000,000,232 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Getting around Visit Cornwall.url
[2012/04/21 18:10:19 | 000,000,307 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Port Isaac Visit Cornwall.url
[2012/04/21 18:07:00 | 000,000,222 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Cornwall County Bus Services.url
[2012/04/21 17:30:53 | 000,000,240 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Travel to Cornwall Visit Cornwall.url
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/05/17 13:13:11 | 000,159,809 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\flomaster pump sprayer.pdf
[2012/05/17 11:45:17 | 000,018,560 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\SCHEDULE. TXT
[2012/05/17 11:38:45 | 000,018,351 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\SCHEDULE
[2012/05/17 11:14:59 | 000,000,250 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Download undelete software. NTFS Recovery.url
[2012/05/16 16:13:24 | 000,000,228 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\New Account created via Safe Mode - Windows XP.url
[2012/05/11 03:02:58 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2012/05/10 11:00:47 | 000,000,135 | —- | C] () – C:\Documents and Settings\All Users\Application Data\avalon2.2_WIPE2012.ini
[2012/05/10 11:00:32 | 000,340,992 | —- | C] () – C:\WINDOWS\System32\sqlite36_engine.dll
[2012/05/10 11:00:29 | 000,340,992 | —- | C] () – C:\WINDOWS\sqlite36_engine.dll
[2012/05/10 09:03:13 | 000,012,288 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Letter to Scientific Turf 3.wps
[2012/05/08 23:01:09 | 000,000,679 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20120508_2301.reg
[2012/05/08 20:32:10 | 000,032,072 | —- | C] () – C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2012/05/08 14:44:40 | 000,003,075 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20120508_1444.reg
[2012/05/06 12:55:02 | 000,002,294 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Canadian Pharmacy, Online Prescription Drugs Store, Canada Pharmacies - Pharmacy RX World.url
[2012/05/05 18:19:45 | 000,002,568 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20120505_1819.reg
[2012/05/05 11:12:33 | 000,000,242 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Buy cheap train tickets - UK train times & train fares - MyTrainTicket.url
[2012/05/04 08:23:22 | 000,001,557 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Video Gallery Martin Clunes.url
[2012/05/02 18:16:12 | 002,367,118 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Suggested Route.bmp
[2012/05/01 03:11:14 | 000,000,384 | -H– | C] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/05/01 03:01:18 | 000,001,706 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/04/28 12:05:23 | 000,006,217 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\William and Mary Series 1, Ep 2, Part 2.url
[2012/04/27 13:42:03 | 000,000,299 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\William and Mary - Series 1, Ep 1, Part 1-3 - YouTube.url
[2012/04/27 13:39:48 | 000,000,299 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\William and Mary - Series 1, Ep 1, Part 2-3 - YouTube.url
[2012/04/26 10:37:28 | 000,000,340 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\TechSpot - Technology News, Reviews and Analysis.url
[2012/04/24 10:57:12 | 000,002,950 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20120424_1057.reg
[2012/04/21 19:00:17 | 000,001,825 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Search results for properties in United Kingdom Holiday Cottage Search Results cottages4you.url
[2012/04/21 18:23:18 | 000,000,235 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\National Rail Enquiries - Official source for UK train times and timetables.url
[2012/04/21 18:22:32 | 000,000,222 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Cornwall County Bus Services (2).url
[2012/04/21 18:21:35 | 000,000,256 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Traveline South West - Contact Details Display - English.url
[2012/04/21 18:11:07 | 000,000,232 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Getting around Visit Cornwall.url
[2012/04/21 18:10:19 | 000,000,307 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Port Isaac Visit Cornwall.url
[2012/04/21 18:07:00 | 000,000,222 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Cornwall County Bus Services.url
[2012/04/21 17:30:53 | 000,000,240 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Travel to Cornwall Visit Cornwall.url
[2012/02/25 12:48:22 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2012/02/23 12:53:33 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/02/23 12:53:33 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/02/23 12:53:33 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/02/23 12:53:33 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/02/23 12:53:33 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/02/15 23:13:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/06 18:08:24 | 000,000,061 | —- | C] () – C:\WINDOWS\TaxACT11.ini
[2011/12/01 00:46:28 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat
[2011/07/24 15:47:34 | 002,130,002 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/07/10 13:48:52 | 000,024,408 | —- | C] () – C:\WINDOWS\System32\ventmon.dll
[2011/07/03 01:10:37 | 000,017,408 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\WebpageIcons.db
[2011/05/14 16:11:18 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/05/14 16:11:18 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/05/14 16:11:18 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/01/12 18:31:18 | 000,000,600 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\PUTTY.RND
[2011/01/07 17:08:16 | 000,000,061 | —- | C] () – C:\WINDOWS\TaxACT10.ini

========== LOP Check ==========

[2012/05/08 23:11:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\529C53B162EB920D5ABF230BD151FC4E
[2011/03/08 17:13:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/06 11:39:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/12/15 11:22:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/07/03 14:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2008/08/04 06:10:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2009/06/06 23:17:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2012/03/21 17:03:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Macrium
[2010/12/15 11:01:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2006/08/23 09:54:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2010/12/24 13:12:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\National Instruments
[2006/07/14 19:28:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Otto
[2009/04/28 16:03:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/12/21 12:57:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2007/10/02 18:02:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2008/01/14 11:46:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uniblue
[2011/11/20 18:01:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2011/07/10 13:48:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Venta
[2007/08/21 09:13:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2010/07/03 15:45:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\GARMIN
[2012/05/16 11:53:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\GetRightToGo
[2007/08/16 19:00:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\GPS Utility
[2011/01/04 18:17:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\gtk-2.0
[2009/10/15 00:36:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\IE7pro
[2006/07/14 23:06:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Leadertech
[2006/09/18 19:48:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\MSNInstaller
[2007/12/13 09:38:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Netscape
[2006/07/14 19:28:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Otto
[2011/01/02 10:58:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Participatory Culture Foundation
[2011/12/08 16:41:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\PCF-VLC
[2012/02/25 12:48:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\pdfforge
[2006/08/08 20:19:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Registry Booster
[2008/10/24 10:58:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Safer Networking
[2011/12/01 00:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Systweak
[2006/07/14 10:57:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Template
[2011/12/16 21:53:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Uniblue
[2009/12/02 19:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Wal-Mart
[2007/07/07 08:48:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\WinBatch
[2010/08/11 19:19:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\wsInspector
[2012/05/17 18:02:00 | 000,000,452 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/07/12 08:45:34 | 000,000,279 | —- | M] () – C:\Boot.bak
[2012/04/24 10:54:58 | 000,000,306 | RHS- | M] () – C:\boot.ini
[2004/08/09 17:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2012/05/12 11:54:11 | 000,000,042 | —- | M] () – C:\hpWebHelper.log
[2005/08/30 17:02:02 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/08/30 17:02:02 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/09 17:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/03/07 16:31:35 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/05/17 17:34:47 | 1507,565,568 | -HS- | M] () – C:\pagefile.sys
[2012/05/12 09:56:57 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.7.13.0_12.05.2012_09.56.52_log.txt
[2012/05/12 09:58:49 | 000,086,260 | —- | M] () – C:\TDSSKiller.2.7.34.0_12.05.2012_09.57.33_log.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/30 17:01:20 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/06/18 20:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2011/12/28 18:51:52 | 000,001,754 | -H– | M] () – C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2006/07/13 23:45:32 | 000,000,251 | —- | M] () – C:\Program Files\wt3d.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/08/30 09:51:10 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/08/30 09:51:10 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/03/07 16:36:53 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/07/23 18:20:38 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/30 17:06:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/05/16 20:47:36 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Compaq_Administrator\Desktop\HijackThis.exe
[2012/03/21 16:57:22 | 032,194,200 | —- | M] (Paramount Software UK Ltd) – C:\Documents and Settings\Compaq_Administrator\Desktop\reflect_setup_free.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoRebootWithLoggedOnUsers" = 1

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-05-11 07:09:48

< >

< >

< End of report >
Hello Lewg and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again Lewg

Did you intentionally install the Babylon toolbar? If you didn’t and want it removed I can give you instructions.

Your OTL log is clean apart from some tidying up.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found
    O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No CLSID value found
    O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
    O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No CLSID value found.
    O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk File not found
    O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk File not found
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} Reg Error: Value error. (Reg Error: Key error.)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
    O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} http://download.microsoft.com/download/viz…N-US/msorun.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
    O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
    O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
===================================================

Run AVG removal tool

There are remnants of AVG on your computer which might interfere with some of the tools we use. Please download and run AVG Removal Tool from here

===================================================

HijackThis and OTL O1 entries

You have Spybot-S&Dinstalled on your computer. This program protects your computer in several ways but one of them is by placing “bad” entries in your hosts file. This way, attempts to access those addresses will direct them back to your computer.

Please read this for more information.

Logs to include in the next post:

OTL fix log

Please can you tell me if there are any issues with your computer or just the O1 entries

Thanks

Satchfan
Cannot locate the AVG removal Tool you directed me to. Not sure if it's the right site page to list the removal tool. However here is the OTL log you requested. My PC apparently has a problem running Hijackthis. It gets started and just sits for several minutes trying to complete…..In the past it would finish and complete the scan in seconds…….Not sure what's going on, but something is not right. . All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found. Starting removal of ActiveX control {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}\ not found. Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Starting removal of ActiveX control {A4639D2F-774E-11D3-A490-00C04F6843FB} C:\WINDOWS\Downloaded Program Files\launchie.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A4639D2F-774E-11D3-A490-00C04F6843FB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4639D2F-774E-11D3-A490-00C04F6843FB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A4639D2F-774E-11D3-A490-00C04F6843FB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A4639D2F-774E-11D3-A490-00C04F6843FB}\ not found. Starting removal of ActiveX control {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control Garmin Communicator Plug-In Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Garmin Communicator Plug-In\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Garmin Communicator Plug-In\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Garmin Communicator Plug-In\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\ deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 112254 bytes ->Flash cache emptied: 0 bytes User: All Users User: Compaq_Administrator ->Temp folder emptied: 1793973 bytes ->Temporary Internet Files folder emptied: 50932015 bytes ->FireFox cache emptied: 15449467 bytes ->Flash cache emptied: 4476 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 105956 bytes ->Temporary Internet Files folder emptied: 619521 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 180482 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 21522708 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 62724 bytes RecycleBin emptied: 34247487 bytes Total Files Cleaned = 119.00 mb OTL by OldTimer - Version 3.2.33.2 log created on 05192012_082451 Files\Folders moved on Reboot… C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\YM8GJAGM\iframe[1].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\CJZMRJ1F\iframe[1].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\9NU0CAXU\iframe[1].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\9NU0CAXU\index[1].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. Registry entries deleted on Reboot…
OK let’s have a couple more scans and see if anything is amiss.

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif

  • disable any script blocking protection (How to Disable your Security Programs)
  • double click DDS icon to run the tool (may take up to 3 minutes to run)
  • when done, DDS.txt will open.
  • after a few moments, attach.txt will open in a second window.
  • save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

DDS.txt
Attach.txt
aswMBR log


Thanks

Satchfan
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.1.0 Run by [removed] at 10:25:28 on 2012-05-19 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.373 [GMT -4:00] . AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . ============== Running Processes =============== . C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\WINDOWS\arservice.exe C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Macrium\Reflect\ReflectService.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\UPHClean\uphclean.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.exe C:\WINDOWS\Explorer.EXE C:\HP\KBD\KBD.EXE C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe . ============== Pseudo HJT Report =============== . uSearchMigratedDefaultURL = uStart Page = hxxp://msn.com/ uInternet Connection Wizard,ShellNext = iexplore BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Bing Bar Helper: {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - c:\program files\microsoft\bingbar\7.1.361.0\BingExt.dll BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No File BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar3.dll BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\webhelper.dll BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar3.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll TB: Bing Bar: {eec0f710-38b5-4aba-99bf-ec87564a4e13} - "c:\program files\microsoft\bingbar\7.1.361.0\BingExt.dll" uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\wkcalrem.lnk - c:\program files\common files\microsoft shared\works shared\WkCalRem.exe StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\autoru~1\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\documents and settings\compaq_administrator\start menu\programs\startup\autorunsdisabled\wkcalrem.lnk.disabled StartupFolder: c:\documents and settings\compaq_administrator\start menu\programs\startup\autorunsdisabled\wordweb.lnk.disabled uPolicies-explorer: EditLevel = 0 (0x0) uPolicies-explorer: NoCommonGroups = 0 (0x0) IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: Garmin Communicator Plug-In DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} - hxxp://www.photodex.com/pxplay.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.1.254 192.168.1.254 TCP: Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D} : DhcpNameServer = [removed] [removed] [removed] [removed] TCP: Interfaces\{DE6A30FD-221E-48A6-B77C-0C5CE0CB4B3E} : DhcpNameServer = 192.168.1.254 192.168.1.254 Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\compaq_administrator\application data\mozilla\firefox\profiles\788pfasp.default\ FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon) FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?AF=109221&babsrc=HP_ss&mntrId=5415158c0000000000000017319e0782 FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=109221&babsrc=adbartrp&mntrId=5415158c0000000000000017319e0782&q= FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\documents and settings\compaq_administrator\application data\mozilla\plugins\npPxPlay.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10329.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll . —- FIREFOX POLICIES —- FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109221 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar_i.id - 5415158c0000000000000017319e0782 FF - user.js: extensions.BabylonToolbar_i.hardId - 5415158c0000000000000017319e0782 FF - user.js: extensions.BabylonToolbar_i.instlDay - 15454 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1722:32:19 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar_i.tlbrId - base FF - user.js: extensions.BabylonToolbar_i.instlRef - sst . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 171064] R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [2012-3-20 16024] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608] R2 CLDTVHNService;CLDTVHNService;c:\program files\directv\directv\kernel\dmp\CLDTVHNService.exe [2009-9-17 75048] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 ntk_dtv;ntk_dtv;c:\program files\directv\directv\kernel\dmp\ntk_dtv.sys [2009-9-17 119792] R2 ReflectService.exe;Macrium Reflect Image Mounting Service;c:\program files\macrium\reflect\ReflectService.exe [2012-3-20 224920] R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\enigma~1\spyhun~1\SH4SER~1.EXE [2012-1-18 737184] R3 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\7.1.361.0\SeaPort.EXE [2012-2-10 240408] S2 BBSvc;BingBar Service;c:\program files\microsoft\bingbar\7.1.361.0\BBSvc.EXE [2012-2-10 193816] S2 gupdate1c9316637dc9d00;Google Update Service (gupdate1c9316637dc9d00);c:\program files\google\update\GoogleUpdate.exe [2008-10-18 133104] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-13 257696] S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2011-12-2 23456] S3 esgiguard;esgiguard;c:\program files\enigma software group\spyhunter\esgiguard.sys [2011-5-6 13904] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-8-15 30192] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2008-10-18 133104] S3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2012-5-8 32072] S3 PCD5SRVC{8A863ACB-F5F6CC6A-05010003};PCD5SRVC{8A863ACB-F5F6CC6A-05010003} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\PCD5SRVC.pkms [2006-2-7 21120] S3 PSMounter;Macrium Reflect Image Explorer Service;c:\windows\system32\drivers\psmounter.sys [2012-3-20 47256] . =============== Created Last 30 ================ . 2012-05-18 15:57:04 56200 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cf8f9dbe-975b-4422-931d-913c5b140665}\offreg.dll 2012-05-18 15:42:54 6737808 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cf8f9dbe-975b-4422-931d-913c5b140665}\mpengine.dll 2012-05-17 13:22:58 ——– d—–w- c:\program files\DiskInternals 2012-05-17 12:52:03 6737808 ——w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2012-05-13 16:45:14 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-05-10 15:00:32 340992 —-a-w- c:\windows\system32\sqlite36_engine.dll 2012-05-10 15:00:29 340992 —-a-w- c:\windows\sqlite36_engine.dll 2012-05-10 15:00:27 501248 —-a-w- c:\windows\system32\dhRichClient3.dll 2012-05-09 00:32:10 32072 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys 2012-05-09 00:29:45 110080 —-a-r- c:\documents and settings\compaq_administrator\application data\microsoft\installer\{4e0c6314-a8b8-4026-ac15-084e8b63afb5}\IconF7A21AF7.exe 2012-05-09 00:29:45 110080 —-a-r- c:\documents and settings\compaq_administrator\application data\microsoft\installer\{4e0c6314-a8b8-4026-ac15-084e8b63afb5}\IconD7F16134.exe 2012-05-09 00:29:45 110080 —-a-r- c:\documents and settings\compaq_administrator\application data\microsoft\installer\{4e0c6314-a8b8-4026-ac15-084e8b63afb5}\IconCF33A0CE.exe 2012-05-09 00:29:37 ——– d—–w- C:\sh4ldr 2012-05-09 00:29:37 ——– d—–w- c:\program files\Enigma Software Group 2012-05-08 18:33:54 ——– d—–w- c:\program files\common files\MSDMine 2012-05-08 18:33:43 ——– d—–w- c:\documents and settings\all users\application data\529C53B162EB920D5ABF230BD151FC4E 2012-04-24 02:31:07 ——– d—–w- c:\program files\1ClickDownload . ==================== Find3M ==================== . 2012-05-13 16:45:14 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-04-11 13:12:06 1862272 —-a-w- c:\windows\system32\win32k.sys 2012-04-11 13:10:58 2192640 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-11 12:35:52 2069120 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-04 19:56:40 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-03-21 00:44:12 171064 —-a-w- c:\windows\system32\drivers\MpFilter.sys 2012-03-21 00:36:10 12952 —-a-w- c:\windows\system32\drivers\PSVolAcc.sys 2012-03-21 00:36:00 16024 —-a-w- c:\windows\system32\drivers\pssnap.sys 2012-03-21 00:35:54 47256 —-a-w- c:\windows\system32\drivers\psmounter.sys 2012-03-01 11:01:32 916992 —-a-w- c:\windows\system32\wininet.dll 2012-03-01 11:01:32 43520 ——w- c:\windows\system32\licmgr10.dll 2012-03-01 11:01:32 1469440 ——w- c:\windows\system32\inetcpl.cpl 2012-02-29 14:10:16 177664 —-a-w- c:\windows\system32\wintrust.dll 2012-02-29 14:10:16 148480 —-a-w- c:\windows\system32\imagehlp.dll 2012-02-29 12:17:40 385024 ——w- c:\windows\system32\html.iec . ============= FINISH: 10:26:42.98 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 07/13/2006 10:01:56 PM System Uptime: 05/19/2012 8:26:17 AM (2 hours ago) . Motherboard: ASUSTek Computer INC. | | NAGAMI2 Processor: AMD Athlon™ 64 Processor 3800+ | Socket 939 | 2405/199mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 225 GiB total, 184.666 GiB free. D: is FIXED (FAT32) - 8 GiB total, 0.542 GiB free. E: is CDROM () F: is FIXED (NTFS) - 93 GiB total, 15.07 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E96D-E325-11CE-BFC1-08002BE10318} Description: Agere Systems PCI-SV92PP Soft Modem Device ID: PCI\VEN_11C1&DEV_0620&SUBSYS_062011C1&REV_00\4&DC268A3&0&4880 Manufacturer: Agere Name: Agere Systems PCI-SV92PP Soft Modem PNP Device ID: PCI\VEN_11C1&DEV_0620&SUBSYS_062011C1&REV_00\4&DC268A3&0&4880 Service: Modem . ==== System Restore Points =================== . RP1: 03/09/2012 8:22:52 AM - System Checkpoint RP2: 03/10/2012 9:00:02 AM - Software Distribution Service 3.0 RP3: 03/11/2012 2:57:54 AM - Software Distribution Service 3.0 RP4: 03/12/2012 3:41:26 AM - System Checkpoint RP5: 03/12/2012 9:48:14 AM - Software Distribution Service 3.0 RP6: 03/13/2012 9:49:58 AM - System Checkpoint RP7: 03/13/2012 3:28:53 PM - Software Distribution Service 3.0 RP8: 03/13/2012 5:10:34 PM - Software Distribution Service 3.0 RP9: 03/14/2012 3:00:16 AM - Software Distribution Service 3.0 RP10: 03/15/2012 3:09:03 AM - System Checkpoint RP11: 03/15/2012 3:11:10 AM - Software Distribution Service 3.0 RP12: 03/16/2012 3:11:11 AM - Software Distribution Service 3.0 RP13: 03/17/2012 3:10:59 AM - Software Distribution Service 3.0 RP14: 03/18/2012 2:08:42 AM - Software Distribution Service 3.0 RP15: 03/19/2012 2:24:17 AM - System Checkpoint RP16: 03/19/2012 10:26:20 AM - Software Distribution Service 3.0 RP17: 03/20/2012 10:26:04 AM - Software Distribution Service 3.0 RP18: 03/21/2012 10:26:38 AM - Software Distribution Service 3.0 RP19: 03/21/2012 5:02:15 PM - Installed Macrium Reflect Free Edition RP20: 03/22/2012 5:24:15 PM - System Checkpoint RP21: 03/23/2012 10:26:11 AM - Software Distribution Service 3.0 RP22: 03/24/2012 10:26:10 AM - Software Distribution Service 3.0 RP23: 03/25/2012 2:12:16 AM - Software Distribution Service 3.0 RP24: 03/25/2012 3:34:53 PM - Software Distribution Service 3.0 RP25: 03/26/2012 3:35:07 PM - Software Distribution Service 3.0 RP26: 03/27/2012 5:04:13 PM - System Checkpoint RP27: 03/27/2012 6:30:44 PM - Software Distribution Service 3.0 RP28: 03/28/2012 6:30:37 PM - Software Distribution Service 3.0 RP29: 03/29/2012 7:11:39 PM - System Checkpoint RP30: 03/29/2012 10:34:21 PM - Software Distribution Service 3.0 RP31: 03/30/2012 10:34:22 PM - Software Distribution Service 3.0 RP32: 03/31/2012 10:34:19 PM - Software Distribution Service 3.0 RP33: 04/01/2012 2:12:10 AM - Software Distribution Service 3.0 RP34: 04/01/2012 10:34:17 PM - Software Distribution Service 3.0 RP35: 04/02/2012 10:34:32 PM - Software Distribution Service 3.0 RP36: 04/03/2012 10:37:57 PM - Software Distribution Service 3.0 RP37: 04/04/2012 10:45:26 PM - System Checkpoint RP38: 04/05/2012 10:47:32 AM - Software Distribution Service 3.0 RP39: 04/06/2012 11:22:17 AM - System Checkpoint RP40: 04/06/2012 12:38:22 PM - Software Distribution Service 3.0 RP41: 04/07/2012 11:03:22 AM - Restore Operation RP42: 04/07/2012 11:20:50 AM - Software Distribution Service 3.0 RP43: 04/08/2012 1:51:53 AM - Software Distribution Service 3.0 RP44: 04/08/2012 3:10:42 PM - Software Distribution Service 3.0 RP45: 04/09/2012 4:48:09 PM - System Checkpoint RP46: 04/09/2012 8:09:01 PM - Software Distribution Service 3.0 RP47: 04/10/2012 8:09:12 PM - Software Distribution Service 3.0 RP48: 04/11/2012 3:00:17 AM - Software Distribution Service 3.0 RP49: 04/11/2012 8:09:30 PM - Software Distribution Service 3.0 RP50: 04/12/2012 3:00:16 AM - Software Distribution Service 3.0 RP51: 04/13/2012 3:40:19 AM - System Checkpoint RP52: 04/13/2012 5:43:38 PM - Software Distribution Service 3.0 RP53: 04/14/2012 5:41:59 PM - Software Distribution Service 3.0 RP54: 04/15/2012 2:08:01 AM - Software Distribution Service 3.0 RP55: 04/15/2012 5:42:10 PM - Software Distribution Service 3.0 RP56: 04/16/2012 5:42:43 PM - Software Distribution Service 3.0 RP57: 04/17/2012 5:42:12 PM - Software Distribution Service 3.0 RP58: 04/18/2012 6:01:16 PM - System Checkpoint RP59: 04/18/2012 9:55:48 PM - Software Distribution Service 3.0 RP60: 04/19/2012 10:09:05 PM - System Checkpoint RP61: 04/20/2012 10:10:08 AM - Software Distribution Service 3.0 RP62: 04/21/2012 10:09:53 AM - Software Distribution Service 3.0 RP63: 04/22/2012 2:17:31 AM - Software Distribution Service 3.0 RP64: 04/23/2012 2:38:04 AM - System Checkpoint RP65: 04/23/2012 9:40:07 AM - Software Distribution Service 3.0 RP66: 04/24/2012 11:00:35 AM - Software Distribution Service 3.0 RP67: 04/25/2012 11:07:18 AM - System Checkpoint RP68: 04/25/2012 11:08:14 AM - Software Distribution Service 3.0 RP69: 04/26/2012 11:08:05 AM - Software Distribution Service 3.0 RP70: 04/27/2012 11:08:06 AM - Software Distribution Service 3.0 RP71: 04/28/2012 11:08:10 AM - Software Distribution Service 3.0 RP72: 04/29/2012 12:02:02 PM - System Checkpoint RP73: 04/30/2012 9:19:31 AM - Software Distribution Service 3.0 RP74: 05/01/2012 3:00:16 AM - Software Distribution Service 3.0 RP75: 05/02/2012 3:11:57 AM - Software Distribution Service 3.0 RP76: 05/03/2012 3:11:55 AM - Software Distribution Service 3.0 RP77: 05/04/2012 3:11:59 AM - Software Distribution Service 3.0 RP78: 05/05/2012 3:11:54 AM - Software Distribution Service 3.0 RP79: 05/06/2012 2:15:44 AM - Software Distribution Service 3.0 RP80: 05/07/2012 2:17:47 AM - System Checkpoint RP81: 05/07/2012 3:11:50 AM - Software Distribution Service 3.0 RP82: 05/08/2012 3:11:57 AM - Software Distribution Service 3.0 RP83: 05/08/2012 8:29:36 PM - Installed SpyHunter RP84: 05/08/2012 11:18:13 PM - Software Distribution Service 3.0 RP85: 05/10/2012 7:25:44 AM - Software Distribution Service 3.0 RP86: 05/11/2012 3:00:20 AM - Software Distribution Service 3.0 RP87: 05/11/2012 7:57:44 PM - Software Distribution Service 3.0 RP88: 05/12/2012 10:23:46 AM - Restore Operation RP89: 05/12/2012 10:35:48 AM - Restore Operation RP90: 05/12/2012 10:42:59 AM - Restore Operation RP91: 05/13/2012 1:42:00 AM - Software Distribution Service 3.0 RP92: 05/13/2012 12:08:08 PM - Software Distribution Service 3.0 RP93: 05/13/2012 12:58:09 PM - Installed QuickTime RP94: 05/14/2012 1:08:18 PM - System Checkpoint RP95: 05/14/2012 1:15:28 PM - Software Distribution Service 3.0 RP96: 05/15/2012 1:23:05 PM - System Checkpoint RP97: 05/15/2012 6:30:45 PM - Software Distribution Service 3.0 RP98: 05/16/2012 6:41:39 PM - System Checkpoint RP99: 05/17/2012 8:52:01 AM - Software Distribution Service 3.0 RP100: 05/17/2012 6:02:24 PM - OTL Restore Point - 05/17/2012 6:02:17 PM RP101: 05/18/2012 11:42:52 AM - Software Distribution Service 3.0 RP102: 05/19/2012 10:19:55 AM - Software Distribution Service 3.0 . ==== Installed Programs ====================== . 1ClickDownloader Adobe AIR Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader X (10.1.3) Agere Systems PCI-SV92PP Soft Modem Apple Application Support Apple Software Update ATT-RC Self Support Tool Audacity 1.2.6 Autodesk MapGuide® Viewer ActiveX Control Release 6.5 Bing Bar BufferChm CameraDrivers CCleaner (remove only) Chart Navigator Compaq Connections (remove only) Cook'n with Pillsbury Coupon Printer for Windows CreativeProjects CreativeProjectsTemplates CueTour Customer Experience Enhancement Destinations Director DIRECTV2PC Playback Advisor DIRECTV2PC™ DISCover Driver Detective DriverAgent by eSupport.com Enhanced Multimedia Keyboard Solution ERUNT 1.1j ESET Online Scanner v3 Extra_POI_Editor_Installer Garmin Communicator Plugin Garmin MapSource Garmin nRoute Garmin POI Loader Garmin Trip and Waypoint Manager v3 Garmin USB Drivers Garmin WebUpdater GdiplusUpgrade Google Desktop Google Earth Google Earth Plug-in Google Update Helper Hampton Hotels eDirectory with MultiView Reader HD Tune 2.55 High Definition Audio Driver Package - KB888111 HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Boot Optimizer HP Deskjet 3050 J610 series Basic Device Software HP Deskjet 3050 J610 series Help HP Deskjet 3050 J610 series Product Improvement Study HP Driver Diagnostics HP DVD Play 2.1 HP Image Zone 4.5 HP Photo Creations HP Rhapsody HP Support Overview HP Update HpSdpAppCoreApp HPSystemDiagnostics InstantShare Interactive User’s Guide iTunes Java Auto Updater Java™ 7 Update 1 LightScribe 1.4.84.1 Macrium Reflect Free Edition Malwarebytes Anti-Malware version 1.61.0.1400 Microsoft .NET Framework 1.0 Hotfix (KB2572066) Microsoft .NET Framework 1.0 Hotfix (KB2604042) Microsoft .NET Framework 1.0 Hotfix (KB2656378) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2656353) Microsoft .NET Framework 1.1 Security Update (KB2656370) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works Miro Mozilla Firefox 9.0.1 (x86 en-US) MSN MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB973686) NVIDIA Control Panel 285.58 NVIDIA Drivers NVIDIA Graphics Driver 285.58 NVIDIA Install Application NVIDIA nView 135.95 NVIDIA nView Desktop Manager Otto Outlook Express Quick Backup overland PanoStandAlone PartyPoker PC-Doctor 5 for Windows PCFriendly PDFCreator Photodex Presenter PhotoGallery Python 2.2 pywin32 extensions (build 203) Python 2.2.3 QFolder Quicken 2006 Quicken Legal Business Pro 2006 Quicken WillMaker Plus 2006 QuickTime RealPlayer Realtek High Definition Audio Driver Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler 3 Roxio Update Manager Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft Windows (KB2564958) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB2482017) Security Update for Windows Internet Explorer 7 (KB2497640) Security Update for Windows Internet Explorer 7 (KB2530548) Security Update for Windows Internet Explorer 7 (KB2544521) Security Update for Windows Internet Explorer 7 (KB2559049) Security Update for Windows Internet Explorer 7 (KB2586448) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2586448) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2647516) Security Update for Windows Internet Explorer 8 (KB2675157) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2491683) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2621440) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2641653) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2647518) Security Update for Windows XP (KB2653956) Security Update for Windows XP (KB2659262) Security Update for Windows XP (KB2660465) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB2676562) Security Update for Windows XP (KB2686509) Security Update for Windows XP (KB2695962) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) ShareIns SkinsHP1 SpeedFan (remove only) Spell Checker For OE 2.1 Spelling Dictionaries Support For Adobe Reader 8 Spybot - Search & Destroy SpyHunter SpywareBlaster v3.5.1 Super GameHouse Solitaire Vol. 1 SUPERAntiSpyware System Requirements Lab TaxACT 2006 TaxACT 2007 TaxACT 2008 TaxACT 2008 Georgia TaxACT 2009 TaxACT 2009 Georgia TaxACT 2010 TaxACT 2010 Georgia TaxACT 2011 - 1040 Edition TaxACT 2011 Georgia TaxACT Georgia 2006 TaxACT Georgia 2007 TrayApp Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows Internet Explorer 8 (KB2598845) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB2641690) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB953356) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update Rollup 2 for Windows XP Media Center Edition 2005 User Profile Hive Cleanup Service WebFldrs XP WebReg Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) Windows Driver Package - Ross-Tech USB Driver Package (08/16/2011 2.08.14) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format Runtime Windows Media Player Firefox Plugin Windows XP Media Center Edition 2005 KB2502898 Windows XP Media Center Edition 2005 KB2619340 Windows XP Media Center Edition 2005 KB2628259 Windows XP Media Center Edition 2005 KB908246 Windows XP Media Center Edition 2005 KB912067 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 WordWeb World Championship Checkers (Gold Plus) WOT for Internet Explorer . ==== Event Viewer Messages From Past Week ======== . 05/19/2012 8:24:52 AM, error: Service Control Manager [7034] - The User Profile Hive Cleanup service terminated unexpectedly. It has done this 1 time(s). 05/19/2012 8:24:52 AM, error: Service Control Manager [7034] - The BBUpdate service terminated unexpectedly. It has done this 1 time(s). 05/19/2012 8:24:51 AM, error: Service Control Manager [7034] - The SpyHunter 4 Service service terminated unexpectedly. It has done this 1 time(s). 05/19/2012 8:24:51 AM, error: Service Control Manager [7034] - The Pml Driver HPZ12 service terminated unexpectedly. It has done this 1 time(s). 05/19/2012 8:24:51 AM, error: Service Control Manager [7034] - The McciCMService service terminated unexpectedly. It has done this 1 time(s). 05/19/2012 8:24:51 AM, error: Service Control Manager [7034] - The Macrium Reflect Image Mounting Service service terminated unexpectedly. It has done this 1 time(s). 05/19/2012 8:24:51 AM, error: Service Control Manager [7034] - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly. It has done this 1 time(s). 05/19/2012 8:24:51 AM, error: Service Control Manager [7034] - The CLDTVHNService service terminated unexpectedly. It has done this 1 time(s). 05/19/2012 8:24:51 AM, error: Service Control Manager [7034] - The ARSVC service terminated unexpectedly. It has done this 1 time(s). 05/19/2012 8:24:51 AM, error: Service Control Manager [7031] - The SAS Core Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service. 05/19/2012 8:24:51 AM, error: Service Control Manager [7031] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service. 05/16/2012 4:29:55 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 05/16/2012 4:29:43 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 Fips ftsata2 IPSec MpFilter MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip WS2IFSL 05/16/2012 4:29:43 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 05/16/2012 4:29:43 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 05/16/2012 4:29:43 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 05/16/2012 4:29:43 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 05/16/2012 3:54:53 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097} 05/16/2012 3:52:46 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 05/16/2012 3:50:08 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 05/16/2012 3:49:55 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdK8 Fips ftsata2 MpFilter SASDIFSV SASKUTIL 05/12/2012 10:42:48 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ftsata2 05/12/2012 10:42:46 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Google Update Service (gupdate1c9316637dc9d00) service to connect. 05/12/2012 10:42:46 AM, error: Service Control Manager [7000] - The Google Update Service (gupdate1c9316637dc9d00) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. . ==== End Of File =========================== I attached the zipped MBR scan let me know if you received it.

Attachments:

Received it fine thanks but please copy and paste all future logs. I may be a while replying as I have a few things to do but after a quick glance I can see no obvious bad issues. I'll have a better check later. BTW, you didn't answer about the Babylon Toolbar. Satchfan
No I did not add the Babylon toolbar, it just appeared one day……I thought I had removed it. Also I would like to remove the remnants of AVG program. Direct me to the site where I can run the removal tool. .Thanks!
Sorry, I gave you a bad link Try this one:

http://www.grisoft.cz/filedir/util/avg_arm…/avgremover.exe

==================================================

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
    FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
    FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
    FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?AF=109221&babsrc=HP_ss&mntrId=5415158c0000000000000017319e0782"
    FF - prefs.js..keyword.URL: "http://search.babylon.com/?AF=109221&babsrc=adbartrp&mntrId=5415158c0000000000000017319e0782&q="
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)

==================================================

Run Malwarebytes’ Anti-Malware

I see that you have MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Satchfan
Here are the OTL log, and MBAM log. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Prefs.js: "Search the web (Babylon)" removed from browser.search.defaultenginename Prefs.js: "Search the web (Babylon)" removed from browser.search.order.1 Prefs.js: "Search the web (Babylon)" removed from browser.search.selectedEngine Prefs.js: "http://search.babylon.com/?AF=109221&babsrc=HP_ss&mntrId=5415158c0000000000000017319e0782" removed from browser.startup.homepage Prefs.js: "http://search.babylon.com/?AF=109221&babsrc=adbartrp&mntrId=5415158c0000000000000017319e0782&q=" removed from keyword.URL ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: Compaq_Administrator ->Temp folder emptied: 57342915 bytes ->Temporary Internet Files folder emptied: 27639694 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 1178 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 9020 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 23120 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 40593 bytes RecycleBin emptied: 469170 bytes Total Files Cleaned = 82.00 mb OTL by OldTimer - Version 3.2.33.2 log created on 05192012_191009 Files\Folders moved on Reboot… C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\D0NZOLIT\iframe[2].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\6U3U7DZC\index[4].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. Registry entries deleted on Reboot… Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.05.19.07 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Compaq_Administrator :: COMPAQ-PRESARIO [administrator] 05/19/2012 7:17:37 PM mbam-log-2012-05-19 (19-17-37).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 235774 Time elapsed: 7 minute(s), 17 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
I think a final online scan should be enough to show that all is well.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Satchfan
Eset running still, Now at 53% of the scan…..Scanning D drive at present. Still some time to go…..Will post up results as soon as it finishes……At present scan shows 13 infected files…..Looks like it's the Babylon files…….
Eset Scan results! C:\Documents and Settings\Compaq_Administrator\Desktop\Desktop Icons\PDFCreator-1_2_3_setup.exe Win32/Toolbar.Widgi application deleted - quarantined C:\Documents and Settings\Compaq_Administrator\My Documents\cnet_framxpro_zip.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined C:\Program Files\1ClickDownload\uninstall.exe Win32/Adware.1ClickDownload application deleted - quarantined C:\Program Files\PDFCreator\Toolbar\pdfforge Toolbar_setup.exe Win32/Toolbar.Widgi application deleted - quarantined C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP104\A0014929.exe Win32/Toolbar.Widgi application deleted - quarantined C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP104\A0014930.exe Win32/Adware.1ClickDownload application deleted - quarantined C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP104\A0014931.exe Win32/Toolbar.Widgi application deleted - quarantined C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP65\A0007153.exe Win32/Adware.1ClickDownload application deleted - quarantined C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP65\A0007160.dll Win32/Toolbar.Babylon application cleaned by deleting - quarantined C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP65\A0007161.dll Win32/Toolbar.Babylon application cleaned by deleting - quarantined C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP65\A0007162.dll a variant of Win32/Toolbar.Babylon application cleaned by deleting - quarantined C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP65\A0007163.dll Win32/Toolbar.Babylon application cleaned by deleting - quarantined C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP65\A0007165.exe probably a variant of Win32/Toolbar.Babylon application cleaned by deleting - quarantined
Hi LewG

Excellent! Your computer appears to be clean..All infections have been deleted or are in System Restore which we will clear.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

You can delete the DDS and aswMBR logs and programs from your desktop.

Uninstall OTL
  • double-click OTL.exe
  • click the CleanUp! button.
  • select Yes when the Begin cleanup Process? prompt appears.
  • if you are prompted to reboot during the cleanup, select Yes.
  • the tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

===================================================

Create a Restore Point
  • click Start, Run
  • copy and paste the following:

    %SystemRoot%\System32\restore\rstrui.exe

  • press OK
  • choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create
  • when the confirmation screen shows that the restore point has been created, click Close.
Remove old restore points
  • go to Start, Programs, Accessories, System tools, Disk Cleanup
  • when the Disc Cleanup dialog box appears, click OK
  • when it finishes running, a box with tabs will appear, select the ”More options” tab
  • on this tab you will find a section for System Restore
  • if you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.
===================================================

Update and run Malwarebytes. This really is an excellent program that you should also update and run on a regular basis, probably weekly.

===================================================
I also recommend that you read the following:

How to prevent malware by miekiemoes

Safe computing

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI