Noviciate: Thank you for your help!!!
Here is the Spy Sweeper Log:
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
5:32 PM: Shield States
5:32 PM: Spyware Definitions: 783
5:31 PM: Spy Sweeper 5.0.5.1286 started
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
5:27 PM: Shield States
5:27 PM: Spyware Definitions: 783
5:26 PM: Spy Sweeper 5.0.5.1286 started
4:50 PM: | End of Session, Wednesday, October 18, 2006 |
4:48 PM: Your spyware definitions have been updated.
Operation: File Access
Target:
Source: C:\PROGRA~1\MCAFEE.COM\VSO\MCSHIELD.EXE
4:48 PM: Tamper Detection
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
4:45 PM: Shield States
4:45 PM: Spyware Definitions: 691
4:45 PM: Spy Sweeper 5.0.5.1286 started
4:45 PM: Spy Sweeper 5.0.5.1286 started
4:45 PM: | Start of Session, Wednesday, October 18, 2006 |
********
5:23 PM: Removal process completed. Elapsed time 00:00:18
5:23 PM: Preparing to restart your computer. Please wait…
5:23 PM: Quarantining All Traces: 2o7.net cookie
5:23 PM: Quarantining All Traces: webtrends cookie
5:23 PM: Quarantining All Traces: commission junction cookie
5:23 PM: Quarantining All Traces: atlas dmt cookie
5:23 PM: Quarantining All Traces: trojan-backdoor-rustock
5:23 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\dj kay slay - rollin 25 deep feat. jae millz, j.r. writer, grafh, posta boy, cory gunz, stack bundles, main-o. john doe, papoose. murda mook, true life, aasim, saigon, pistol p.mp3 is in use. It will be removed on reboot.
5:23 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\drum and bass 3- shaylor - tribal 1 this track rocks ( techno tekno acid rave jungle dj drum bass electronic funk vinyl dance industrial trance juno beat tech vs remix hardcore.mp3 is in use. It will be removed on reboot.
5:23 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\2pac, snoop dogg, dr. dre, 50 cent, spm, ludacris, al pacino, scarface, methodman,redman, ice cube, big pun, busta rhymes, dmx, nwa, d12, eminem, lil flip, obie trice, outkast.jpg is in use. It will be removed on reboot.
5:23 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\mxpx, blink 182, nofx, sum 41, offspring, green day, relient k, slick shoes, lagwagon, less than jake, ace troubleshooter, new found glory, ramones, pennywise, unwritten law, y.mp3 is in use. It will be removed on reboot.
5:23 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\tequila ( twista kanye west snoop ludacris jayz cassidy r kelly wu tang redman eminem nate dogg 50 cent g unit b2k beyonce britney spears christina aguilera missy elliott outka.mp3 is in use. It will be removed on reboot.
5:23 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\ultimate best loops libraries 4 acid fruity loops reason home studios musician tools sample 3packed full loops library cd roms by music artist mike night of stilo novo read faq.zip is in use. It will be removed on reboot.
5:23 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\illegal_street_racing_europe_rally_drift_drifting_bad_ass_monster_burn_s90_740_tic_turbo_powervolvo960_race_racing_cars_nice_cool_crazy_fast_xxx_teen_illegal_ferrari_battle_por.mpg is in use. It will be removed on reboot.
5:23 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\respect (unreleased) ft snoop ludacris jayz cassidy r kelly wu tang redman eminem nate dogg 50 cent g unit b2k beyonce britney spears christina aguilera missy elliott outkast a.mp3 is in use. It will be removed on reboot.
5:23 PM: potentially rootkit-masked files is in use. It will be removed on reboot.
5:23 PM: Quarantining All Traces: potentially rootkit-masked files
5:23 PM: Removal process initiated
5:21 PM: Traces Found: 13
5:21 PM: Full Sweep has completed. Elapsed time 00:30:40
5:21 PM: File Sweep Complete, Elapsed Time: 00:27:44
5:19 PM: Warning: Stream read error
5:19 PM: Warning: Stream read error
5:19 PM: Warning: Stream read error
5:19 PM: Warning: Stream read error
5:19 PM: Warning: Stream read error
5:19 PM: Warning: Stream read error
5:18 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\dj kay slay - rollin 25 deep feat. jae millz, j.r. writer, grafh, posta boy, cory gunz, stack bundles, main-o. john doe, papoose. murda mook, true life, aasim, saigon, pistol p.mp3 (ID = 0)
5:18 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\drum and bass 3- shaylor - tribal 1 this track rocks ( techno tekno acid rave jungle dj drum bass electronic funk vinyl dance industrial trance juno beat tech vs remix hardcore.mp3 (ID = 0)
5:18 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\2pac, snoop dogg, dr. dre, 50 cent, spm, ludacris, al pacino, scarface, methodman,redman, ice cube, big pun, busta rhymes, dmx, nwa, d12, eminem, lil flip, obie trice, outkast.jpg (ID = 0)
5:18 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\mxpx, blink 182, nofx, sum 41, offspring, green day, relient k, slick shoes, lagwagon, less than jake, ace troubleshooter, new found glory, ramones, pennywise, unwritten law, y.mp3 (ID = 0)
5:18 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\tequila ( twista kanye west snoop ludacris jayz cassidy r kelly wu tang redman eminem nate dogg 50 cent g unit b2k beyonce britney spears christina aguilera missy elliott outka.mp3 (ID = 0)
5:18 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\ultimate best loops libraries 4 acid fruity loops reason home studios musician tools sample 3packed full loops library cd roms by music artist mike night of stilo novo read faq.zip (ID = 0)
5:18 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\illegal_street_racing_europe_rally_drift_drifting_bad_ass_monster_burn_s90_740_tic_turbo_powervolvo960_race_racing_cars_nice_cool_crazy_fast_xxx_teen_illegal_ferrari_battle_por.mpg (ID = 0)
5:18 PM: c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\respect (unreleased) ft snoop ludacris jayz cassidy r kelly wu tang redman eminem nate dogg 50 cent g unit b2k beyonce britney spears christina aguilera missy elliott outkast a.mp3 (ID = 0)
5:18 PM: Found System Monitor: potentially rootkit-masked files
5:18 PM: Warning: Failed to access drive H:
5:18 PM: Warning: Failed to access drive G:
5:18 PM: Warning: Failed to access drive F:
5:18 PM: Warning: Failed to access drive E:
5:18 PM: Warning: Failed to access drive D:
5:16 PM: Warning: Failed to open file "c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\dj kay slay - rollin 25 deep feat. jae millz, j.r. writer, grafh, posta boy, cory gunz, stack bundles, main-o. john doe, papoose. murda mook, true life, aasim, saigon, pistol p.mp3". The operation completed successfully
5:16 PM: Warning: Failed to open file "c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\drum and bass 3- shaylor - tribal 1 this track rocks ( techno tekno acid rave jungle dj drum bass electronic funk vinyl dance industrial trance juno beat tech vs remix hardcore.mp3". The operation completed successfully
5:15 PM: Warning: Failed to open file "c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\2pac, snoop dogg, dr. dre, 50 cent, spm, ludacris, al pacino, scarface, methodman,redman, ice cube, big pun, busta rhymes, dmx, nwa, d12, eminem, lil flip, obie trice, outkast.jpg". The operation completed successfully
5:15 PM: Warning: Failed to open file "c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\mxpx, blink 182, nofx, sum 41, offspring, green day, relient k, slick shoes, lagwagon, less than jake, ace troubleshooter, new found glory, ramones, pennywise, unwritten law, y.mp3". The operation completed successfully
5:15 PM: Warning: Failed to open file "c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\tequila ( twista kanye west snoop ludacris jayz cassidy r kelly wu tang redman eminem nate dogg 50 cent g unit b2k beyonce britney spears christina aguilera missy elliott outka.mp3". The operation completed successfully
5:15 PM: Warning: Failed to open file "c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\ultimate best loops libraries 4 acid fruity loops reason home studios musician tools sample 3packed full loops library cd roms by music artist mike night of stilo novo read faq.zip". The operation completed successfully
5:15 PM: Warning: Failed to open file "c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\illegal_street_racing_europe_rally_drift_drifting_bad_ass_monster_burn_s90_740_tic_turbo_powervolvo960_race_racing_cars_nice_cool_crazy_fast_xxx_teen_illegal_ferrari_battle_por.mpg". The operation completed successfully
5:15 PM: Warning: Failed to open file "c:\documents and settings\hugo c betancor\local settings\temp\sqlite_b3jxqf2bwksrlqg". The operation completed successfully
5:14 PM: Warning: Failed to open file "c:\documents and settings\hugo c betancor\my documents\my music\itunes\itunes music\respect (unreleased) ft snoop ludacris jayz cassidy r kelly wu tang redman eminem nate dogg 50 cent g unit b2k beyonce britney spears christina aguilera missy elliott outkast a.mp3". The operation completed successfully
5:14 PM: Warning: Failed to open file "c:\documents and settings\hugo c betancor\local settings\application data\microsoft\windows defender\filetracker\{599e6fc9-4a2c-4d31-9607-561f520f2571}". The operation completed successfully
5:14 PM: Warning: Failed to read file "c:\windows\temp\tmp0000006742f0654a0a003471". "c:\windows\temp\tmp0000006742f0654a0a003471": File not found
5:03 PM: c:\windows\system32:lzx32.sys (ID = 350068)
5:03 PM: Found Trojan Horse: trojan-backdoor-rustock
4:53 PM: Starting File Sweep
4:53 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
4:53 PM: c:\documents and settings\hugo c betancor\cookies\hugo c betancor@msnportal.112.2o7[1].txt (ID = 1958)
4:53 PM: Found Spy Cookie: 2o7.net cookie
4:53 PM: c:\documents and settings\hugo c betancor\cookies\hugo c [removed][1].txt (ID = 3669)
4:53 PM: Found Spy Cookie: webtrends cookie
4:53 PM: c:\documents and settings\hugo c betancor\cookies\hugo c betancor@commission-junction[2].txt (ID = 2455)
4:53 PM: Found Spy Cookie: commission junction cookie
4:53 PM: c:\documents and settings\hugo c betancor\cookies\hugo c betancor@atdmt[2].txt (ID = 2253)
4:53 PM: Found Spy Cookie: atlas dmt cookie
4:53 PM: Starting Cookie Sweep
4:53 PM: Registry Sweep Complete, Elapsed Time:00:00:33
4:53 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
4:52 PM: Starting Registry Sweep
4:52 PM: Memory Sweep Complete, Elapsed Time: 00:02:14
4:50 PM: Starting Memory Sweep
4:50 PM: Sweep initiated using definitions version 783
4:50 PM: Spy Sweeper 5.0.5.1286 started
4:50 PM: | Start of Session, Wednesday, October 18, 2006 |
********
And here is the HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 5:42:18 PM, on 10/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\AOL\1139878632\ee\AOLSoftware.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Hugo C Betancor\My Documents\HIJACKTHIS\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Joi Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe"
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Dell\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] "C:\Program Files\McAfee.com\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OASClnt] "C:\Program Files\McAfee.com\VSO\oasclnt.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1139878632\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 9\LaunchList.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] "C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" /startup
O4 - HKLM\..\Run: [MPSExe] "c:\PROGRA~1\mcafee.com\mps\mscifapp.exe" /embedding
O4 - HKLM\..\Run: [IPHSend] "C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"
O4 - HKLM\..\Run: [ViewMgr] "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SecretSmileys] C:\PROGRA~1\SECRET~1\ss.exe
O4 - HKCU\..\Run: [MySpaceIM] "C:\Program Files\MySpace\IM\MySpaceIM.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &AIM; Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Search; -
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) -
http://www.amiuptodate.com/vsc/bin/1,0,0,9…pdatePortal.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1144175501218
O16 - DPF: {7DFDB8FD-B498-4958-B930-38021B94351D} (imlUCID Class) -
http://imlive.com/chatsource/ImlCID.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) -
https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) -
http://acs.pandasoftware.com/activescanpro/as5/asproinst.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by101fd.bay101.hotmail.msn.com/activex/HMAtchmt.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Unfortunately.
1) The computer is very slow.
2) The shut down window still appears.
3) Sometimes the computer will freeze and the screen will go black for a second and then a blue screen will appear which says
" Stop 0x0000008E (0xC000005, 0xAA684D03, 0xA9492A28, 0x00000000)
Beginning dump of Physical Memory
Dump of Physical Memory Complete"
Once again, thank you for everything!!, more help would be greatly appreciated!!
