This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Dell Laptop! [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 5/21/2012 4:12:50 PM - Run 2
OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\Lew\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 44.85% Memory free
4.21 Gb Paging File | 2.92 Gb Available in Paging File | 69.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.74 Gb Total Space | 69.56 Gb Free Space | 50.87% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 0.27 Gb Free Space | 2.72% Space Free | Partition Type: NTFS

Computer Name: CAROL-PC | User Name: Lew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found –
PRC - [2012/05/21 16:10:17 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Lew\Downloads\OTL (1).com
PRC - [2012/04/26 09:12:10 | 000,113,592 | —- | M] (Adobe Systems, Inc.) – C:\Windows\System32\Adobe\Director\SWDNLD.EXE
PRC - [2012/03/26 17:08:12 | 000,931,200 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/02/10 11:28:06 | 000,240,408 | —- | M] (Microsoft Corporation.) – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE
PRC - [2012/02/10 11:28:06 | 000,193,816 | —- | M] (Microsoft Corporation.) – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/08/02 11:53:36 | 000,142,336 | —- | M] (Wavexpress, Inc.) – C:\Program Files\Wavexpress\TVTonic\WXRSS.exe
PRC - [2008/05/04 05:25:32 | 000,040,960 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\hidfind.exe
PRC - [2008/05/04 05:25:26 | 000,167,936 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\Apoint.exe
PRC - [2008/05/04 05:25:26 | 000,050,736 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2008/05/04 05:25:26 | 000,049,152 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\ApntEx.exe
PRC - [2007/11/12 07:07:20 | 000,102,400 | —- | M] (IDT, Inc.) – C:\Windows\System32\stacsv.exe


========== Modules (No Company Name) ==========

MOD - [2012/05/16 20:46:34 | 011,820,032 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\ef684a2ee2f7276eec3973a0654d2bd4\System.Web.ni.dll
MOD - [2012/05/16 20:46:24 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/05/11 17:11:07 | 007,953,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/11 17:10:49 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2010/12/20 16:04:08 | 001,671,840 | —- | M] () – C:\Program Files\WOT\WOT.dll
MOD - [2008/05/19 02:25:24 | 000,054,784 | —- | M] () – C:\Windows\System32\bcmwlrmt.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2012/05/04 21:26:35 | 000,257,696 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/03/26 17:03:40 | 000,214,952 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2012/02/10 11:28:06 | 000,240,408 | —- | M] (Microsoft Corporation.) [On_Demand | Running] – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE – (BBUpdate)
SRV - [2012/02/10 11:28:06 | 000,193,816 | —- | M] (Microsoft Corporation.) [Auto | Running] – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE – (BBSvc)
SRV - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2008/08/02 11:53:36 | 000,142,336 | —- | M] (Wavexpress, Inc.) [Auto | Running] – C:\Program Files\Wavexpress\TVTonic\WXRSS.exe – (WXRSS)
SRV - [2008/07/24 01:20:23 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2008/04/28 17:56:28 | 000,161,048 | —- | M] (Stardock Corporation) [Disabled | Stopped] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV - [2008/01/20 22:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/11/12 07:07:20 | 000,102,400 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\stacsv.exe – (STacSV)
SRV - [2007/11/12 07:07:16 | 000,073,728 | —- | M] (Andrea Electronics Corporation) [Disabled | Stopped] – C:\Windows\System32\AEstSrv.exe – (AESTFilters)
SRV - [2007/03/21 14:00:04 | 000,355,096 | —- | M] (Intel Corporation) [Disabled | Stopped] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – system32\drivers\RT-USB.sys – (RT-USB)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Running] – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys – (esgiguard)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\drivers\BCM42RLY.sys – (BCM42RLY)
DRV - [2012/05/21 16:04:41 | 000,029,904 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C6B3BC2C-2879-44EC-BCD7-C094B0616D1F}\MpKslef200719.sys – (MpKslef200719)
DRV - [2012/03/20 20:44:12 | 000,074,112 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2010/05/10 14:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/17 14:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/05/25 17:01:00 | 000,069,098 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\jl2005c.sys – (JL2005C)
DRV - [2008/05/04 05:25:24 | 000,164,400 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Apfiltr.sys – (ApfiltrService)
DRV - [2008/03/06 03:58:44 | 000,111,616 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV - [2008/01/20 22:23:25 | 000,220,672 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\e1e6032.sys – (e1express) Intel®
DRV - [2008/01/20 22:23:21 | 000,016,896 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\WSDPrint.sys – (WSDPrintDevice)
DRV - [2007/11/12 07:07:28 | 000,330,240 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\stwrt.sys – (STHDA)
DRV - [2007/09/06 12:35:16 | 000,037,376 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2007/09/06 12:35:14 | 000,039,936 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2007/09/06 12:35:12 | 000,042,496 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2006/11/02 03:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/08/04 20:39:10 | 000,008,192 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=0080724
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DMUS


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\.DEFAULT\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DMUS
IE - HKU\.DEFAULT\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\S-1-5-18\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DMUS
IE - HKU\S-1-5-18\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=0080724
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GPEA_en
IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



========== Chrome ==========

CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}

O1 HOSTS File: ([2011/10/03 11:37:36 | 000,434,545 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 14956 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Carol\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Lew\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Lew\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://my.garmin.com/static/m/cab/2.9.1.0/…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{54616514-34E7-4A11-A4D6-37C98C4F228A}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC1269BC-025B-49DB-8A8F-716A88F2C75A}: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Lew\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\Lew\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/05/11 09:56:17 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012/05/11 09:56:17 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2012/05/11 09:56:16 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2012/05/11 09:56:16 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2012/05/11 09:56:16 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2012/05/11 09:55:56 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/05/11 09:55:56 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/05/11 09:55:56 | 002,044,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/05/09 00:05:43 | 000,000,000 | —D | C] – C:\sh4ldr
[2012/05/09 00:05:43 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/05/09 00:04:48 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/05/04 23:17:47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/05/04 23:17:17 | 000,476,960 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2012/05/04 23:17:17 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/05/04 23:17:17 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/05/04 23:17:17 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/05/21 16:02:17 | 000,606,552 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/05/21 16:02:17 | 000,106,376 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/05/21 15:56:31 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/21 15:56:31 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/21 15:56:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/16 20:36:43 | 000,002,519 | —- | M] () – C:\Users\Lew\Desktop\HiJackThis.lnk
[2012/05/13 20:59:47 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/13 17:26:59 | 000,000,193 | —- | M] () – C:\Users\Lew\Desktop\Qualys BrowserCheck.url
[2012/05/11 17:09:03 | 000,271,432 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/05/07 22:22:13 | 000,002,263 | —- | M] () – C:\Users\Lew\Desktop\Watch Kingdom Full Episode 5 Video Online.url
[2012/05/04 23:30:09 | 000,000,281 | —- | M] () – C:\Users\Lew\Desktop\CAROLINE CATZ - EPISODES.url
[2012/05/04 23:16:57 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/05/04 23:16:57 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/05/04 23:16:57 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2012/05/04 23:16:56 | 000,476,960 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2012/05/04 23:16:56 | 000,472,864 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2012/05/04 21:38:57 | 000,000,253 | —- | M] () – C:\Users\Lew\Desktop\Compare Hotel Prices - Best Hotel Deals Guaranteed.url
[2012/05/04 21:26:32 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/05/04 21:26:32 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/05/04 21:14:56 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Six - YouTube.url
[2012/05/04 21:14:43 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Five - YouTube.url
[2012/05/04 21:14:23 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Four - YouTube.url
[2012/05/04 21:13:42 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Three - YouTube.url
[2012/05/04 21:13:22 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Two - YouTube.url
[2012/05/04 21:06:14 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 3-3 - YouTube.url
[2012/05/04 21:05:59 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 2-3 - YouTube.url
[2012/05/04 21:05:42 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 1-3 - YouTube.url
[2012/05/04 21:05:22 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 3-3 - YouTube.url
[2012/05/04 21:02:15 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 2-3 - YouTube.url
[2012/05/04 21:02:00 | 000,000,355 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 1-3 - YouTube.url
[2012/05/04 20:55:52 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 5. - YouTube.url
[2012/05/04 20:55:38 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 4. - YouTube.url
[2012/05/04 20:55:23 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 3. - YouTube.url
[2012/05/04 20:55:10 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 2. - YouTube.url
[2012/04/27 11:05:22 | 000,000,356 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part One - YouTube.url
[2012/04/26 18:48:12 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012/04/23 00:40:36 | 000,000,403 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 1. - YouTube.url
[2012/04/23 00:29:08 | 000,005,191 | —- | M] () – C:\Users\Lew\Desktop\Watch Red Shoe Diaries Online, Full Episodes of Season 1 to 5 Yidio.url
[2012/04/22 21:55:32 | 000,000,638 | —- | M] () – C:\Users\Lew\Desktop\VCDS Release 11.11.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/05/13 20:59:47 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/13 17:26:59 | 000,000,193 | —- | C] () – C:\Users\Lew\Desktop\Qualys BrowserCheck.url
[2012/05/07 22:22:13 | 000,002,263 | —- | C] () – C:\Users\Lew\Desktop\Watch Kingdom Full Episode 5 Video Online.url
[2012/05/04 23:30:09 | 000,000,281 | —- | C] () – C:\Users\Lew\Desktop\CAROLINE CATZ - EPISODES.url
[2012/05/04 21:14:56 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Six - YouTube.url
[2012/05/04 21:14:42 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Five - YouTube.url
[2012/05/04 21:14:23 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Four - YouTube.url
[2012/05/04 21:13:42 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Three - YouTube.url
[2012/05/04 21:13:22 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Two - YouTube.url
[2012/05/04 21:06:14 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 3-3 - YouTube.url
[2012/05/04 21:05:58 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 2-3 - YouTube.url
[2012/05/04 21:05:41 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 1-3 - YouTube.url
[2012/05/04 21:05:22 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 3-3 - YouTube.url
[2012/05/04 21:02:15 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 2-3 - YouTube.url
[2012/05/04 21:02:00 | 000,000,355 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 1-3 - YouTube.url
[2012/05/04 20:55:52 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 5. - YouTube.url
[2012/05/04 20:55:38 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 4. - YouTube.url
[2012/05/04 20:55:23 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 3. - YouTube.url
[2012/05/04 20:55:10 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 2. - YouTube.url
[2012/04/27 11:05:22 | 000,000,356 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part One - YouTube.url
[2012/04/26 18:48:11 | 000,001,828 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/04/23 00:40:36 | 000,000,403 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 1. - YouTube.url
[2012/04/23 00:29:08 | 000,005,191 | —- | C] () – C:\Users\Lew\Desktop\Watch Red Shoe Diaries Online, Full Episodes of Season 1 to 5 Yidio.url
[2011/11/13 18:15:45 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/10/02 14:01:03 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/10/02 13:51:12 | 000,038,868 | —- | C] () – C:\Windows\hpomdl03.dat.temp
[2011/10/02 13:51:12 | 000,029,359 | —- | C] () – C:\Windows\hpoins03.dat.temp
[2011/10/02 13:48:28 | 000,000,091 | —- | C] () – C:\Users\Lew\AppData\Local\fusioncache.dat
[2011/07/07 00:03:30 | 000,017,408 | —- | C] () – C:\Users\Lew\AppData\Local\WebpageIcons.db

< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!! :thumbup:
———-

Do you still need help? Sorry for any delay. :)
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-05-25 16:14:04 —————————– 16:14:04.186 OS Version: Windows 6.0.6002 Service Pack 2 16:14:04.187 Number of processors: 2 586 0xF0D 16:14:04.188 ComputerName: CAROL-PC UserName: Lew 16:14:05.295 Initialize success 16:14:13.974 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 16:14:13.977 Disk 0 Vendor: Hitachi_ BBCO Size: 152627MB BusType: 3 16:14:13.991 Disk 0 MBR read successfully 16:14:13.994 Disk 0 MBR scan 16:14:13.997 Disk 0 Windows VISTA default MBR code 16:14:14.001 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 16:14:14.012 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10000 MB offset 81920 16:14:14.026 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 140026 MB offset 20561920 16:14:14.030 Disk 0 Partition - 00 0F Extended LBA 2559 MB offset 307337216 16:14:14.077 Disk 0 Partition 4 00 DD MSDOS5.0 2558 MB offset 307339264 16:14:14.083 Disk 0 scanning sectors +312578048 16:14:14.139 Disk 0 scanning C:\Windows\system32\drivers 16:14:22.522 Service scanning 16:14:37.594 Service MpKsl332c8056 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C6B3BC2C-2879-44EC-BCD7-C094B0616D1F}\MpKsl332c8056.sys **LOCKED** 32 16:15:02.298 Modules scanning 16:15:26.583 Disk 0 trace - called modules: 16:15:26.606 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll 16:15:26.607 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8593d690] 16:15:26.607 3 CLASSPNP.SYS[883a78b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84de9030] 16:15:26.608 Scan finished successfully 16:16:30.361 Disk 0 MBR has been saved successfully to "C:\Users\Lew\Desktop\MBR.dat" 16:16:30.371 The log file has been saved successfully to "C:\Users\Lew\Desktop\aswMBR.txt"
Hi,

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
    IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
    IE - HKU\S-1-5-21-2218398561-541322015-3387695361-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-2218398561-541322015-3387695361-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Lew\Downloads\cmd.bat deleted successfully.
C:\Users\Lew\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 187987 bytes
->Temporary Internet Files folder emptied: 15542147 bytes
->Flash cache emptied: 57001 bytes

User: All Users

User: Carol
->Temp folder emptied: 98406226 bytes
->Temporary Internet Files folder emptied: 277959576 bytes
->Java cache emptied: 519718 bytes
->Flash cache emptied: 145646 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56545 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 66044 bytes
->Temporary Internet Files folder emptied: 19989917 bytes
->Flash cache emptied: 659 bytes

User: Lew
->Temp folder emptied: 35758 bytes
->Temporary Internet Files folder emptied: 3147580 bytes
->Java cache emptied: 2061 bytes
->Google Chrome cache emptied: 49299874 bytes
->Flash cache emptied: 2506 bytes

User: Public

User: TEMP

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1639098 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 24307 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 5461656 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 595968 bytes

Total Files Cleaned = 451.00 mb


OTL by OldTimer - Version 3.2.43.1 log created on 05252012_223705

Files\Folders moved on Reboot…
C:\Windows\temp\JET2BE0.tmp moved successfully.

Registry entries deleted on Reboot…


OTL logfile created on: 5/25/2012 10:47:19 PM - Run 3
OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\Lew\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.93 Gb Available Physical Memory | 46.85% Memory free
4.21 Gb Paging File | 3.13 Gb Available in Paging File | 74.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.74 Gb Total Space | 70.05 Gb Free Space | 51.23% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 0.27 Gb Free Space | 2.72% Space Free | Partition Type: NTFS

Computer Name: CAROL-PC | User Name: Lew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/05/25 22:35:53 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Lew\Downloads\OTL.com
PRC - [2012/03/26 17:08:12 | 000,931,200 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/02/10 11:28:06 | 000,193,816 | —- | M] (Microsoft Corporation.) – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE
PRC - [2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/08/02 11:53:36 | 000,142,336 | —- | M] (Wavexpress, Inc.) – C:\Program Files\Wavexpress\TVTonic\WXRSS.exe
PRC - [2008/05/04 05:25:32 | 000,040,960 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\hidfind.exe
PRC - [2008/05/04 05:25:26 | 000,167,936 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\Apoint.exe
PRC - [2008/05/04 05:25:26 | 000,050,736 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2008/05/04 05:25:26 | 000,049,152 | —- | M] (Alps Electric Co., Ltd.) – C:\Program Files\DellTPad\ApntEx.exe
PRC - [2007/11/12 07:07:20 | 000,102,400 | —- | M] (IDT, Inc.) – C:\Windows\System32\stacsv.exe


========== Modules (No Company Name) ==========

MOD - [2012/05/16 20:46:34 | 011,820,032 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\ef684a2ee2f7276eec3973a0654d2bd4\System.Web.ni.dll
MOD - [2012/05/16 20:46:24 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/05/11 17:11:07 | 007,953,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/11 17:10:49 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2010/12/20 16:04:08 | 001,671,840 | —- | M] () – C:\Program Files\WOT\WOT.dll
MOD - [2009/01/18 16:50:02 | 000,417,792 | —- | M] () – C:\Program Files\Adobe\Reader 9.0\Reader\AdobeXMP.dll
MOD - [2008/05/19 02:25:24 | 000,054,784 | —- | M] () – C:\Windows\System32\bcmwlrmt.dll
MOD - [2007/11/16 17:02:18 | 000,479,232 | R— | M] () – C:\Program Files\Adobe\Reader 9.0\Reader\ccme_base.dll
MOD - [2007/11/16 17:02:18 | 000,401,408 | R— | M] () – C:\Program Files\Adobe\Reader 9.0\Reader\cryptocme2.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2012/05/04 21:26:35 | 000,257,696 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/03/26 17:03:40 | 000,214,952 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV - [2012/02/10 11:28:06 | 000,240,408 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE – (BBUpdate)
SRV - [2012/02/10 11:28:06 | 000,193,816 | —- | M] (Microsoft Corporation.) [Auto | Running] – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE – (BBSvc)
SRV - [2008/11/09 16:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2008/08/02 11:53:36 | 000,142,336 | —- | M] (Wavexpress, Inc.) [Auto | Running] – C:\Program Files\Wavexpress\TVTonic\WXRSS.exe – (WXRSS)
SRV - [2008/07/24 01:20:23 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2008/04/28 17:56:28 | 000,161,048 | —- | M] (Stardock Corporation) [Disabled | Stopped] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV - [2008/01/20 22:23:32 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/11/12 07:07:20 | 000,102,400 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\System32\stacsv.exe – (STacSV)
SRV - [2007/11/12 07:07:16 | 000,073,728 | —- | M] (Andrea Electronics Corporation) [Disabled | Stopped] – C:\Windows\System32\AEstSrv.exe – (AESTFilters)
SRV - [2007/03/21 14:00:04 | 000,355,096 | —- | M] (Intel Corporation) [Disabled | Stopped] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – system32\drivers\RT-USB.sys – (RT-USB)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys – (esgiguard)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\drivers\BCM42RLY.sys – (BCM42RLY)
DRV - [2012/03/20 20:44:12 | 000,074,112 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\NisDrvWFP.sys – (NisDrv)
DRV - [2010/05/10 14:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/17 14:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/05/25 17:01:00 | 000,069,098 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\jl2005c.sys – (JL2005C)
DRV - [2008/05/04 05:25:24 | 000,164,400 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\Apfiltr.sys – (ApfiltrService)
DRV - [2008/03/06 03:58:44 | 000,111,616 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\IntcHdmi.sys – (IntcHdmiAddService) Intel®
DRV - [2008/01/20 22:23:25 | 000,220,672 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\e1e6032.sys – (e1express) Intel®
DRV - [2008/01/20 22:23:21 | 000,016,896 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\WSDPrint.sys – (WSDPrintDevice)
DRV - [2007/11/12 07:07:28 | 000,330,240 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\stwrt.sys – (STHDA)
DRV - [2007/09/06 12:35:16 | 000,037,376 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2007/09/06 12:35:14 | 000,039,936 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2007/09/06 12:35:12 | 000,042,496 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\System32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2006/11/02 03:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/08/04 20:39:10 | 000,008,192 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=0080724
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…amp;rlz=1I7DMUS

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=0080724
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GPEA_en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



========== Chrome ==========

CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}

O1 HOSTS File: ([2011/10/03 11:37:36 | 000,434,545 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 14956 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Lew\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Lew\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://my.garmin.com/static/m/cab/2.9.1.0/…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{54616514-34E7-4A11-A4D6-37C98C4F228A}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC1269BC-025B-49DB-8A8F-716A88F2C75A}: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Lew\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\Lew\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/05/25 22:37:05 | 000,000,000 | —D | C] – C:\_OTL
[2012/05/25 22:35:13 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/05/25 22:34:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/05/25 22:34:29 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/05/11 09:56:17 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012/05/11 09:56:17 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2012/05/11 09:56:16 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2012/05/11 09:56:16 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2012/05/11 09:56:16 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2012/05/11 09:55:56 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/05/11 09:55:56 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/05/11 09:55:56 | 002,044,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/05/09 00:05:43 | 000,000,000 | —D | C] – C:\sh4ldr
[2012/05/09 00:05:43 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012/05/09 00:04:48 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2012/05/04 23:17:47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/05/04 23:17:17 | 000,476,960 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2012/05/04 23:17:17 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/05/04 23:17:17 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/05/04 23:17:17 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe

========== Files - Modified Within 30 Days ==========

[2012/05/25 22:50:35 | 000,606,552 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/05/25 22:50:35 | 000,106,376 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/05/25 22:43:38 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/25 22:43:38 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/25 22:43:33 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/25 22:34:32 | 000,000,735 | —- | M] () – C:\Users\Lew\Desktop\NTREGOPT.lnk
[2012/05/25 22:34:31 | 000,000,716 | —- | M] () – C:\Users\Lew\Desktop\ERUNT.lnk
[2012/05/25 16:19:38 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2012/05/25 16:16:30 | 000,000,512 | —- | M] () – C:\Users\Lew\Desktop\MBR.dat
[2012/05/21 16:43:09 | 000,073,360 | —- | M] () – C:\Users\Lew\Documents\cc_20120521_164259.reg
[2012/05/16 20:36:43 | 000,002,519 | —- | M] () – C:\Users\Lew\Desktop\HiJackThis.lnk
[2012/05/13 20:59:47 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/13 17:26:59 | 000,000,193 | —- | M] () – C:\Users\Lew\Desktop\Qualys BrowserCheck.url
[2012/05/11 17:09:03 | 000,271,432 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/05/07 22:22:13 | 000,002,263 | —- | M] () – C:\Users\Lew\Desktop\Watch Kingdom Full Episode 5 Video Online.url
[2012/05/04 23:30:09 | 000,000,281 | —- | M] () – C:\Users\Lew\Desktop\CAROLINE CATZ - EPISODES.url
[2012/05/04 23:16:57 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2012/05/04 23:16:57 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2012/05/04 23:16:57 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2012/05/04 23:16:56 | 000,476,960 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\npdeployJava1.dll
[2012/05/04 23:16:56 | 000,472,864 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2012/05/04 21:38:57 | 000,000,253 | —- | M] () – C:\Users\Lew\Desktop\Compare Hotel Prices - Best Hotel Deals Guaranteed.url
[2012/05/04 21:26:32 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/05/04 21:26:32 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/05/04 21:14:56 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Six - YouTube.url
[2012/05/04 21:14:43 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Five - YouTube.url
[2012/05/04 21:14:23 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Four - YouTube.url
[2012/05/04 21:13:42 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Three - YouTube.url
[2012/05/04 21:13:22 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part Two - YouTube.url
[2012/05/04 21:06:14 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 3-3 - YouTube.url
[2012/05/04 21:05:59 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 2-3 - YouTube.url
[2012/05/04 21:05:42 | 000,000,401 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 1-3 - YouTube.url
[2012/05/04 21:05:22 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 3-3 - YouTube.url
[2012/05/04 21:02:15 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 2-3 - YouTube.url
[2012/05/04 21:02:00 | 000,000,355 | —- | M] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 1-3 - YouTube.url
[2012/05/04 20:55:52 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 5. - YouTube.url
[2012/05/04 20:55:38 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 4. - YouTube.url
[2012/05/04 20:55:23 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 3. - YouTube.url
[2012/05/04 20:55:10 | 000,000,400 | —- | M] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 2. - YouTube.url
[2012/04/27 11:05:22 | 000,000,356 | —- | M] () – C:\Users\Lew\Desktop\Deep End Part One - YouTube.url
[2012/04/26 18:48:12 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif

========== Files Created - No Company Name ==========

[2012/05/25 22:34:32 | 000,000,735 | —- | C] () – C:\Users\Lew\Desktop\NTREGOPT.lnk
[2012/05/25 22:34:31 | 000,000,716 | —- | C] () – C:\Users\Lew\Desktop\ERUNT.lnk
[2012/05/25 16:16:30 | 000,000,512 | —- | C] () – C:\Users\Lew\Desktop\MBR.dat
[2012/05/21 16:43:04 | 000,073,360 | —- | C] () – C:\Users\Lew\Documents\cc_20120521_164259.reg
[2012/05/13 20:59:47 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/13 17:26:59 | 000,000,193 | —- | C] () – C:\Users\Lew\Desktop\Qualys BrowserCheck.url
[2012/05/07 22:22:13 | 000,002,263 | —- | C] () – C:\Users\Lew\Desktop\Watch Kingdom Full Episode 5 Video Online.url
[2012/05/04 23:30:09 | 000,000,281 | —- | C] () – C:\Users\Lew\Desktop\CAROLINE CATZ - EPISODES.url
[2012/05/04 21:14:56 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Six - YouTube.url
[2012/05/04 21:14:42 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Five - YouTube.url
[2012/05/04 21:14:23 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Four - YouTube.url
[2012/05/04 21:13:42 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Three - YouTube.url
[2012/05/04 21:13:22 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part Two - YouTube.url
[2012/05/04 21:06:14 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 3-3 - YouTube.url
[2012/05/04 21:05:58 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 2-3 - YouTube.url
[2012/05/04 21:05:41 | 000,000,401 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 5, Part 1-3 - YouTube.url
[2012/05/04 21:05:22 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 3-3 - YouTube.url
[2012/05/04 21:02:15 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 2-3 - YouTube.url
[2012/05/04 21:02:00 | 000,000,355 | —- | C] () – C:\Users\Lew\Desktop\William and Mary - Series 2, Ep 4, Part 1-3 - YouTube.url
[2012/05/04 20:55:52 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 5. - YouTube.url
[2012/05/04 20:55:38 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 4. - YouTube.url
[2012/05/04 20:55:23 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 3. - YouTube.url
[2012/05/04 20:55:10 | 000,000,400 | —- | C] () – C:\Users\Lew\Desktop\M.I.S.E.1. Part 2. - YouTube.url
[2012/04/27 11:05:22 | 000,000,356 | —- | C] () – C:\Users\Lew\Desktop\Deep End Part One - YouTube.url
[2012/04/26 18:48:11 | 000,001,828 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/11/13 18:15:45 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/10/02 14:01:03 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/10/02 13:51:12 | 000,038,868 | —- | C] () – C:\Windows\hpomdl03.dat.temp
[2011/10/02 13:51:12 | 000,029,359 | —- | C] () – C:\Windows\hpoins03.dat.temp
[2011/10/02 13:48:28 | 000,000,091 | —- | C] () – C:\Users\Lew\AppData\Local\fusioncache.dat
[2011/07/07 00:03:30 | 000,017,408 | —- | C] () – C:\Users\Lew\AppData\Local\WebpageIcons.db

< End of report >



I will be away from the Laptop all day tomorrow. Back Sunday! Let's continue then.
Hi,

That sounds fine.

When you do:

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats is NOT selected and the option Scan unwanted applications is selected.
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
———-

Post the logs made by Malwarebytes and ESET online scanner. :)
Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.05.26.06 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Lew :: CAROL-PC [administrator] 5/26/2012 6:51:48 PM mbam-log-2012-05-26 (18-51-48).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 274672 Time elapsed: 8 minute(s), 54 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) Ran Eset online scanner and no infections were found.
Great!!

Please open OTL.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the Extra Registry section change it to All
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open 2 notepad windows, OTL.Txt and Extra.txt. Please post the Extra.txt.
———-
OTL logfile created on: 5/29/2012 12:37:47 PM - Run 4
OTL by OldTimer - Version 3.2.43.1 Folder = c:\Users\Lew\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 42.67% Memory free
4.21 Gb Paging File | 2.83 Gb Available in Paging File | 67.20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.74 Gb Total Space | 70.34 Gb Free Space | 51.44% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 0.00 Gb Free Space | 0.03% Space Free | Partition Type: NTFS

Computer Name: CAROL-PC | User Name: Lew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

< End of report >



OTL Extras logfile created on: 5/29/2012 12:37:47 PM - Run 4
OTL by OldTimer - Version 3.2.43.1 Folder = c:\Users\Lew\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 42.67% Memory free
4.21 Gb Paging File | 2.83 Gb Available in Paging File | 67.20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.74 Gb Total Space | 70.34 Gb Free Space | 51.44% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 0.00 Gb Free Space | 0.03% Space Free | Partition Type: NTFS

Computer Name: CAROL-PC | User Name: Lew | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.bat [@ = batfile] – "%1" %*
.chm [@ = chm.file] – C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] – "%1" %*
.com [@ = comfile] – "%1" %*
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.exe [@ = exefile] – "%1" %*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – "%1" %*
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf [@ = inffile] – C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] – C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\Windows\System32\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] – "%1" %*
.reg [@ = regfile] – C:\Windows\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] – "%1" /S
.txt [@ = txtfile] – C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\Windows\System32\WScript.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] – "%1" %*
batfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] – "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] – "%1" %*
cmdfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile – C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] – C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] – C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile – C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] – C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] – C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile – %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
regfile [print] – %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
txtfile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] – %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] – "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] – "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] – "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] – "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05116BB9-D59F-4133-95C4-E96A27E494D4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{0C75BA56-CBA8-4D5D-B061-8A4B9446CD6C}" = rport=139 | protocol=6 | dir=out | app=system |
"{138F77AA-8965-4FD3-9F4A-E95844460AA3}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{1C1F988C-F235-41CB-81C0-299C907266AF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2818F1C4-8AFC-46C8-9D65-B6503F777CE1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{285036FB-4F86-4A17-B5AC-49F1D27F3B15}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{31E4D86F-49B6-4098-9F72-630734EA1108}" = lport=139 | protocol=6 | dir=in | app=system |
"{3FBD850B-26CA-4FF7-AF5F-04561EEA5628}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4DE84B22-AAD4-46CB-B58D-7EF4EDEB522F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{56F1F01B-8081-4A83-BF6C-73FEEDED8273}" = lport=2869 | protocol=6 | dir=in | app=system |
"{59618F70-3ED0-48B0-877E-B483D2053AF5}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{62CD0311-E23C-4F7E-A365-1FACD08AE4AB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7685CAFA-A5B0-4301-8E5D-E1E86308635A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8F1370C8-AD1E-4B1D-8D17-B4FEC959B20B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9355D961-A8D6-4785-8E7A-9876289DB1F0}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{936F5BB6-DFC1-4487-B3FD-67C9021524FD}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9EAC0BED-7F85-4C35-BB5E-71102732AED7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B2D66044-6D02-46AF-980F-8952A861AECD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B2E0D749-560E-4248-9E32-8C99F99A5D30}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{BB88F860-8B2C-4BFF-9058-01877E6F228E}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{BD412C20-5E40-4A15-9176-9FEE53378319}" = rport=138 | protocol=17 | dir=out | app=system |
"{C348DBF9-1D41-4759-AC1B-4EE690D7930C}" = lport=138 | protocol=17 | dir=in | app=system |
"{C40A1DBB-9721-4630-8471-FFE848DA0779}" = rport=445 | protocol=6 | dir=out | app=system |
"{DD7E8A20-E378-477B-98A0-45D4AF35BAD6}" = lport=137 | protocol=17 | dir=in | app=system |
"{DDB1ED30-7FD4-4EB5-9AE3-85D15CE99BE9}" = lport=445 | protocol=6 | dir=in | app=system |
"{F9A68BAB-3FA7-412C-BE35-A9CB475EBF39}" = rport=137 | protocol=17 | dir=out | app=system |
"{FD028249-6301-4A6E-81AE-3757A39ED631}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0C89DF31-67FF-4BF5-BCE2-2BA967C71D42}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1004B372-9F07-4482-8D98-81AB1D5B21D8}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{109EC9E2-6DEB-42BE-9D58-7EB3EBA33711}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\devicesetup.exe |
"{1876C485-BB25-469B-90F0-748FD2C779EB}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dmp\clbrowserengine.exe |
"{1ECAE768-AB69-4181-BD9A-948B4B5E4824}" = protocol=6 | dir=out | app=system |
"{25DDDBDD-7C1B-423D-AF70-568B042D214D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{29DDF941-0369-4CC5-8CB9-1D1CCEA5A9FD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3BBE2828-0B66-4F02-BDCD-4F800CC1FC23}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{43FA4229-473D-4598-A726-7F0F4600A247}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{554077CC-3640-49D2-A8D2-FFAD76A66105}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{566710BA-D24C-44F4-8732-6D2A9EB53CDB}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{64ADC60B-7A14-4AE8-8204-E7E5CDFCD8CF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{689F8E3E-1F6D-4489-A6F5-46D8DF94F830}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{721722A0-289C-4AC4-919E-A37C47018A2F}" = dir=in | app=c:\program files\dell\mediadirect\pcmservice.exe |
"{74F2ED02-6A16-4BF6-917F-BA11EEC9B66E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{80D7FEA1-3A59-4E74-B12A-3557A5A38FDD}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{89F80860-B52F-4995-8B6C-39730A543AEF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9231A59D-4300-4EDD-8E5E-87D079C3069D}" = dir=in | app=c:\program files\dell\mediadirect\kernel\dms\clmsservice.exe |
"{9AE38383-B080-41EE-885F-A31E73F63574}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\devicesetup.exe |
"{A46E4327-AD4B-4EEB-9E00-DAA967D6B83D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{AC650863-CAD3-460D-AC26-911523CF1FA9}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\devicesetup.exe |
"{B2D86227-DB77-4C64-9CED-C9B21C4183E2}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\devicesetup.exe |
"{C4110C11-3379-4662-85C5-E3AACFE4C2CA}" = dir=in | app=c:\program files\dell\mediadirect\mediadirect.exe |
"{C747D5CC-1833-4F02-97BE-E69FDB096F12}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CA3E03AB-0B03-48B4-A397-5CF6D3D51643}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E4C3D6AC-2441-4F1C-836F-EFFD6EF9F3E2}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E84A9AC1-1549-449F-B9BC-60E3959AE873}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{E8D3FF2B-0772-4BED-97CF-25435F504CB7}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{EB5E901B-9BE3-4931-87E0-DD9839C18AC6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EE75A81F-A212-4BC5-BD8A-56B6EA3B606F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EF55B84D-15AA-4BE0-88C9-7933899925F7}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{FCE5DF83-AD46-44B7-92C8-100A451453CD}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"TCP Query User{5363A1F3-612B-451E-9802-9DA4DDB806BD}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{99EC3129-C412-422F-A8F4-8611FAE08DE1}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"TCP Query User{C2CB4126-B46D-443E-81F6-A3B7F2DA1729}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{D44963E1-DC88-4AB0-8C04-6ACCEF2E9BD5}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{39FD92BE-8E28-4195-8E6D-11E20DE03F25}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{6DF8DFCA-7890-4132-A7B1-63197A1347E5}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{97B59DAB-8E59-4D28-82FC-254CC9D1B673}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
"UDP Query User{F25067BC-704E-417B-86A4-8CB0C3918D95}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0090A87C-3E0E-43D4-AA71-A71B06563A4A}" = Dell Support Center
"{0563178E-80EF-42C8-ABB6-F33339ACA65E}" = TVTonic With NBC Olympics
"{0564C76B-8E1F-4157-8654-B0F9F308BEE9}" = HP Deskjet 3050 J610 series Basic Device Software
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0F842B77-56EA-4AAF-8295-81A022350B5E}" = Microsoft Security Client
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D10C273-3F95-42A2-8371-AB6B1F59821B}" = WOT for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java™ 6 Update 32
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{34E90074-C80C-4182-A995-65E88B5B56E0}" = HP Deskjet 3050 J610 series Product Improvement Study
"{38B9A4E1-4482-44D9-AC14-64F70938CCB5}" = Garmin MapSource
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{479F8C12-576B-4A58-AB78-4B70F7012AA8}" = DIRECTV2PC Playback Advisor
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B6AD248-D3BF-426A-8D64-847288154F13}" = QuickSet
"{4D3C9F4B-4B7D-4E5D-99B9-0123AB0D51ED}" = Dell DataSafe Online
"{4E5386F5-C0F6-4532-A54A-374865AEAB71}" = Cisco PEAP Module
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5E3CFCA6-C95A-47CB-A822-7FA80D423AF2}" = MapSource
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}" = EDocs
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{76F9CF97-FC4B-4E20-B363-D127C888448F}" = Cisco LEAP Module
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A0F584A7-B0C2-4D90-9580-15456B9CF63C}" = MapSource - Trip & Waypoint Manager v2
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1
"{AC76BA86-7AD7-5464-3428-800000000003}" = Spelling Dictionaries Support For Adobe Reader 8
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B935C985-A17F-484B-8470-09E4FC27DC26}" = Dell-eBay
"{BC70488C-D4EF-42C2-A60D-20A3C14335D2}" = Weather Exchange
"{BF53252E-4AB2-4C7F-A0FD-6100755745E3}" = Cisco EAP-FAST Module
"{C39A4E1F-9AF1-4FE1-A80E-A5B867FABB42}" = Dell Best of Web
"{C3EBEF79-DE34-44AE-8774-F6A17ABE27B2}" = Garmin nRoute
"{C7DD94A8-F775-426C-B56C-8E555A59F9E2}" = Garmin Communicator Plugin
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D186329B-1B4D-408D-ABEC-EA5CE1F182C9}" = Overland
"{D6C3C9E7-D334-4918-BD57-5B1EF14C207D}" = Bing Bar
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock
"{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}" = HP Deskjet 3050 J610 series Help
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"B4DFFB06B716298277125094C48185BFE8B5A7E1" = Windows Driver Package - Ross-Tech USB Driver Package (06/16/2010 2.06.02)
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Dell Support Center" = Dell Support Center
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"GoToAssist" = GoToAssist 8.0.0.514
"HaaliMkx" = Haali Media Splitter
"HijackThis" = HijackThis 1.99.1
"Hijackthis_is1" = Hijackthis 1.99.1
"HP Photo Creations" = HP Photo Creations
"InstallShield_{479F8C12-576B-4A58-AB78-4B70F7012AA8}" = DIRECTV2PC Playback Advisor
"InstallShield_{A0F584A7-B0C2-4D90-9580-15456B9CF63C}" = MapSource - Trip & Waypoint Manager v2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"PartyPoker" = PartyPoker
"ST606_2011_0111_1248_is1" = Uninstall Dual Mode Camera (ST606)
"TaxACT 2009" = TaxACT 2009
"VCDS Release 10.6" = VCDS Release 10.6.5
"VCDS Release 11.11" = VCDS Release 11.11.3
"VCDS Release 805" = VCDS Release 805.4
"VCDS Release 908" = VCDS Release 908.2
"Vivitar Experience Image Manager" = Vivitar Experience Image Manager
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hi,

Let's get some updates and we are almost finished….. :)

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 9.5.1 first. Be sure to move any PDF documents to another folder first though.
———-

Let me know if you had any problems with the instructions above and if there are anymore malware related problems. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI