This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Ie7 Self Loads Over 40 Windows And Locks Up

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have Vista home Premium and use Firefox browser. I'll notice things either slow down or lock up and it's always because IE7 is trying to self load and has between 30-40 windows all over the monitor like a deck of cards. It says res://ieframe.dll/navcancl.htm- in the URL window on every window. When I run Spybot S&D I receive a message that says " C:\ProgramFiles\Spybot-Search-Destroy\Includes\TrojansC.sb: See "Include errors.log" for details . This has been going on for about a month. It got worse today when I downloaded Open Office .org 2.2. Here is my Hijack this log…any help would be appreciated…Thanks…OldSportsGuy

Logfile of HijackThis v1.99.1
Scan saved at 8:33:52 PM, on 7/14/2007
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\SpeedItUpFree\SpeedItUp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
C:\Windows\system32\taskeng.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [FlashIcon] "C:\Program Files\\USB 2.0 Card Reader Driver v2.2\FlashIcon.EXE"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Ahead\InCD\InCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RunSpySweeperScheduleAtStartup] "C:\Windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{D5148304-AF67-4E76-AF30-6AD50B903BA3}
O4 - HKCU\..\Run: [SpeedItUpEX] C:\Program Files\SpeedItUpFree\SpeedItUp.exe -MINI
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Hello and welcome to the forum. Sorry about the delay in responding If you still need help, Scan again with HijackThis, and "copy/paste" a new log file into this thread. Also please describe how your computer behaves at the moment.
Mac70…..Thanks for the help. Here is a new hijack log…but….since I didn't hear from anyone for a while, I ran Spybot S&D and haven't had the IE7 attack since then. The problem was intermittent before. While in firefox browser (which I use 90%) IE7 would launch in another window without my knowing. When I clicked over to that browser there would 30-50 windows open asking me to refresh (which I never did!).Would at least look thru the log file and see if there appears to be any unusual entries. Otherwise I'll just have to wait until it attacks again. Thanks again…Monty

Logfile of HijackThis v1.99.1
Scan saved at 9:20:14 PM, on 7/17/2007
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\SOUNDMAN.EXE
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [FlashIcon] "C:\Program Files\\USB 2.0 Card Reader Driver v2.2\FlashIcon.EXE"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Ahead\InCD\InCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [RunSpySweeperScheduleAtStartup] "C:\Windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{D5148304-AF67-4E76-AF30-6AD50B903BA3}
O4 - HKCU\..\Run: [SpeedItUpEX] C:\Program Files\SpeedItUpFree\SpeedItUp.exe -MINI
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Hello OldSportsGuy

Glad to hear things are better. Why dont we just be a little thorough?

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Mac70..I can't get Kapersky to load. When I click accept nothing happens. The screen just sits there. What should I try now?…Monty
Mac70…I just figured out that it is because I was using firefox. I downloaded it in IE and when it hit 100% I got this message…..Update precess FAILED. No further antivirus actions can be performed. Attention, you must be online to activate Kapersky Online Scanner, since the latest Anti-virus bases version must be downloaded prior to scan. Otherwise we cannot guarantee detection of latest viruses [21]. I doubled checked and I was definitely connected to the internet. I tried the scanner again and immediately received the same message! Look forward to hearing from you tomorrow…Thanks again…Monty
Ok Monty, lets try something else.

Download and run Sysclean
  • Create a folder on your desktop called Sysclean.
  • Go to http://www.trendmicro.com/download/dcs.asp and download sysclean package to the folder you made.
  • Go to http://www.trendmicro.com/download/pattern.asp and download the Virus Pattern File (Official Pattern Release) to your desktop.
    This file will be called lptXXX.zip (XXX represents the version number)
  • Unzip lptXXX.zip and you'll get the file lpt$vpn.XXX. Read here how to unzip/extract properly.
  • Move the lpt$vpn.XXX to the Sysclean-folder you created on your desktop.
  • Open the sysclean-folder and doubleclick sysclean.com.
  • Check: "Automatically clean or delete detected files".
  • Click scan.
Open your sysclean-folder and copy and paste the contents of sysclean.log in your next reply.
OK…here we go again…….I downloaded everything. But when I attempted the scan I received two windows. The one in the background was the window to perform the scan and the one on top was an error message which read…"Patter file "LPT4VPN' is missing.Please download a copy." I moved the error window out of the way and clicked scan anyway. Here is the log it created…Monty



/————————————————————–\
| Trend Micro System Cleaner |
| Copyright 2006, Trend Micro, Inc. |
| http://www.antivirus.com |
\————————————————————–/


2007-07-19, 09:03:11, Auto-clean mode specified.
2007-07-19, 09:03:11, Running scanner "C:\Users\MONTY\Desktop\Sysclean\TSC.BIN"…
2007-07-19, 09:03:21, Scanner "C:\Users\MONTY\Desktop\Sysclean\TSC.BIN" has finished running.
2007-07-19, 09:03:21, TSC Log:

Damage Cleanup Engine (DCE) 5.3(Build 1103)
Windows Longhorn(Build 6000: )

Start time : Thu Jul 19 2007 09:03:12

Load Damage Cleanup Template (DCT) "C:\Users\MONTY\Desktop\Sysclean\TMRDCT.ptn" (version ) [fail]
Load Damage Cleanup Template (DCT) "C:\Users\MONTY\Desktop\Sysclean\tsc.ptn" (version 880) [success]

Complete time : Thu Jul 19 2007 09:03:21
Execute pattern count(2867), Virus found count(0), Virus clean count(0), Clean failed count(0)

2007-07-19, 09:03:22, An error was detected on "C:\$Recycle.Bin\S-1-5-21-1404372269-2393766007-1317723904-1001\*.*": Access is denied.
2007-07-19, 09:03:22, An error was detected on "C:\$Recycle.Bin\S-1-5-21-2152478756-3922319563-605102323-500\*.*": Access is denied.
2007-07-19, 09:03:22, An error was detected on "C:\Documents and Settings\*.*": Access is denied.


/————————————————————–\
| Trend Micro System Cleaner |
| Copyright 2006, Trend Micro, Inc. |
| http://www.antivirus.com |
\————————————————————–/


2007-07-19, 09:06:31, Auto-clean mode specified.
2007-07-19, 09:06:31, Running scanner "C:\Users\MONTY\Desktop\Sysclean\TSC.BIN"…
2007-07-19, 09:06:38, Scanner "C:\Users\MONTY\Desktop\Sysclean\TSC.BIN" has finished running.
2007-07-19, 09:06:38, TSC Log:

Damage Cleanup Engine (DCE) 5.3(Build 1103)
Windows Longhorn(Build 6000: )

Start time : Thu Jul 19 2007 09:06:31

Load Damage Cleanup Template (DCT) "C:\Users\MONTY\Desktop\Sysclean\TMRDCT.ptn" (version ) [fail]
Load Damage Cleanup Template (DCT) "C:\Users\MONTY\Desktop\Sysclean\tsc.ptn" (version 880) [success]

Complete time : Thu Jul 19 2007 09:06:38
Execute pattern count(2867), Virus found count(0), Virus clean count(0), Clean failed count(0)

2007-07-19, 09:06:38, An error was detected on "C:\$Recycle.Bin\S-1-5-21-1404372269-2393766007-1317723904-1001\*.*": Access is denied.
2007-07-19, 09:06:38, An error was detected on "C:\$Recycle.Bin\S-1-5-21-2152478756-3922319563-605102323-500\*.*": Access is denied.
2007-07-19, 09:06:38, An error was detected on "C:\Documents and Settings\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Application Data\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Desktop\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Documents\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Favorites\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Network\Downloader\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report030ffcd3\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report03757576\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report0375e5f3\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report04f9e9a7\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report04f9ef83\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report07ccd5ba\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report08006ac4\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report08006e5d\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report08006fa6\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report0800713c\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report08fd46c8\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report04152ec8\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report042919dc\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report070dd278\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report070dd288\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report070dd298\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report094b467a\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report0f709ab6\*.*": Access is denied.
2007-07-19, 09:06:45, An error was detected on "C:\ProgramData\Microsoft\Windows Defender\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\ProgramData\Start Menu\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\ProgramData\Templates\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\System Volume Information\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Application Data\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Desktop\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Documents\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Favorites\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Network\Downloader\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Search\Data\Temp\usgthrsvc\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report030ffcd3\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report03757576\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report0375e5f3\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report04f9e9a7\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report04f9ef83\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report07ccd5ba\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report08006ac4\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report08006e5d\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report08006fa6\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report0800713c\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report08fd46c8\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report04152ec8\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report042919dc\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report070dd278\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report070dd288\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report070dd298\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report094b467a\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report0f709ab6\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Microsoft\Windows Defender\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Start Menu\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\All Users\Templates\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\AppData\Local\Application Data\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\AppData\Local\History\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\AppData\Local\Temporary Internet Files\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\Application Data\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\Cookies\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\Documents\My Music\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\Documents\My Pictures\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\Documents\My Videos\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\Local Settings\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\My Documents\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\NetHood\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\PrintHood\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\Recent\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\SendTo\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\Start Menu\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default\Templates\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\Default User\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\MONTY\AppData\Local\Application Data\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\MONTY\AppData\Local\History\*.*": Access is denied.
2007-07-19, 09:06:46, An error was detected on "C:\Users\MONTY\AppData\Local\Microsoft\CardSpace\*.*": Access is denied.
2007-07-19, 09:06:50, An error was detected on "C:\Users\MONTY\AppData\Local\Temporary Internet Files\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\Application Data\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\Cookies\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\Documents\My Music\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\Documents\My Pictures\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\Documents\My Videos\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\Local Settings\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\My Documents\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\NetHood\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\PrintHood\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\Recent\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\SendTo\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\Start Menu\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\MONTY\Templates\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\Public\Documents\My Music\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\Public\Documents\My Pictures\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\Public\Documents\My Videos\*.*": Access is denied.
2007-07-19, 09:06:55, An error was detected on "C:\Users\SHERRY\*.*": Access is denied.
2007-07-19, 09:06:57, An error was detected on "C:\Windows\LiveKernelReports\*.*": Access is denied.
2007-07-19, 09:06:57, An error was detected on "C:\Windows\Minidump\*.*": Access is denied.
2007-07-19, 09:06:57, An error was detected on "C:\Windows\ModemLogs\*.*": Access is denied.
2007-07-19, 09:06:57, An error was detected on "C:\Windows\Prefetch\*.*": Access is denied.
2007-07-19, 09:06:57, An error was detected on "C:\Windows\ServiceProfiles\LocalService\*.*": Access is denied.
2007-07-19, 09:06:57, An error was detected on "C:\Windows\ServiceProfiles\NetworkService\*.*": Access is denied.
2007-07-19, 09:06:59, An error was detected on "C:\Windows\System32\com\dmp\*.*": Access is denied.
2007-07-19, 09:06:59, An error was detected on "C:\Windows\System32\config\RegBack\*.*": Access is denied.
2007-07-19, 09:06:59, An error was detected on "C:\Windows\System32\config\systemprofile\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\System32\ias\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\System32\LogFiles\HTTPERR\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\System32\LogFiles\WMI\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\System32\Msdtc\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\System32\networklist\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\System32\spool\PRINTERS\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\System32\Tasks\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\System32\wbem\MOF\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\System32\WDI\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\System32\wfp\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\tapi\*.*": Access is denied.
2007-07-19, 09:07:02, An error was detected on "C:\Windows\Temp\*.*": Access is denied.
2007-07-19, 09:07:18, An error was detected on "D:\$RECYCLE.BIN\S-1-5-21-1404372269-2393766007-1317723904-1001\*.*": Access is denied.
2007-07-19, 09:07:18, An error was detected on "D:\baf8785f9aebe704a2c7ff\*.*": Access is denied.
2007-07-19, 09:07:33, An error was detected on "D:\RECYCLER\NPROTECT\*.*": Access is denied.
2007-07-19, 09:07:33, An error was detected on "D:\RECYCLER\S-1-5-21-1220945662-152049171-1957994488-1003\*.*": Access is denied.
2007-07-19, 09:07:33, An error was detected on "D:\System Volume Information\*.*": Access is denied.
2007-07-19, 09:07:34, An error was detected on "K:\$RECYCLE.BIN\S-1-5-21-1404372269-2393766007-1317723904-1001\*.*": Access is denied.
2007-07-19, 09:07:34, An error was detected on "K:\System Volume Information\*.*": Access is denied.
2007-07-19, 09:07:34, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:07:34
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.*

2007-07-19, 09:07:34, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:07:34
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.*

2007-07-19, 09:07:34, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:07:34
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.*

2007-07-19, 09:07:34, Scanner "C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN" has finished running.
2007-07-19, 09:07:34, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:07:34
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.*

2007-07-19, 09:07:34, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:07:34
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.*

2007-07-19, 09:07:34, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:07:34
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.*

2007-07-19, 09:07:34, Scanner "C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN" has finished running.
2007-07-19, 09:07:34, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:07:34
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 K:\*.*

2007-07-19, 09:07:34, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:07:34
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 K:\*.*

2007-07-19, 09:07:34, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:07:34
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 K:\*.*

2007-07-19, 09:07:34, Scanner "C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN" has finished running.


/————————————————————–\
| Trend Micro System Cleaner |
| Copyright 2006, Trend Micro, Inc. |
| http://www.antivirus.com |
\————————————————————–/


2007-07-19, 09:17:01, Auto-clean mode specified.
2007-07-19, 09:17:01, Running scanner "C:\Users\MONTY\Desktop\Sysclean\TSC.BIN"…
2007-07-19, 09:17:09, Scanner "C:\Users\MONTY\Desktop\Sysclean\TSC.BIN" has finished running.
2007-07-19, 09:17:09, TSC Log:

Damage Cleanup Engine (DCE) 5.3(Build 1103)
Windows Longhorn(Build 6000: )

Start time : Thu Jul 19 2007 09:17:02

Load Damage Cleanup Template (DCT) "C:\Users\MONTY\Desktop\Sysclean\TMRDCT.ptn" (version ) [fail]
Load Damage Cleanup Template (DCT) "C:\Users\MONTY\Desktop\Sysclean\tsc.ptn" (version 880) [success]

Complete time : Thu Jul 19 2007 09:17:09
Execute pattern count(2867), Virus found count(0), Virus clean count(0), Clean failed count(0)

2007-07-19, 09:17:09, An error was detected on "C:\$Recycle.Bin\S-1-5-21-1404372269-2393766007-1317723904-1001\*.*": Access is denied.
2007-07-19, 09:17:09, An error was detected on "C:\$Recycle.Bin\S-1-5-21-2152478756-3922319563-605102323-500\*.*": Access is denied.
2007-07-19, 09:17:09, An error was detected on "C:\Documents and Settings\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Application Data\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Desktop\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Documents\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Favorites\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Network\Downloader\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report030ffcd3\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report03757576\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report0375e5f3\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report04f9e9a7\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report04f9ef83\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report07ccd5ba\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report08006ac4\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report08006e5d\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report08006fa6\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report0800713c\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report08fd46c8\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report04152ec8\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report042919dc\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report070dd278\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report070dd288\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report070dd298\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report094b467a\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report0f709ab6\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Microsoft\Windows Defender\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Start Menu\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\ProgramData\Templates\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\System Volume Information\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Application Data\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Desktop\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Documents\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Favorites\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Network\Downloader\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Search\Data\Applications\Windows\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Search\Data\Temp\usgthrsvc\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report030ffcd3\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report03757576\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report0375e5f3\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report04f9e9a7\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report04f9ef83\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report07ccd5ba\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report08006ac4\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report08006e5d\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report08006fa6\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report0800713c\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report08fd46c8\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report04152ec8\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report042919dc\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report070dd278\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report070dd288\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report070dd298\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report094b467a\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report0f709ab6\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Microsoft\Windows Defender\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Start Menu\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\All Users\Templates\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\AppData\Local\Application Data\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\AppData\Local\History\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\AppData\Local\Temporary Internet Files\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\Application Data\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\Cookies\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\Documents\My Music\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\Documents\My Pictures\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\Documents\My Videos\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\Local Settings\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\My Documents\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\NetHood\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\PrintHood\*.*": Access is denied.
2007-07-19, 09:17:13, An error was detected on "C:\Users\Default\Recent\*.*": Access is denied.
2007-07-19, 09:17:14, An error was detected on "C:\Users\Default\SendTo\*.*": Access is denied.
2007-07-19, 09:17:14, An error was detected on "C:\Users\Default\Start Menu\*.*": Access is denied.
2007-07-19, 09:17:14, An error was detected on "C:\Users\Default\Templates\*.*": Access is denied.
2007-07-19, 09:17:14, An error was detected on "C:\Users\Default User\*.*": Access is denied.
2007-07-19, 09:17:14, An error was detected on "C:\Users\MONTY\AppData\Local\Application Data\*.*": Access is denied.
2007-07-19, 09:17:14, An error was detected on "C:\Users\MONTY\AppData\Local\History\*.*": Access is denied.
2007-07-19, 09:17:14, An error was detected on "C:\Users\MONTY\AppData\Local\Microsoft\CardSpace\*.*": Access is denied.
2007-07-19, 09:17:15, An error was detected on "C:\Users\MONTY\AppData\Local\Temporary Internet Files\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\Application Data\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\Cookies\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\Documents\My Music\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\Documents\My Pictures\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\Documents\My Videos\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\Local Settings\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\My Documents\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\NetHood\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\PrintHood\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\Recent\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\SendTo\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\Start Menu\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\MONTY\Templates\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\Public\Documents\My Music\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\Public\Documents\My Pictures\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\Public\Documents\My Videos\*.*": Access is denied.
2007-07-19, 09:17:16, An error was detected on "C:\Users\SHERRY\*.*": Access is denied.
2007-07-19, 09:17:17, An error was detected on "C:\Windows\LiveKernelReports\*.*": Access is denied.
2007-07-19, 09:17:17, An error was detected on "C:\Windows\Minidump\*.*": Access is denied.
2007-07-19, 09:17:17, An error was detected on "C:\Windows\ModemLogs\*.*": Access is denied.
2007-07-19, 09:17:17, An error was detected on "C:\Windows\Prefetch\*.*": Access is denied.
2007-07-19, 09:17:17, An error was detected on "C:\Windows\ServiceProfiles\LocalService\*.*": Access is denied.
2007-07-19, 09:17:17, An error was detected on "C:\Windows\ServiceProfiles\NetworkService\*.*": Access is denied.
2007-07-19, 09:17:18, An error was detected on "C:\Windows\System32\com\dmp\*.*": Access is denied.
2007-07-19, 09:17:18, An error was detected on "C:\Windows\System32\config\RegBack\*.*": Access is denied.
2007-07-19, 09:17:18, An error was detected on "C:\Windows\System32\config\systemprofile\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\System32\ias\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\System32\LogFiles\HTTPERR\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\System32\LogFiles\WMI\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\System32\Msdtc\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\System32\networklist\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\System32\spool\PRINTERS\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\System32\Tasks\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\System32\wbem\MOF\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\System32\WDI\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\System32\wfp\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\tapi\*.*": Access is denied.
2007-07-19, 09:17:20, An error was detected on "C:\Windows\Temp\*.*": Access is denied.
2007-07-19, 09:17:26, An error was detected on "D:\$RECYCLE.BIN\S-1-5-21-1404372269-2393766007-1317723904-1001\*.*": Access is denied.
2007-07-19, 09:17:26, An error was detected on "D:\baf8785f9aebe704a2c7ff\*.*": Access is denied.
2007-07-19, 09:17:33, An error was detected on "D:\RECYCLER\NPROTECT\*.*": Access is denied.
2007-07-19, 09:17:33, An error was detected on "D:\RECYCLER\S-1-5-21-1220945662-152049171-1957994488-1003\*.*": Access is denied.
2007-07-19, 09:17:33, An error was detected on "D:\System Volume Information\*.*": Access is denied.
2007-07-19, 09:17:33, An error was detected on "K:\$RECYCLE.BIN\S-1-5-21-1404372269-2393766007-1317723904-1001\*.*": Access is denied.
2007-07-19, 09:17:33, An error was detected on "K:\System Volume Information\*.*": Access is denied.
2007-07-19, 09:17:33, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.*

2007-07-19, 09:17:33, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.*

2007-07-19, 09:17:33, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.*

2007-07-19, 09:17:33, Scanner "C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN" has finished running.
2007-07-19, 09:17:33, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.*

2007-07-19, 09:17:33, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.*

2007-07-19, 09:17:33, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.*

2007-07-19, 09:17:33, Scanner "C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN" has finished running.
2007-07-19, 09:17:33, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 K:\*.*

2007-07-19, 09:17:33, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 K:\*.*

2007-07-19, 09:17:33, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 7/19/2007 09:17:33
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Command Line: C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 K:\*.*

2007-07-19, 09:17:33, Scanner "C:\Users\MONTY\Desktop\Sysclean\VSCANTM.BIN" has finished running.
Ok. Could well be compatibility issues. This defintly works with Vista.

Do a virus scan from here.
Click on Scan now it's free
A new page will open. Click Scan now it's free a second time
Place a check in the box Yes, I accept the Terms of Use
Press Launch House Call
Be patient, it's going to take a while. Let it clean all infection found.
If you get report of files that can’t be cleaned / deleted please write down the filenames and locations and post that in your reply.

Could you give me an idea of what the popups are, such as sites or ads?
Mac70…Housecall is currently scanning. I thought I would let you know that the are NO popup ads. These are Internet Explorer browser windows. Every window is identical. My first post tells what the window says. It asks me to refresh, which I assume might be a "redirect" from a hacker. I have never refreshed. Also, as a reminder, I am not trying to open IE. I am browsing in firefox and notice an IE tab at the bottom control bar. When I open it there are numerous windows all over the page…Thanks…Monty
It appears Housecall has stopped about 33% into the scan. I've been watching it scan it stopped in the spot about 20 minutes ago and has not moved. I am still connected to trendmicro because the screen keeps cycling thru its information pages.It scanned 72656 resources and stopped at C:\Program Files\OpenOffice.org 2.2\pr…\xsltc\dom\ NodeSortRecordFactory.class LMK….Monty
Hi OSG

Download WinPFind3U.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
  • Now click the Run Scan button on the toolbar.
  • The program will be scanning huge amounts of data so depending on your system it could take a long time to complete. Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Save the log on your desktop.
Now post it in your next reply.
Mac70…..FINALLY! the program loaded and gave me a report. Here is the log….Thanks again….OldSportsGuy

WinPFind3 logfile created on: 7/20/2007 3:31:41 PM
WinPFind3U by OldTimer - Version 1.0.39 Folder = C:\Users\MONTY\Desktop\WinPFind3u\
Windows Vista ™ Home Premium (Version = 6.0.6000)
Internet Explorer (Version = 7.0.6000.16473)

1021.94 Mb Total Physical Memory | 615.57 Mb Available Physical Memory | 60.24% Memory free
2.38 Gb Paging File | 1.32 Gb Available in Paging File | 55.50% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 58.59 Gb Total Space | 34.29 Gb Free Space | 58.52% Space Free
Drive D: | 111.79 Gb Total Space | 84.97 Gb Free Space | 76.01% Space Free
E: Drive not present or media not loaded
F: Drive not present or media not loaded

Computer Name: MONTY-PC
Current User Name: MONTY
Logged in as Administrator.
Current Boot Mode: Normal


[Processes - Non-Microsoft Only]
apdproxy.exe -> %ProgramFiles%\Adobe\Photoshop Elements 4.0\apdproxy.exe -> Adobe Systems Incorporated [Ver = 3.0.0.53237 | Size = 57344 bytes | Modified Date = 9/9/2005 1:18:10 AM | Attr = ]
bdagent.exe -> %ProgramFiles%\Softwin\BitDefender10\bdagent.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 69632 bytes | Modified Date = 3/26/2007 3:49:46 PM | Attr = ]
bdmcon.exe -> %ProgramFiles%\Softwin\BitDefender10\bdmcon.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 15 | Size = 290816 bytes | Modified Date = 5/28/2007 3:58:32 PM | Attr = ]
bdss.exe -> %CommonProgramFiles%\Softwin\BitDefender Scan Server\bdss.exe -> [Ver = | Size = 81920 bytes | Modified Date = 12/20/2006 5:33:08 PM | Attr = ]
ding.exe -> %ProgramFiles%\Southwest Airlines\Ding\Ding.exe -> Southwest Airlines [Ver = 1.05.005 | Size = 462848 bytes | Modified Date = 6/22/2006 2:15:48 PM | Attr = ]
incd.exe -> %ProgramFiles%\Ahead\InCD\InCD.exe -> Nero AG [Ver = 4, 3, 18, 0 | Size = 1397760 bytes | Modified Date = 3/16/2006 1:00:08 AM | Attr = ]
incdsrv.exe -> %ProgramFiles%\Ahead\InCD\InCDsrv.exe -> Nero AG [Ver = 4, 3, 18, 0 | Size = 871424 bytes | Modified Date = 7/8/2005 4:24:46 PM | Attr = ]
jusched.exe -> %ProgramFiles%\Java\jre1.6.0\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 77824 bytes | Modified Date = 3/10/2007 4:45:16 PM | Attr = ]
livesrv.exe -> %CommonProgramFiles%\Softwin\BitDefender Update Service\livesrv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 237568 bytes | Modified Date = 3/21/2007 12:31:00 PM | Attr = ]
lssrvc.exe -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> Hewlett-Packard Company [Ver = 1.4.142.1 | Size = 61440 bytes | Modified Date = 1/17/2007 11:20:10 AM | Attr = ]
photoshopelementsfileagent.exe -> %ProgramFiles%\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe -> [Ver = | Size = 102400 bytes | Modified Date = 9/9/2005 3:24:30 AM | Attr = ]
qttask.exe -> %ProgramFiles%\QuickTime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1.5a38 | Size = 282624 bytes | Modified Date = 3/20/2007 12:35:30 PM | Attr = ]
soffice.bin -> %ProgramFiles%\OpenOffice.org 2.2\program\soffice.bin -> OpenOffice.org [Ver = 1.09.9153 | Size = 2510848 bytes | Modified Date = 5/29/2007 4:29:42 PM | Attr = ]
soffice.exe -> %ProgramFiles%\OpenOffice.org 2.2\program\soffice.exe -> OpenOffice.org [Ver = 1.09.9153 | Size = 2359296 bytes | Modified Date = 5/29/2007 4:29:36 PM | Attr = ]
soundman.exe -> %SystemRoot%\SOUNDMAN.EXE -> Realtek Semiconductor Corp. [Ver = 5.1.0.39 | Size = 77824 bytes | Modified Date = 5/17/2005 6:48:32 PM | Attr = ]
winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.38.0 | Size = 322048 bytes | Modified Date = 6/23/2007 3:15:54 PM | Attr = ]
xcommsvr.exe -> %CommonProgramFiles%\Softwin\BitDefender Communicator\xcommsvr.exe -> SOFTWIN S.R.L [Ver = 1, 8, 11, 0 | Size = 86016 bytes | Modified Date = 11/9/2006 1:33:04 PM | Attr = ]

[Win32 Services - Non-Microsoft Only]
(AdobeActiveFileMonitor4.0) Adobe Active File Monitor V4 [Win32_Own | Auto | Running] -> %ProgramFiles%\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe -> [Ver = | Size = 102400 bytes | Modified Date = 9/9/2005 3:24:30 AM | Attr = ]
(bdss) BitDefender Scan Server [Win32_Own | Auto | Stop_Pending] -> %CommonProgramFiles%\Softwin\BitDefender Scan Server\bdss.exe -> [Ver = | Size = 81920 bytes | Modified Date = 12/20/2006 5:33:08 PM | Attr = ]
(CertPropSvc) Certificate Propagation [Win32_Shared | Unknown | Running] -> -> File not found
(DcomLaunch) DCOM Server Process Launcher [Win32_Shared | Unknown | Running] -> -> File not found
(DPS) Diagnostic Policy Service [Win32_Shared | Unknown | Running] -> -> File not found
(gpsvc) Group Policy Client [Win32_Shared | Unknown | Running] -> -> File not found
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> -> File not found
(InCDsrv) InCD Helper [Win32_Own | Auto | Running] -> %ProgramFiles%\Ahead\InCD\InCDsrv.exe -> Nero AG [Ver = 4, 3, 18, 0 | Size = 871424 bytes | Modified Date = 7/8/2005 4:24:46 PM | Attr = ]
(LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> Hewlett-Packard Company [Ver = 1.4.142.1 | Size = 61440 bytes | Modified Date = 1/17/2007 11:20:10 AM | Attr = ]
(LIVESRV) BitDefender Desktop Update Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Softwin\BitDefender Update Service\livesrv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 237568 bytes | Modified Date = 3/21/2007 12:31:00 PM | Attr = ]
(MSDTC) Distributed Transaction Coordinator [Win32_Own | Unknown | Stopped] -> -> File not found
(RpcSs) Remote Procedure Call (RPC) [Win32_Shared | Unknown | Running] -> -> File not found
(SCardSvr) Smart Card [Win32_Shared | Unknown | Stopped] -> -> File not found
(Schedule) Task Scheduler [Win32_Shared | Unknown | Running] -> -> File not found
(SCPolicySvc) Smart Card Removal Policy [Win32_Shared | Unknown | Stopped] -> -> File not found
(TrustedInstaller) Windows Modules Installer [Win32_Own | Unknown | Stopped] -> -> File not found
(VSSERV) BitDefender Virus Shield [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Softwin\BitDefender10\vsserv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 1, 156 | Size = 471040 bytes | Modified Date = 6/21/2007 7:49:10 AM | Attr = ]
(WdiServiceHost) Diagnostic Service Host [Win32_Shared | Unknown | Stopped] -> -> File not found
(WdiSystemHost) Diagnostic System Host [Win32_Shared | Unknown | Running] -> -> File not found
(XCOMM) BitDefender Communicator [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Softwin\BitDefender Communicator\xcommsvr.exe -> SOFTWIN S.R.L [Ver = 1, 8, 11, 0 | Size = 86016 bytes | Modified Date = 11/9/2006 1:33:04 PM | Attr = ]

[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
Adobe Photo Downloader -> %ProgramFiles%\Adobe\Photoshop Elements 4.0\apdproxy.exe -> Adobe Systems Incorporated [Ver = 3.0.0.53237 | Size = 57344 bytes | Modified Date = 9/9/2005 1:18:10 AM | Attr = ]
Adobe Reader Speed Launcher -> %ProgramFiles%\Adobe\Reader 8.0\Reader\Reader_sl.exe -> Adobe Systems Incorporated [Ver = 8.0.0.0 | Size = 40048 bytes | Modified Date = 5/11/2007 3:06:32 AM | Attr = ]
amd_dc_opt -> %ProgramFiles%\AMD\Dual-Core Optimizer\amd_dc_opt.exe -> AMD [Ver = 1, 1, 1, 0 | Size = 77824 bytes | Modified Date = 11/17/2006 4:49:48 PM | Attr = ]
BDAgent -> %ProgramFiles%\Softwin\BitDefender10\bdagent.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 69632 bytes | Modified Date = 3/26/2007 3:49:46 PM | Attr = ]
BDMCon -> %ProgramFiles%\Softwin\BitDefender10\bdmcon.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 15 | Size = 290816 bytes | Modified Date = 5/28/2007 3:58:32 PM | Attr = ]
FlashIcon -> %ProgramFiles%\USB 2.0 Card Reader Driver v2.2\FlashIcon.EXE -> Neodio Corp. [Ver = 1, 3, 0, 6 | Size = 49152 bytes | Modified Date = 1/14/2004 2:16:28 AM | Attr = ]
InCD -> %ProgramFiles%\Ahead\InCD\InCD.exe -> Nero AG [Ver = 4, 3, 18, 0 | Size = 1397760 bytes | Modified Date = 3/16/2006 1:00:08 AM | Attr = ]
NeroFilterCheck -> %System32%\NeroCheck.exe -> Ahead Software Gmbh [Ver = 1, 0, 0, 2 | Size = 155648 bytes | Modified Date = 7/9/2001 10:50:42 AM | Attr = ]
QuickTime Task -> %ProgramFiles%\QuickTime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1.5a38 | Size = 282624 bytes | Modified Date = 3/20/2007 12:35:30 PM | Attr = ]
SoundMan -> %SystemRoot%\SOUNDMAN.EXE -> Realtek Semiconductor Corp. [Ver = 5.1.0.39 | Size = 77824 bytes | Modified Date = 5/17/2005 6:48:32 PM | Attr = ]
SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 77824 bytes | Modified Date = 3/10/2007 4:45:16 PM | Attr = ]
< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->
IMAIL -> Installed = 1 ->
MAPI -> Installed = 1 ->
MSFS -> Installed = 1 ->
< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
SpeedItUpEX -> %ProgramFiles%\SpeedItUpFree\SpeedItUp.exe -> MicroSmarts LLC. [Ver = 4.0.1.4 | Size = 1876992 bytes | Modified Date = 3/26/2007 8:50:04 PM | Attr = ]
< User Startup > -> C:\Users\MONTY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup ->
%UserAppData%\Microsoft\Windows\Start Menu\Programs\Startup\DING!.lnk -> %ProgramFiles%\Southwest Airlines\Ding\Ding.exe -> Southwest Airlines [Ver = 1.05.005 | Size = 462848 bytes | Modified Date = 6/22/2006 2:15:48 PM | Attr = ]
%UserAppData%\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.2.lnk -> %ProgramFiles%\OpenOffice.org 2.2\program\quickstart.exe -> [Ver = | Size = 393216 bytes | Modified Date = 2/2/2007 5:54:56 PM | Attr = ]
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Attachments\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Attachments\\ScanWithAntiVirus -> 3 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin -> 2 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableInstallerDetection -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableLUA -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableSecureUIAPaths -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\EnableVirtualization -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\PromptOnSecureDesktop -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ValidateAdminCodeSignatures -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\scforceoption -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\FilterAdministratorToken -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats\\CF_TEXT -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats\\CF_BITMAP -> 2 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats\\CF_OEMTEXT -> 7 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats\\CF_DIB -> 8 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats\\CF_PALETTE -> 9 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats\\CF_UNICODETEXT -> 13 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats\\CF_DIBV5 -> 17 ->
< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 91 ->
< HOSTS File > (761 bytes) -> C:\Windows\System32\drivers\etc\Hosts ->
127.0.0.1 localhost -> ->
::1 localhost -> ->
< Internet Explorer Settings > -> ->
HKLM: Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKLM: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKLM: Search Bar -> http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html ->
HKLM: Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKLM: Start Page -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKCU: Search Bar -> http://red.clientapps.yahoo.com/customize/…/search/ie.html ->
HKCU: Search Page -> http://red.clientapps.yahoo.com/customize/…//www.yahoo.com ->
HKCU: Start Page -> http://msn.com/ ->
HKCU: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 2:39:26 PM | Attr = ]
HKCU: ProxyEnable -> 0 ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn\yt.dll [&Yahoo! Toolbar Helper] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 2:39:26 PM | Attr = ]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 8.0.0.2006102200 | Size = 62080 bytes | Modified Date = 10/22/2006 11:08:42 PM | Attr = ]
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Modified Date = 5/31/2005 1:04:00 AM | Attr = ]
{5A263CF7-56A6-4D68-A8CF-345BE45BC911} [HKLM] -> %ProgramFiles%\Yahoo!\Search\YSearchSuggest.dll [Yahoo! IE Suggest] -> Yahoo! Inc. [Ver = 2007, 2, 23, 1 | Size = 140840 bytes | Modified Date = 2/23/2007 4:04:32 PM | Attr = ]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! IE Services Button] -> Yahoo! Inc. [Ver = 2006, 10, 31, 3 | Size = 198136 bytes | Modified Date = 10/31/2006 1:33:52 PM | Attr = ]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 3/14/2007 3:43:40 AM | Attr = ]
< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 2:39:26 PM | Attr = ]
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\{55FAF0F2-44D4-425F-B5F5-6B275B621EAB} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 3/14/2007 3:43:40 AM | Attr = ]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -> Reg Data - Value does not exist [ButtonText: Yahoo! Services] -> File not found
< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> -> File not found
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{93E267E7-0214-4A1B-8A5B-41B9B12980F7} -> (Airlink101 MIMO XR PCI Adapter) ->
{B386A438-D97C-4694-B63E-D7DB4E045F1A} -> (Microsoft Windows Mobile Remote Adapter) ->
{C85AD5F4-0AD0-4B1E-A5E5-7188E140F652} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) ->
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
about -> Reg Data - Key not found -> File not found
dvd -> Reg Data - Key not found -> File not found
its -> Reg Data - Key not found -> File not found
mhtml -> Reg Data - Key not found -> File not found
ms-its -> Reg Data - Key not found -> File not found
tv -> Reg Data - Key not found -> File not found
vbscript -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{0DB074F0-617E-4EE9-912C-2965CF2AA5A4} -> SentinelVE3D Class - CodeBase = http://download.microsoft.com/download/0/f…tualEarth3D.cab ->
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -> CKAVWebScan Object - CodeBase = http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab ->
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -> Installation Support - CodeBase = C:\Program Files\Yahoo!\Common\Yinsthelper.dll ->
{406B5949-7190-4245-91A9-30A17DE16AD0} -> Snapfish Activia - CodeBase = http://www.costcophotocenter.com/CostcoActivia.cab ->


[Files/Folders - Created Within 30 days]
DriveKey -> %SystemDrive%\DriveKey -> [Folder | Created Date = 7/10/2007 10:11:08 PM | Attr = ]
KAV -> %SystemDrive%\KAV -> [Folder | Created Date = 6/22/2007 5:36:48 PM | Attr = ]
Sun -> %SystemRoot%\Sun -> [Folder | Created Date = 7/19/2007 4:37:35 PM | Attr = ]
GameUXLegacyGDFs.dll -> %System32%\GameUXLegacyGDFs.dll -> Microsoft [Ver = 1.0.0.1 | Size = 4247552 bytes | Created Date = 7/10/2007 10:27:59 PM | Attr = ]
Kaspersky Lab -> %System32%\Kaspersky Lab -> [Folder | Created Date = 7/18/2007 10:01:27 PM | Attr = ]
tmcomm.sys -> %System32%\drivers\tmcomm.sys -> Trend Micro Inc. [Ver = 1.6.0.1049 | Size = 94480 bytes | Created Date = 7/19/2007 4:38:31 PM | Attr = ]
Msft_User_WpdRapi_01_00_00.Wdf -> %System32%\drivers\UMDF\Msft_User_WpdRapi_01_00_00.Wdf -> [Ver = | Size = 0 bytes | Created Date = 7/15/2007 2:26:08 PM | Attr = H ]

[Files/Folders - Modified Within 30 days]
DriveKey -> %SystemDrive%\DriveKey -> [Folder | Modified Date = 7/10/2007 10:11:10 PM | Attr = ]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 1072226304 bytes | Modified Date = 7/16/2007 10:08:48 AM | Attr = HS]
KAV -> %SystemDrive%\KAV -> [Folder | Modified Date = 6/22/2007 5:36:50 PM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 7/16/2007 3:17:38 PM | Attr = R ]
ProgramData -> %AllUsersAppData% -> [Folder | Modified Date = 7/19/2007 4:28:58 PM | Attr = H ]
System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 7/16/2007 4:35:26 PM | Attr = HS]
Windows -> %SystemRoot% -> [Folder | Modified Date = 7/19/2007 4:37:36 PM | Attr = ]
AppPatch -> %SystemRoot%\AppPatch -> [Folder | Modified Date = 7/10/2007 10:33:24 PM | Attr = ]
assembly -> %SystemRoot%\assembly -> [Folder | Modified Date = 7/14/2007 5:42:40 PM | Attr = R S]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 67584 bytes | Modified Date = 7/16/2007 10:09:08 AM | Attr = S]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 7/20/2007 2:51:54 PM | Attr = S]
ehome -> %SystemRoot%\ehome -> [Folder | Modified Date = 7/4/2007 5:03:44 PM | Attr = ]
Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 7/14/2007 5:41:34 PM | Attr = R S]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 7/16/2007 10:14:42 AM | Attr = ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 7/14/2007 5:43:20 PM | Attr = HS]
Microsoft.NET -> %SystemRoot%\Microsoft.NET -> [Folder | Modified Date = 7/10/2007 11:02:52 PM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 7/20/2007 3:29:26 PM | Attr = ]
rescache -> %SystemRoot%\rescache -> [Folder | Modified Date = 7/10/2007 10:34:42 PM | Attr = ]
servicing -> %SystemRoot%\servicing -> [Folder | Modified Date = 6/27/2007 3:00:56 AM | Attr = ]
Sun -> %SystemRoot%\Sun -> [Folder | Modified Date = 7/19/2007 4:37:36 PM | Attr = ]
System32 -> %System32% -> [Folder | Modified Date = 7/18/2007 10:01:28 PM | Attr = ]
Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 7/16/2007 3:06:10 PM | Attr = ]
Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 7/20/2007 3:31:22 PM | Attr = ]
win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 335 bytes | Modified Date = 7/19/2007 2:28:24 PM | Attr = ]
WindowsMobile -> %SystemRoot%\WindowsMobile -> [Folder | Modified Date = 7/15/2007 2:25:32 PM | Attr = ]
winsxs -> %SystemRoot%\winsxs -> [Folder | Modified Date = 7/16/2007 3:01:00 AM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 7/16/2007 10:09:10 AM | Attr = H ]
User_Feed_Synchronization-{D5148304-AF67-4E76-AF30-6AD50B903BA3}.job -> %SystemRoot%\tasks\User_Feed_Synchronization-{D5148304-AF67-4E76-AF30-6AD50B903BA3}.job -> [Ver = | Size = 418 bytes | Modified Date = 7/20/2007 6:07:32 AM | Attr = H ]
7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> %System32%\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [Ver = | Size = 3552 bytes | Modified Date = 7/20/2007 3:09:00 PM | Attr = H ]
7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> %System32%\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [Ver = | Size = 3552 bytes | Modified Date = 7/20/2007 3:09:00 PM | Attr = H ]
bdod.bin -> %System32%\bdod.bin -> [Ver = | Size = 81984 bytes | Modified Date = 7/19/2007 5:29:10 PM | Attr = ]
catroot -> %System32%\catroot -> [Folder | Modified Date = 7/15/2007 2:27:16 PM | Attr = ]
catroot2 -> %System32%\catroot2 -> [Folder | Modified Date = 7/10/2007 9:05:42 PM | Attr = ]
drivers -> %System32%\drivers -> [Folder | Modified Date = 7/19/2007 4:38:32 PM | Attr = ]
en-US -> %System32%\en-US -> [Folder | Modified Date = 7/10/2007 10:33:22 PM | Attr = ]
FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 536328 bytes | Modified Date = 7/14/2007 5:49:10 PM | Attr = ]
GameUXLegacyGDFs.dll -> %System32%\GameUXLegacyGDFs.dll -> Microsoft [Ver = 1.0.0.1 | Size = 4247552 bytes | Modified Date = 7/10/2007 10:28:00 PM | Attr = ]
Kaspersky Lab -> %System32%\Kaspersky Lab -> [Folder | Modified Date = 7/18/2007 10:01:28 PM | Attr = ]
LogFiles -> %System32%\LogFiles -> [Folder | Modified Date = 7/10/2007 2:38:28 PM | Attr = ]
Macromed -> %System32%\Macromed -> [Folder | Modified Date = 6/30/2007 8:42:38 PM | Attr = ]
migration -> %System32%\migration -> [Folder | Modified Date = 6/23/2007 3:12:36 AM | Attr = ]
NDF -> %System32%\NDF -> [Folder | Modified Date = 7/2/2007 6:46:28 PM | Attr = ]
perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 104534 bytes | Modified Date = 7/16/2007 10:14:44 AM | Attr = ]
perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 620086 bytes | Modified Date = 7/16/2007 10:14:44 AM | Attr = ]
PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 716948 bytes | Modified Date = 7/16/2007 10:14:42 AM | Attr = ]
SLUI -> %System32%\SLUI -> [Folder | Modified Date = 7/10/2007 10:33:22 PM | Attr = ]
Tasks -> %System32%\Tasks -> [Folder | Modified Date = 7/16/2007 2:55:04 PM | Attr = ]
XPSViewer -> %System32%\XPSViewer -> [Folder | Modified Date = 6/27/2007 3:01:06 AM | Attr = ]
bdfsfltr.sys -> %System32%\drivers\bdfsfltr.sys -> SOFTWIN S.R.L. [Ver = 6.0.6000.16386 built by: WinDDK | Size = 167320 bytes | Modified Date = 6/21/2007 7:49:10 AM | Attr = ]
UMDF -> %System32%\drivers\UMDF -> [Folder | Modified Date = 7/15/2007 2:26:10 PM | Attr = ]
Msft_User_WpdRapi_01_00_00.Wdf -> %System32%\drivers\UMDF\Msft_User_WpdRapi_01_00_00.Wdf -> [Ver = | Size = 0 bytes | Modified Date = 7/15/2007 2:26:10 PM | Attr = H ]

[File String Scan - Non-Microsoft Only]
File scan skipped for file %SystemRoot%\MEMORY.DMP -> File size too big (116474250 bytes) ->
WSUD , -> %System32%\ALSNDMGR.CPL -> Realtek Semiconductor Corp. [Ver = 2.2.0.44 | Size = 18726912 bytes | Modified Date = 5/18/2005 3:17:54 PM | Attr = ]

< End of report >
This week it seems to have stopped. Maybe we scared it away with all the tests. Let's just wait and see. If it occurs again I will contact you…Thanks for your patience and diligence…Monty

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI