Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

301.

Solve : Help: Several problems I believed caused by an infection long ago?

Answer»

1. Right-click the My Computer icon on the Desktop and click Properties.
2. Click the Performance tab.
3. Click the File System button.
4. Click the Troubleshooting tab.
5. Remove the check mark next to Disable System Restore.
6. Click OK.
7. Click Yes when prompted to restart.


Then, please try the process above again.Sorry, but I don't see a Performance tab.. I see General, Computer Name, Hardware, Advanced, Automatic Updates, Remote? I'm right clicking My Computer, than properties than I'm missing something? 1. Right-click the My Computer icon on the Desktop and click Properties.
2. On the System Restore tab, uncheck Disable System Restore.

See if that helps
There isn't a system restore tab, I'm logged in as an Administrator. I don't know why its not there?Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
Code: [Select]:filefind
rstrui.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txtok, here it is.

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 09:43 on 11/06/2010 by Rachell (Administrator - Elevation successful)

========== filefind ==========

Searching for "rstrui.exe"
C:\WINDOWS\$NtServicePackUninstall$\rstrui.exe--a--c 380416 bytes[08:02 16/10/2008][19:00 04/08/2004] 4375CD59161C0A033DF68D9510D1F8CF
C:\WINDOWS\ServicePackFiles\i386\rstrui.exe--a--c 380416 bytes[17:31 29/08/2008][00:12 14/04/2008] BD6C1488F63D64DEA8EE514802FC2CDD
C:\WINDOWS\system32\dllcache\rstrui.exe--a--c 380416 bytes[19:01 07/08/2004][00:12 14/04/2008] BD6C1488F63D64DEA8EE514802FC2CDD
C:\WINDOWS\system32\Restore\rstrui.exe--a--- 380416 bytes[19:01 07/08/2004][00:12 14/04/2008] BD6C1488F63D64DEA8EE514802FC2CDD

-=End Of File=-Please open Notepad and enter in the following:
Quote
Windows Registry Editor Version 5.00

[HKLM\Software\Policies\Microso­ft\Windows NT\SystemRestore]
"DisableSR"=-
Then, click File > Save as...
Save as enableSR.reg to your Desktop.
Choose Save as type... All Files.
Click Save.

Then, exit Notepad.

Double-click on enableSR.reg.


Then, restart your computer.

Then, look in the System Properties window again for the System Restore tab.Sorry for just now writing back, long weekend... I did what you said and it asked if I wanted to add it to my registry I said yes and it said it had. I restarted and still no system restore tab. Also I get the same message still if I try to open System restore.
    We Need to Diagnose a Possible Problem with WGA
    • Please download MGADiag and save it to your desktop.
    • Double click the icon on your desktop.
    • Push
    • Push
    • Go to Start -> Run and type in "Notepad"
    • Go to Edit -> Paste in notepad.
    • x out all of the numbers and letters in the line beginning with "Windows Product Key:"
    • Copy and paste that log here.
    [/LIST]Ok, here it is

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->
    Validation Status: Genuine
    Validation Code: 0
    Cached Validation Code: N/A
    Windows Product Key: *****-*****-XXXXX-XXXXX-XXXXX
    Windows Product Key HASH: 2V2VyxlfhiaCt/JkDzYQfiNOHMA=
    Windows Product ID: 76477-OEM-2111907-00106
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 5.1.2600.2.00010300.3.0.hom
    ID: {16CCC64D-E3B3-4DA7-B4CA-7D6BBD0ECCAE}(3)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: Registered, 1.7.69.2
    Signed By: Microsoft
    Product Name: N/A
    Architecture: N/A
    Build lab: N/A
    TTS Error: N/A
    Validation Diagnostic: 025D1FF3-230-1
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A
    Version: N/A

    Windows XP Notifications Data-->
    Cached Result: 0
    File Exists: Yes
    Version: 1.7.17.0
    WgaTray.exe Signed By: Microsoft
    WgaLogon.dll Signed By: Microsoft

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 102
    Microsoft Office Standard Edition 2003 - 100 Genuine
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not MARKED as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: {16CCC64D-E3B3-4DA7-B4CA-7D6BBD0ECCAE}1.9.0027.05.1.2600.2.00010300.3.0.homx32*****-*****-*****-*****-3PMFT76477-OEM-2111907-001062S-1-5-21-1273659944-3790613762-3211983470HP Pavilion 061PL382AA-ABA A706NPhoenix Technologies, LTD 3.1120040902000000.000000+000HP PAVILION21DD39AF0184205F04090409Eastern Standard Time(GMT-05:00)02Hewlett-PackardPavilion102100Microsoft Office Standard Edition 200311606A581CC1FD930FEOgdhbkAmkHjihJ9UWrNxearM4=70141-152-3817414-5631810

    Licensing Data-->
    N/A

    Windows Activation Technologies-->
    N/A

    HWID Data-->
    N/A

    OEM Activation 1.0 Data-->
    BIOS string MATCHES: yes
    Marker string from BIOS: 106DD:Compaq Computer Corporation|106DD:Compaq Computer Corporation|106DD:Hewlett-Packard Company|10859:Hewlett-Packard Company
    Marker string from OEMBIOS.DAT: HP PAVILION

    OEM Activation 2.0 Data-->
    N/A

    -Click Start, and then click My Computer.
    -On the Tools menu, click Folder Options.
    -On the View tab, click Show hidden files and folders.
    -Clear the Hide protected operating system files (Recommended) check box. Click Yes when you are prompted to confirm the change.
    -Clear the Use simple file sharing (Recommended) check box.
    -Click OK.
    -Right-click the System Volume Information folder in the root folder, and then click Properties.
    -Click the Security tab.
    -Click Add, and then type the name of the user to whom you want to give access to the folder. Typically, this is the account with which you are logged on. Click OK, and then click OK again.

    -Then, navigate to C:\SystemVolumeInformation right click on it, and click on Rename.

    -Rename it to SystemVolumeBAK

    -Restart your computer.

    Tell me if you can see the Restore tab.Ok, Can you explain ''-Right-click the System Volume Information folder in the root folder'' I don't know where/what those are exactly? Sorry when I got to that step I was unsure of what to do. I did the first stuff already though. Clicked Show hidden files and folders already, Hide protected operating system files (Recommended) was already unchecked and there is no Use simple file sharing (Recommended) check box. c:\SystemVolumeInformationIt's not there and if I try to RUN it says Windows can not find 'c:\SystemVolumeInformation'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click search. Do you have a Windows XP CD??

    We need to do a system in-place upgrade, which is a data-safe process to fully repair Windows.


    However, if you do not feel comfortable with this, there are alternative routes to be able to take to backup your system configuration, like ERUNT program.
    302.

    Solve : psw.generic8.QQ malware??

    Answer»

    I've been working on a neighbors system for a few days trying to remove this pswgeneric8.QQ anyone have any experience with this one? I'll be running Hihack this this tomorrow night. Looks well written and have been OUTWITTED at most turns.

    R.Hello, and welcome to COMPUTER Hope.

    Please note the following information about the malware forum:

    • Only the Malware Specialist Team is allowed to give advice on removing malware from your computer.
    • From this point on, please do not make any more changes to your computer; such as install/uninstall PROGRAMS, use special fix tools, delete files, edit the registry, etc. - unless advised by the staff I noted above.
    • Please do not attach logs or post them in Quote/Code boxes unless requested.
    • Please do not ask for help elsewhere (in this site or other sites). Doing so can result in system changes, which may not show up in the logs you post.
    • If you have already ASKED for help somewhere, please post the link to the topic you were helped.
    • We try our best to reply quickly, but for any reason we do not reply in two days, reply to this topic with the word BUMP
    • Lastly, keep in mind that we are volunteers, so you do not have to pay for malware removal. Persist in this topic until its close, and your computer is declared clean.

    Please DOWNLOAD MySystem-Search from here: Download mirror
    • Save the file to your Desktop.
    • Double-click on mss.exe
    • Allow it to run, and follow the prompts.
    • Once done, it will launch a log.
    • Post it in your next reply.
    Note: the logs are long. Please use more than one post, if necessary. Sorry but the individual decided to buy a new system because the removal was becoming somewhat endless.
    303.

    Solve : Application cannot be executed. The file *** is infected.?

    Answer»
    I got a serious issue with my system. Somehow some trogan/rogue has affected my system. It keeps flashing me virus alert and whenever i try to run any program it says "Application cannot be executed. The file **** is infected......." (not even a command prompt or notepad can be opened but with multiple try sometime i get the command prompt but it is ridiculous). I saw a post about this but super dave said i would need my own help b/c it is complicated i need help asap[
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 03/01/2010 at 04:45 AM

    Application Version : 4.34.1000

    Core Rules Database Version : 4596
    Trace Rules Database Version: 1978

    Scan type : Complete Scan
    Total Scan Time : 00:56:48

    Memory ITEMS scanned : 475
    Memory threats detected : 0
    Registry items scanned : 5328
    Registry threats detected : 4
    File items scanned : 56527
    File threats detected : 91

    Rogue.AntivirusSoft
    [eyvcgfqu] C:\DOCUMENTS AND SETTINGS\MARCUS\LOCAL SETTINGS\APPLICATION DATA\YXRHFW\NMHWSFTAV.EXE
    C:\DOCUMENTS AND SETTINGS\MARCUS\LOCAL SETTINGS\APPLICATION DATA\YXRHFW\NMHWSFTAV.EXE
    HKU\S-1-5-21-13070270-1486359743-909414271-1008\Software\avsoft

    Adware.Tracking Cookie
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][3].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][3].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\jud[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][3].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Judy Martinez\Local Settings\Temp\Cookies\[emailprotected][1].txt

    Rogue.Agent/Gen
    HKLM\SOFTWARE\07720420
    HKLM\SOFTWARE\07720420#FirstRun

    Malware.Installer-Pkg/Gen
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{26D2C2C3-CF14-4ED7-B1FC-0BE64AFBA3B3}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{3C48F877-A164-45E9-B9DA-26A049FFC207}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6293BC00-4EB8-4C65-8548-53E2FC3BF937}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{651956B7-1969-42AA-9453-E0B813019D54}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6B6A7665-DB48-4762-AB5D-BEEB9E1CD7FA}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{989E4C3B-B2C9-4486-9A09-D5A8F953837C}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{C2D8F0E2-6978-4409-8351-BA8785DA11EE}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{D1A6F3FD-7B40-443F-8767-BADB25A0D222}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{E0814F95-5380-4892-B8C8-7FA4B349EF46}.EXE

    Adware.Vundo/Variant-Senorita
    C:\WINDOWS\SYSTEM32\BIGUKOVE.DLL
    C:\WINDOWS\SYSTEM32\BOBUHEZE.DLL
    C:\WINDOWS\SYSTEM32\FUNEREVU.DLL
    C:\WINDOWS\SYSTEM32\GAWOJUSO.DLL
    C:\WINDOWS\SYSTEM32\HIGUBOWO.DLL
    C:\WINDOWS\SYSTEM32\KABAHIGO.DLL
    C:\WINDOWS\SYSTEM32\KUFULEMU.DLL
    C:\WINDOWS\SYSTEM32\MEMUREZO.DLL
    C:\WINDOWS\SYSTEM32\MUFOHITO.DLL
    C:\WINDOWS\SYSTEM32\NAHATONA.DLL
    C:\WINDOWS\SYSTEM32\PAJOSURI.DLL
    C:\WINDOWS\SYSTEM32\WURAJOBI.DLL
    C:\WINDOWS\SYSTEM32\YAWEVODU.DLL
    C:\WINDOWS\SYSTEM32\ZAWEDIVO.DLL
    C:\WINDOWS\SYSTEM32\ZUHUYABA.DLL
    C:\WINDOWS\SYSTEM32\ZUWUPIMA.DLL

    Adware.Vundo/Variant-EC
    C:\WINDOWS\SYSTEM32\DIFORUSA.DLL
    C:\WINDOWS\SYSTEM32\FAGESEFA.DLL
    C:\WINDOWS\SYSTEM32\YOBIJOWU.DLL

    Adware.Vundo/Variant-[Fixed]
    C:\WINDOWS\SYSTEM32\LODORAJA.DLL
    C:\WINDOWS\SYSTEM32\MIZUYOHA.DLL
    C:\WINDOWS\SYSTEM32\TAROKUWE.DLL

    Adware.Vundo/Variant-BigJunk
    C:\WINDOWS\SYSTEM32\VIDUVUVE.DLL

    Adware.Vundo/Variant-Diddle
    C:\WINDOWS\SYSTEM32\YUYIFANE.DLL
    May I know the operating system? Internet connection type? Any specific pop up that you're being prompted to INSTALL? Hello,

    I am getting the same message.. Application cannot be executed. The file *** is infected. and it keeps popping up every 2 minutes....also a windows security alert keeps popping up...i need help desperatley!!!! please...Hi Telly 24...
    May I know the version of the operating system that you have. Internet connection type:..?yes, its windows xp and i use internet exploer and moziilla firefox...and i have at&t dsl..i recently got it about 5 days ago...and those yellow shields with the exclamation points are all acroos my toolbar at the bottom of my screen!!! i need help!!Hi, this seems to be what's happening to me as well. In addition, after awhile random PORN sites will pop up. There's also a file on my desktop that I didn't put there: hs_err_pid1176.txt

    I'm running Windows XP, using a wireless connection on my laptop. As for my browser, I use Internet Explorer. I hope that's enough! YES THE RANDOM PORN WEBSITES ARE HAPPENING TO ME AS WELL!!!Please DO NOT give advice in this forum UNLESS you are a malware specialist.thank u so much..i will give it a try and u know!!!!


    -tellyhey...
    it wont let me open the iexplore (misconfig)...the same error message is popping up..its saying its infected and do i want to run antivrus scan now....the "System Configuration Utility" screen pops up now but it dissaperas after a second..i cant do anything with it...You have been warned to not post any advice in this forum.
    304.

    Solve : persistent TR/Crypt.Xpack.gen?

    Answer»

    I'll look you up the NEXT time I'm in HAWAII

    Quote

    OK - how do I MARK this ONE [solved] ?

    I can do that for you
    305.

    Solve : Virus will not get out of my computer...requesting assistance pls.?

    Answer»

    That's good. I would say your computer is as clean as our scans can make it. Let's do some clean-up.

    * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
    * Now type Combofix /uninstall in the runbox
    * Make sure there's a space between Combofix and /Uninstall
    * Then hit Enter

    * The above procedure will:
    * Delete the following:
    * ComboFix and its associated files and folders.
    * Reset the clock settings.
    * Hide file extensions, if required.
    * Hide System/Hidden files, if required.
    * SET a new, clean Restore Point.

    =============================

    Download OTC by OldTimer and save it to your desktop.

    1. Double-click OTC to run it.
    2. Click the CleanUp! button.
    3. Select Yes when the "Begin cleanup Process?" prompt appears.
    4. If you are prompted to Reboot during the cleanup, select Yes
    5. OTC should delete itself once it finishes, if not delete it yourself.

    ===========================

    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have saved all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
    * Please let TFC run uninterrupted until it is finished.

    Once TFC is finished it should RESTART your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

    ===============================

    Looking over your log it seems you don't have any evidence of a third party firewall.

    Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

    Remember only install ONE firewall

    1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
    2) Online Armor
    3) Agnitum Outpost
    4) PC Tools Firewall Plus

    If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing CONNECTIONS. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

    =================================

    Use the Secunia Software Inspector to check for out of date software.

    •Click Start Now

    •Check the box next to Enable thorough system inspection.

    •Click Start

    •Allow the scan to finish and scroll down to see if any updates are needed.
    •Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, VIRUSES and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to PREVENT spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!
    Thank you Dave for all your time and work. My computer is running a lot better. I really appreciate this!

    306.

    Solve : Stuck with fake antivirus, can't install anything.?

    Answer»

    Alright, here is the OTM log first, scanning with ESET now. That file looked suspicious to me also when I looked at the GSI report, 58FE1887.exe. Hey man, I really appreciate the time and effort you guys spend on these forums.

    All processes killed
    ========== FILES ==========
    C:\WINDOWS\system32\58FE1887.exe moved successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Guest
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 74045948 bytes
    ->Flash cache emptied: 3408 bytes

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 802950 bytes
    ->Flash cache emptied: 1693 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes
    ->Java cache emptied: 493 bytes
    ->Flash cache emptied: 4297 bytes

    User: Zickes
    ->Temp folder emptied: 2397433 bytes
    ->Temporary Internet Files folder emptied: 7186538 bytes
    ->Java cache emptied: 68365446 bytes
    ->FireFox cache emptied: 62844203 bytes
    ->Flash cache emptied: 499146 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 3353102 bytes
    %systemroot%\System32 .tmp files removed: 1847313 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 278528 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 211.00 mb


    OTM by OldTimer - Version 3.1.12.2 log created on 06292010_205014

    Files moved on Reboot...

    Registry entries deleted on Reboot...
    Hello, I have just finish the ESET scan, and here is the log.

    # version=4
    # OnlineScanner.ocx=1.0.0.635
    # OnlineScannerDLLA.dll=1, 0, 0, 79
    # OnlineScannerDLLW.dll=1, 0, 0, 78
    # OnlineScannerUninstaller.exe=1, 0, 0, 49
    # vers_standard_module=3650 (20081128)
    # vers_arch_module=1.064 (20080214)
    # vers_adv_heur_module=1.066 (20070917)
    # EOSSerial=abd6c213bafb4a44b0582f84f841acd5
    # end=finished
    # remove_checked=true
    # unwanted_checked=true
    # utc_time=2008-11-29 07:15:28
    # local_time=2008-11-29 11:15:28 (-0800, Pacific Standard Time)
    # country="United States"
    # osver=5.1.2600 NT Service Pack 3
    # scanned=692417
    # found=0
    # scan_time=5536

    I don't know how that log will help you but here is the log of the infected files found by ESET if it helps.

    C:\Qoobox\Quarantine\C\Documents and Settings\Zickes\Local Settings\Application Data\mgeohxxdo\joxqswktssd.exe.vira variant of Win32/Kryptik.FFD trojancleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\afd.sys.virWin32/Olmarik.ZC trojancleaned - quarantined
    Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:

    • Select Start > All Programs > Accessories > System tools > System Restore.
    • On the dialogue box that appears select Create a Restore Point
    • Click NEXT
    • Enter a name e.g. Clean
    • Click CREATE
    You now have a clean restore point, to get rid of the bad ones:
    • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
    • In the Drop down box that appears select your main drive e.g. C
    • Click OK
    • The System will do some calculation and the display a dialogue box with TABS
    • Select the More Options Tab.
    • At the bottom will be a system restore box with a CLEANUP button click this
    • Accept the Warning and select OK again, the program will close and you are DONE
    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will DELETE itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    ==

    Please download TFC by OldTimer to your desktop
    • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • It will close all programs when run, so make sure you have saved all your work before you begin.
    • Click the Start
      button to begin the process. Depending on how often you clean temp
      files, execution time should be anywhere from a few seconds to a minute
      or two. Let it run uninterrupted to completion.
    • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
    ==

    Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and FOLLOW the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    Everything done. Does this mean I finally rid my computer of that nasty virus? Was the Quarantine Olmarik trojan and the Kryptik trojan deleted?

    Results of screen317's Security Check version 0.99.4
    Windows XP Service Pack 3
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Disabled!
    ESET Online Scanner v3
    ESET Online Scanner
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    Java(TM) 6 Update 18
    Out of date Java installed!
    Adobe Flash Player 9 (Out of date Flash Player installed!)
    Adobe Flash Player 10.0.45.2
    Adobe Reader 9.1.2
    Out of date Adobe Reader installed!
    Mozilla Firefox (3.6.6)
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    ````````````````````````````````
    DNS Vulnerability Check:

    GREAT! (Not vulnerable to DNS cache poisoning)

    ``````````End of Log```````````` Those are in quarantine and are harmless.

    Please download the newest version of Adobe Acrobat Reader from Adobe.com

    Before installing: it is IMPORTANT to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
    Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

    Once old versions are gone, please install the newest version.

    ==

    Please download the newest version of Java from Java.com.

    Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
    Search in the list for all previous installed versions of Java. (J2SE Runtime ENVIRONMENT). Please uninstall/remove each of them.

    Once old versions are gone, please install the newest version.

    =================================

    Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

    Software recommendations

    Antivirus/Antispyware
    • Microsoft Security Essentials: this is Microsoft's free antivirus/antispyware program. It equips you with protection against viruses, spyware, trojans, rootkits, and worms. It is also light on the computer's performance. Note: when installing this, you have both an antivirus and antispyware. Make sure you also get a firewall.
    • Avira Free: this is one of the most powerful, and easiest to use security software. The free version equips you with protection against viruses, spyware, trojans, rootkits, worms, and rogue software.
    Firewall
    • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
    • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
    • PC Tools Firewall Plus: free and excellent firewall.
    Note: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

    Resident Protection help
    A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

    Securing your computer
    • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
    • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
    Please consider using an alternate browser
    Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

    If you are interested:
    See this page for more info about malware and prevention.Awesome thanks, so what do I do with the other install files like Rookit Unhooker LE? or GSI?Delete them.
    Okay, I updated my Java and my Adobe Flash, and I tried using hphost but I feel like it is to much for me so I took it off. Thanks for all these great programs!You're welcome.lol. I don't really know how to express my relieve and my gratefulness for you because I'm not very good at it. lol I just want to say that I am just very happy for this forum to exist and for people like you who spend countless hours providing easy to read step by step instructions on fighting malware. I don't know if you guys have a database where you keep a bunch of pre-written instructions but I think it is very helpful and it definitely makes things go a lot quicker. You probably receive hundreds of thank you's or whatnot but I don't know any other way to express how I feel right not without using profanity so thank you.

    This will be my last post for a while because I am inspired deeply of the things a Malware removal specialist do. Next time I post, it will be approximately a year or so later and I will come back telling you about my accomplishments as a Malware removal specialist. I know it isn't like riding a bike on a downhill and its not just saying I have to do it, but I have a lot of time on me and hopefully I will have a good start. Hopefully you will remain in this forum, no pressure =P. You might be busy with other important things.

    p.s-waiting for bleepingcomputer to have an open slot
    307.

    Solve : infected laptop??

    Answer»

    i'm running Windows XP home service pack 1.

    upon startup i get 4 Trojans(according to Avira). i also get a Zone Alarm alert.
    They are:

    Avira:
    TR/Spy.62464.55 Trojan
    TR/Gendal.304896 Trojan
    TR/Gendal.304896 Trojan
    TR/Spy.zbo.YW.15358

    Zone Alarm:
    Windows Explorer is trying to act as a server

    Of course i denied and closed all the alerts. i've also included my Hijackthis log. hopefully someone can help.

    i also just noticed the recycle bin on my desktop is not showing the icon.

    thanks




    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:13:11 PM, on 7/5/2010
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot MODE: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\WINDOWS\System32\gearsec.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\Avira\AntiVir Desktop\GUARDGUI.EXE
    C:\Program Files\Avira\AntiVir Desktop\GUARDGUI.EXE
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Avira\AntiVir Desktop\GUARDGUI.EXE
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Avira\AntiVir Desktop\GUARDGUI.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Avira\AntiVir Desktop\update.exe
    C:\Program Files\Trend Micro\HijackThis2.0.2\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Yahoo! IE Services BUTTON - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: (no name) - {BD31D51D-B8AD-4E64-B8CE-91AAF4DB1E54} - C:\WINDOWS\System32\byvsq.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [dmfcvtdn] C:\Documents and Settings\Big Dog\Local Settings\Application Data\iwbbwjnrm\jqrvjudtssd.exe
    O4 - HKLM\..\Run: [Evuco] rundll32.exe "C:\WINDOWS\amuhegucob.dll",Startup
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [dmfcvtdn] C:\Documents and Settings\Big Dog\Local Settings\Application Data\iwbbwjnrm\jqrvjudtssd.exe
    O4 - HKCU\..\Run: [{029289AA-FCD3-A95A-5DCF-8D3D723B1BBA}] "C:\Documents and Settings\Big Dog\Application Data\Ryxun\kulei.exe"
    O4 - HKCU\..\Run: [Acarucu] rundll32.exe "C:\WINDOWS\moncodi.dll",Startup
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'Default user')
    O4 - Global Startup: BTTray.lnk = ?
    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 7932 bytes



    Please VISIT this webpage for a tutorial on downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    See the area: Using ComboFix, and when done, post the log back here.hi.
    thanks for the redirect and the reply. here is my combofix log:



    ComboFix 10-07-06.02 - Big Dog 07/07/2010 0:26.1.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.511.311 [GMT -4:00]
    Running from: c:\documents and settings\Big Dog\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Big Dog\Application Data\Ryxun
    c:\documents and settings\Big Dog\Application Data\Ryxun\kulei.exe
    c:\documents and settings\Big Dog\Local Settings\Application Data\{F8CA3691-B7C2-467B-A3A6-DB64088DB614}
    c:\documents and settings\Big Dog\Local Settings\Application Data\{F8CA3691-B7C2-467B-A3A6-DB64088DB614}\chrome.manifest
    c:\documents and settings\Big Dog\Local Settings\Application Data\{F8CA3691-B7C2-467B-A3A6-DB64088DB614}\chrome\content\_cfg.js
    c:\documents and settings\Big Dog\Local Settings\Application Data\{F8CA3691-B7C2-467B-A3A6-DB64088DB614}\chrome\content\overlay.xul
    c:\documents and settings\Big Dog\Local Settings\Application Data\{F8CA3691-B7C2-467B-A3A6-DB64088DB614}\install.rdf
    c:\documents and settings\Big Dog\Local Settings\Application Data\iwbbwjnrm\jqrvjudtssd.exe
    c:\windows\amuhegucob.dll
    c:\windows\moncodi.dll

    .
    ((((((((((((((((((((((((( Files Created from 2010-06-07 to 2010-07-07 )))))))))))))))))))))))))))))))
    .

    2010-07-06 00:10 . 2010-07-06 00:10--------d-----w-c:\program files\Trend Micro
    2010-06-22 08:45 . 2010-06-22 08:4552224----a-w-c:\documents and settings\Big Dog\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-07 04:27 . 2010-06-06 17:440----a-w-c:\windows\Jcepabowinewuno.bin
    2010-07-07 03:53 . 2010-06-06 17:43120----a-w-c:\windows\Mxupofulo.dat
    2010-07-06 00:19 . 2007-08-17 09:23--------d-----w-c:\documents and settings\Big Dog\Application Data\Apnyyh
    2010-06-22 08:45 . 2009-09-14 01:13117760----a-w-c:\documents and settings\Big Dog\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2010-06-15 04:13 . 2006-04-23 04:1628242846----a-w-c:\windows\Internet Logs\tvDebug.zip
    .

    ------- Sigcheck -------



    [-] 2003-05-30 13:00 . 7BA80564F369A96AF84E3AA27E75E90B . 1634304 . . [5.3.0000001.902 built by: DIRECTX] . . c:\windows\system32\d3d9.dll

    c:\windows\System32\wscntfy.exe ... is missing !!
    c:\windows\System32\xmlprov.dll ... is missing !!
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 4670968]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-07-13 110592]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-07-13 618496]
    "Zone Labs Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-03-16 755480]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-10-23 98304]
    "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
    "AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2007-10-24 219136]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-11-10 507965]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2009-09-03 19:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "mixer"=APTRRNTm.dll
    "wave"=APTRRNTm.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
    backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Big Dog^Start Menu^Programs^Startup^Adobe Gamma.lnk]
    path=c:\documents and settings\Big Dog\Start Menu\Programs\Startup\Adobe Gamma.lnk
    backup=c:\windows\pss\Adobe Gamma.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
    2003-05-04 11:1688267----a-r-c:\windows\AGRSMMSG.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
    2001-09-03 03:2428672----a-w-c:\windows\system32\Ati2mdxx.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
    2004-01-21 01:10335872----a-w-c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
    2008-10-21 01:30590848----a-w-c:\progra~1\Grisoft\AVG7\avgcc.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
    2004-03-01 17:05200766----a-w-c:\program files\HPQ\Default Settings\Cpqset.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2004-01-16 16:16229376----a-w-c:\program files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    2004-11-15 20:181670144----a-w-c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2004-10-23 20:3398304----a-w-c:\program files\QuickTime\qttask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2006-11-09 19:0749263----a-w-c:\program files\Java\jre1.5.0_10\bin\jusched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    2006-05-14 14:42180269----a-w-c:\program files\Common Files\Real\Update_OB\realsched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
    2003-08-19 05:01110592----a-w-c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe"

    R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [12/20/2009 9:56 AM 22360]
    R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [12/20/2009 9:56 AM 45416]
    R1 ewido security suite driver;ewido security suite driver;c:\program files\ewido anti-malware\guard.sys [12/30/2005 7:12 AM 3072]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/4/2009 2:50 PM 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/4/2009 2:49 PM 74480]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/20/2009 9:56 AM 108289]
    R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;c:\windows\system32\drivers\wbsd.sys [10/23/2004 4:20 PM 27008]
    S2 mrtRate;mrtRate;


    S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/4/2009 2:50 PM 7408]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-07 c:\windows\Tasks\Symantec NetDetect.job
    - c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-10-23 17:24]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.yahoo.com/
    uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
    IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{BD31D51D-B8AD-4E64-B8CE-91AAF4DB1E54} - c:\windows\System32\byvsq.dll
    HKCU-Run-dmfcvtdn - c:\documents and settings\Big Dog\Local Settings\Application Data\iwbbwjnrm\jqrvjudtssd.exe
    HKCU-Run-{029289AA-FCD3-A95A-5DCF-8D3D723B1BBA} - c:\documents and settings\Big Dog\Application Data\Ryxun\kulei.exe
    HKCU-Run-Acarucu - c:\windows\moncodi.dll
    HKLM-Run-dmfcvtdn - c:\documents and settings\Big Dog\Local Settings\Application Data\iwbbwjnrm\jqrvjudtssd.exe
    HKLM-Run-Evuco - c:\windows\amuhegucob.dll
    MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
    MSConfigStartUp-SSC_UserPrompt - c:\program files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-07-07 00:32
    Windows 5.1.2600 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\8ond*Ä***Àˆ/*_*a*u*t*o*_*f*i*l*e*\shell\open\command]
    @="\"c:\\Program Files\\Winamp\\winamp.exe\" \"%1\""
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(968)
    c:\windows\system32\ODBC32.dll
    c:\program files\SUPERAntiSpyware\SASWINLO.dll

    - - - - - - - > 'lsass.exe'(1028)
    c:\windows\System32\dssenh.dll
    .
    Completion time: 2010-07-07 00:35:37
    ComboFix-quarantined-files.txt 2010-07-07 04:35

    Pre-Run: 11,391,451,136 bytes free
    Post-Run: 11,687,886,848 bytes free

    winxpsp1_en_hom_bf.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect

    - - End Of File - - 79FC033ACDA507704DE217164703EEA6
    GMER

    Note about this tool:
    • This program may freeze. Do not reboot the computer, unless it has been frozen for over 30 minutes.
    • This program may cause a blue screen of death. If it does, do not scan, and then reply to let me know.
    • No matter what is in the log, please post all the information/contents of the log.
    Please download the GMER Rootkit Scanner. UNZIP it to your Desktop.

    Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

    Double-click gmer.exe. The program will begin to run.

    **Caution**
    These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised!

    If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
    • Click NO
    • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
    • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
    • Click OK.
    • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
    • Save it where you can easily find it, such as your desktop.
    Post the contents of GMER.txt in your next reply.GMER 1.0.15.15281 - http://www.gmer.net
    Rootkit scan 2010-07-09 23:37:37
    Windows 5.1.2600 Service Pack 1
    Running: gmer.exe; Driver: C:\DOCUME~1\BIGDOG~1\LOCALS~1\Temp\uwtdqpob.sys


    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwConnectPort [0xB2A82C90]
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateFile [0xB2A7FB70]
    SSDT F8C3B496 ZwCreateKey
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateProcess [0xB2A97760]
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateProcessEx [0xB2A97980]
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateSection [0xB2A9A610]
    SSDT F8C3B48C ZwCreateThread
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteFile [0xB2A80180]
    SSDT F8C3B49B ZwDeleteKey
    SSDT F8C3B4A5 ZwDeleteValueKey
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDuplicateObject [0xB2A97080]
    SSDT F8C3B4AA ZwLoadKey
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenFile [0xB2A7FFD0]
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenProcess [0xB2A96E80]
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenThread [0xB2A96C40]
    SSDT F8C3B4B4 ZwReplaceKey
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwRequestWaitReplyPort [0xB2A82960]
    SSDT F8C3B4AF ZwRestoreKey
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSecureConnectPort [0xB2A82E40]
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSetInformationFile [0xB2A802F0]
    SSDT F8C3B4A0 ZwSetValueKey
    SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwTerminateProcess [0xB2A97BB0]

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntoskrnl.exe!_abnormal_termination + 38F 804DE941 3 Bytes [2E, A8, B2]

    ---- Kernel IAT/EAT - GMER 1.0.15 ----

    IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCoSendPackets] 8162C5C0
    IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateFile] [B2AA5980] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\irda.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\irda.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\irda.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\irda.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [B2A87590] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [B2A87700] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [B2A87C30] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [B2A87AD0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtOpenFile] [B2A80630] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtSetInformationFile] [B2A80580] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateFile] [B2A806F0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtCreateFile] [B2A804A0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AnimateWindow] [63601740] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [63602AE9] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [63602B3E] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63602AA2] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63602A5B] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [63602441] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [63602065] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [63601FC4] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [636015C8] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [636015EF] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)
    IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3868] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [6360208F] C:\Program Files\Yahoo!\Shared\YbSkin2.dll (Yahoo! Skinning Object/Yahoo! Inc.)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \FileSystem\Ntfs \Ntfs avgntmgr.sys (Avira AntiVir File Filter Driver Manager/Avira GmbH)
    AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

    Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    Device \Driver\Tcpip \Device\Ip avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)

    AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
    AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 mouclass.sys (Mouse Class Driver/Microsoft CORPORATION)
    AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

    Device \Driver\Tcpip \Device\Tcp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    Device \Driver\Tcpip \Device\Tcp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
    Device \Driver\Tcpip \Device\Udp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    Device \Driver\Tcpip \Device\Udp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
    Device \Driver\Tcpip \Device\RawIp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    Device \Driver\Tcpip \Device\RawIp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
    Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
    Device \Driver\Tcpip \Device\IPMULTICAST avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)

    AttachedDevice \FileSystem\Fastfat \Fat avgntmgr.sys (Avira AntiVir File Filter Driver Manager/Avira GmbH)
    AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

    ---- EOF - GMER 1.0.15 ----
    Please run a free online scan with the ESET Online Scanner
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • When asked, allow the ActiveX control to install
    • Click Start
    • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, you may close the window
    • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    • Copy and paste that log as a reply to this topic
    here ya go


    [emailprotected] as CAB hook log:
    OnlineScanner.ocx - registred OK
    # version=7
    # IEXPLORE.EXE=6.00.2800.1106 (xpsp1.020828-1920)
    # OnlineScanner.ocx=1.0.0.6211
    # api_version=3.0.2
    # EOSSerial=e54cef16f0e80844b00e0a12fbd7fbd1
    # end=finished
    # remove_checked=true
    # archives_checked=false
    # unwanted_checked=true
    # unsafe_checked=false
    # antistealth_checked=true
    # utc_time=2010-07-12 04:45:50
    # local_time=2010-07-12 12:45:50 (-0500, Eastern Daylight Time)
    # country="United States"
    # lang=1033
    # osver=5.1.2600 NT Service Pack 1
    # compatibility_mode=512 16777215 100 0 0 0 0 0
    # compatibility_mode=1797 16775165 100 94 0 50622782 0 0
    # compatibility_mode=8192 67108863 100 0 0 0 0 0
    # compatibility_mode=9217 16777214 75 70 128644083 135471291 0 0
    # scanned=39824
    # found=4
    # cleaned=4
    # scan_time=2089
    C:\Qoobox\Quarantine\C\Documents and Settings\Big Dog\Application Data\Ryxun\kulei.exe.virWin32/Spy.Zbot.YW trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
    C:\Qoobox\Quarantine\C\Documents and Settings\Big Dog\Local Settings\Application Data\iwbbwjnrm\jqrvjudtssd.exe.vira variant of Win32/Injector.BXP trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
    C:\Qoobox\Quarantine\C\WINDOWS\amuhegucob.dll.vira variant of Win32/Cimag.CK trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
    C:\Qoobox\Quarantine\C\WINDOWS\moncodi.dll.vira variant of Win32/Cimag.CL trojan (cleaned by deleting - quarantined)00000000000000000000000000000000C
    Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
    • Select Start > All Programs > Accessories > System tools > System Restore.
    • On the dialogue box that appears select Create a Restore Point
    • Click NEXT
    • Enter a name e.g. Clean
    • Click CREATE
    You now have a clean restore point, to get rid of the bad ones:
    • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
    • In the Drop down box that appears select your main drive e.g. C
    • Click OK
    • The System will do some calculation and the display a dialogue box with TABS
    • Select the More Options Tab.
    • At the bottom will be a system restore box with a CLEANUP button click this
    • Accept the Warning and select OK again, the program will close and you are done
    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    ==

    Please download TFC by OldTimer to your desktop
    • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • It will close all programs when run, so make sure you have saved all your work before you begin.
    • Click the Start
      button to begin the process. Depending on how often you clean temp
      files, execution time should be anywhere from a few seconds to a minute
      or two. Let it run uninterrupted to completion.
    • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
    ==

    Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    sorry for the late reply.
    i couldnt get past the disk cleanup part. the program hangs up.
    should i skip that step?sureagain, sorry for the late reply but i have a SERIOUS problem now.

    i'm using a friend's computer right now because mine will not boot up. it seems as if my hard drive crashed.

    it started almost a week ago. i downloaded TFC and followed the steps. after all was finished i had to reboot manually as directed. i did and went to bed. i awoke the next morning to find a black screen with the words "Non-System disk or disk error. replace and strike any key when ready" nothing happens no matter which key i hit.

    i shut the computer off and tried to restart it. this time i hear clicking noises, then i get the same message. and the same results.


    what gives?Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster Jay@bklyn

    Do you have an XP disc?Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help. ~ DragonMaster JaySorry, I mistakenly posted the last post from my friend's account. i thought he had logged off. Remember, I'm using his computer since i cannot use mine?

    Ok, all i have is a disc labeled "Operating System CD". Microsoft Windoes XP Home SP1a.
    308.

    Solve : Alureon.H rootkit virus TermDD?

    Answer»

    ESET Scan result:
    ------------------------

    C:\Documents and Settings\HelpAssistant\Local Settings\Temp\jar_cache57910.tmpa variant of Java/TrojanDownloader.Agent.NAN trojandeleted - quarantined
    C:\Documents and Settings\HelpAssistant\Local Settings\Temp\jar_cache7136.tmpa variant of Java/TrojanDownloader.Agent.NAN trojandeleted - quarantined


    Log file content:
    --------------------
    [emailprotected] as CAB hook log:
    OnlineScanner.ocx - registred OK
    # version=7
    # iexplore.exe=7.00.6000.17023 (vista_gdr.100222-0012)
    # OnlineScanner.ocx=1.0.0.6211
    # api_version=3.0.2
    # EOSSerial=30832513b651c148a9e0d6094cf3eca9
    # end=finished
    # remove_checked=true
    # archives_checked=true
    # unwanted_checked=true
    # unsafe_checked=true
    # antistealth_checked=true
    # utc_time=2010-06-04 10:29:58
    # local_time=2010-06-04 03:29:58 (-0800, Pacific Daylight Time)
    # country="United States"
    # lang=1033
    # osver=5.1.2600 NT Service Pack 3
    # compatibility_mode=1024 16777215 100 0 0 0 0 0
    # compatibility_mode=2560 16777215 100 0 0 0 0 0
    # compatibility_mode=8192 67108863 100 0 0 0 0 0
    # scanned=239584
    # found=2
    # cleaned=2
    # scan_time=24685
    C:\Documents and Settings\HelpAssistant\Local Settings\Temp\jar_cache57910.tmpa variant of Java/TrojanDownloader.Agent.NAN trojan (deleted - quarantined)00000000000000000000000000000000C
    C:\Documents and Settings\HelpAssistant\Local Settings\Temp\jar_cache7136.tmpa variant of Java/TrojanDownloader.Agent.NAN trojan (deleted - quarantined)00000000000000000000000000000000C
    That looks good. If there are no other issues, it's time for some clean-up

    * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
    * Now type Combofix /uninstall in the runbox
    * Make sure there's a space between Combofix and /Uninstall
    * Then hit Enter

    * The above procedure will:
    * Delete the following:
    * ComboFix and its associated files and folders.
    * Reset the clock settings.
    * Hide file extensions, if required.
    * Hide System/Hidden files, if required.
    * Set a new, clean Restore Point.

    ==============================

    Download OTC by OldTimer and save it to your desktop.

    1. Double-click OTC to run it.
    2. Click the CleanUp! button.
    3. Select Yes when the "Begin cleanup Process?" prompt appears.
    4. If you are prompted to Reboot during the cleanup, select Yes
    5. OTC should delete itself once it finishes, if not delete it yourself.

    ===============================

    Clean out your temporary internet files and temp files.

    Download TFC by OldTimer to your desktop.

    Double-click TFC.exe to run it.

    Note: If you are running on Vista, right-click on the file and choose Run As Administrator

    TFC will close all programs when run, so make sure you have saved all your work before you begin.

    * Click the Start button to begin the cleaning process.
    * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
    * Please let TFC run uninterrupted until it is finished.

    Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

    ============================

    Looking over your log it seems you don't have any evidence of a third party firewall.

    Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

    Remember only install ONE firewall

    1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com OPTIONS if you choose this one)
    2) Online Armor
    3) Agnitum Outpost
    4) PC Tools Firewall Plus

    If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software SOLUTION. Remember to use only one firewall at the same time.

    ===============================

    Use the Secunia Software Inspector to check for out of DATE software.

    •Click Start Now

    •Check the box next to Enable thorough system inspection.

    •Click Start

    •Allow the scan to finish and scroll down to see if any updates are needed.
    •Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of TRUST. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. GUIDE: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!
    Thanks. I have not had any more issues recently. I will perform those steps and revert.SuperDev:

    I installed Comodo Plus firewall and since then I did not encounter any issues. However, Firewall keeps popping up for any action that is being performed against important files.

    I think firewall does learn on its own and will be fine later.

    Thanks so much for your help.

    Any other advice for me?

    Thanks!I had that same problem when I install Comodo but now I hardly notice it. One thing I do when I'm installing a new program is to disable it and enable my Windows Firewall because Comodo can make a simple install into a 1/2 hr. ordeal.

    309.

    Solve : Spyware Problem. :/?

    Answer»

    Re-running ComboFix to remove infections:

    • Close any open browsers.
    • Close/disable all anti virus and anti MALWARE PROGRAMS so they do not interfere with the running of ComboFix.
    • Open notepad and copy/paste the text in the codebox below into it:
    Code: [Select]killall::

    Snapshot::

    SysRst::

    TDL::
    c:\windows\system32\drivers\mouclass.sys
    c:\windows\system32\drivers\atapi.sys

    Reboot::
    • SAVE this as CFScript.txt, in the same location as ComboFix.exe



    • Referring to the picture above, drag CFScript into ComboFix.exe
    • When finished, it shall produce a log for you at C:\ComboFix.txt
    • Please POST the contents of the log in your next reply.
    310.

    Solve : File wuauclt.exe is infected?

    Answer»

    Thank you very much for your assistance in CLEANING my COMPUTER. It WORKS great! Thanks again!You're WELCOME.

    311.

    Solve : multiple virus attacks?

    Answer»

    I have been attacked by multiple viruses. My AV, Bit Defender has blocked them but has not gotten rid of them, after waiting 4 days for their help I DECIDED to follow the steps here to remove them. I used SuperAV and found four infections, and removed them, but today the viruses came back. So I ran antiMalware and found 5( some of which MIGHT have be in quarantine. I next did a hijack log but I got a message saying "denied write access to Host file" hijack gave me instructions on how to resolve this but that didn't work. I suspect these viruses are still there. I could not cut and paste the hijack log but I did take a pic of it. I would appreciate any help .

    Thank yourename hjt to snipper.exe and run

    are you on win 7Yes I am on Windows7
    I tried changing it to snipper exe but my pc couldn't read the exe file. It was originally downloaded as a msi file.I did rename it to snipper .msi and installed it and got the same message. I did a screen capture of the message, I also did a screen capture of the hijack results. It would not create a log file.

    Thankssome additional information. When I ran the hijack the FIRST time it gave me instruction on how to by PASS the problem with the host file. It said to edit it myself but I was unable to do that too. I am now getting a message saying C/user/mark/appData/local/afoheyev.dll "specified module could not be found"
    I get this message whenever I boot up. Thought this might help.win7 , right click and run as adminwin7 right, but I need a little more clarification on "right click and run as administrator".Right click what? When I install something? And if I do run as administrator what do I do next? do you mean to install something or run a virus scan? I am not that familiar with your directions.

    Thankssorry , the hjt icon on the screen , right click it and click run as adim , its the only way it starts for me on win7 , worth a try If I do a right click on it I don't get any option to run as administrator. Are you TALKING about the installed program or the install file. I tried both and neither would allow me to run as administrator.

    Thankssorry i dont know what else to tell , you will have to wait for a malware expert to get something else , harry

    312.

    Solve : Malware removal - can't perform any suggested steps with .exe file?

    Answer»

    I ran superantispyware this morning and rebooted per your instructions. Once I did that, I could not open any progeam, I get the error message about .exe file being infected. So I ran rkill again since that is what enabled me to do ANYTHING yesterday.

    This is the rkill log:

    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.
    Ran as Lisa on 08/17/2010 at 10:36:51.


    Processes terminated by Rkill or while it was running:


    C:\Users\Lisa\AppData\Local\tconxtygj\yqidoqdshdw.exe
    C:\Users\Lisa\Desktop\rkill.scr


    Rkill completed on 08/17/2010 at 10:36:57.

    Then I was able to run Super anti spyware and get the log below:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 08/17/2010 at 09:48 AM

    Application Version : 4.41.1000

    Core Rules Database Version : 5347
    Trace Rules Database Version: 3159

    Scan type : Complete Scan
    Total Scan Time : 01:27:59

    Memory items scanned : 649
    Memory threats detected : 0
    Registry items scanned : 16216
    Registry threats detected : 0
    File items scanned : 48107
    File threats detected : 24

    Adware.Tracking Cookie
    .hitbox.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .ehg-verizon.hitbox.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .ehg-verizon.hitbox.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .ehg-verizon.hitbox.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .hitbox.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .atdmt.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .atdmt.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .revsci.net [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .revsci.net [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .revsci.net [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .doubleclick.net [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .statcounter.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .revsci.net [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .revsci.net [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .kontera.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .kontera.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .kontera.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .kontera.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .collective-media.net [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .collective-media.net [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .collective-media.net [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    .collective-media.net [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]
    ad.yieldmanager.com [ C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\cookies.sqlite ]


    Ran Security Check, log follows:

    Results of screen317's Security Check version 0.99.5
    Windows Vista (UAC is enabled)
    Out of date service pack!![/b]
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    Avira AntiVir Personal - Free Antivirus
    WMI entry may not exist for antivirus; attempting automatic update.
    Avira successfully updated!
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    CCleaner
    Java(TM) 6 Update 15
    Java(TM) 6 Update 2
    Java(TM) 6 Update 4
    Java(TM) 6 Update 7
    Out of date Java installed!
    Adobe Flash Player 10.0.2.54
    Adobe Reader 8.1.0
    Out of date Adobe Reader installed!
    Mozilla Firefox (3.6.6) Firefox Out of Date!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Avira Antivir avgnt.exe
    Avira Antivir avguard.exe
    Verizon Online Backup & Sharing Filesystem Watcher DigiData.FilesystemWatcher.Service.Watc her.exe
    Verizon Online Backup & Sharing Scheduler OnlineBackup.SchedulerService.exe
    Verizon Online Backup & Sharing Auto Update OnlineBackup.UpdateSystemTray.exe
    Verizon Online Backup & Sharing vewatch.exe
    ````````````````````````````````
    DNS Vulnerability Check:

    GREAT! (Not vulnerable to DNS cache poisoning)

    ``````````End of Log````````````


    Ran Hijack this, log follows:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:54:21 AM, on 8/17/2010
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v8.00 (8.00.6001.18943)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Windows\vsnp2uvc.exe
    C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files (x86)\HP\QuickPlay\QPService.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files (x86)\Java\jre6\bin\jusched.exe
    C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe
    C:\Program Files (x86)\Internet Content Filter\mfp.exe
    C:\Program Files (x86)\Verizon\VSP\VerizonServicepoint.exe
    C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
    C:\Program Files (x86)\Common Files\Motive\McciContextHookShim.exe
    C:\Program Files (x86)\Verizon\VSP\VerizonServicepointComHandler.exe
    C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\SysWOW64\DllHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0unattached&bm=ho_central
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (filesize 75128 bytes, MD5 5CF6190CD875DA6B35256FEE573E7908)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (filesize 278192 bytes, MD5 389947CAD1A9C504DF6285AA1E7BE6F1)
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (filesize 349576 bytes, MD5 C0E4908B752509D795E79496530BFD69)
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (filesize 814648 bytes, MD5 42CB4EE0B0FC259C8AD20B460FA7D72A)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (filesize 41760 bytes, MD5 1E57B1A44C7DFFA1C38534279C14B3CE)
    O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (filesize 349576 bytes, MD5 C0E4908B752509D795E79496530BFD69)
    O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll (filesize 177504 bytes, MD5 7D5759CDDC966369EF460B552DB465BD)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (filesize 349576 bytes, MD5 C0E4908B752509D795E79496530BFD69)
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (filesize 278192 bytes, MD5 389947CAD1A9C504DF6285AA1E7BE6F1)
    O4 - HKLM\..\Run: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe" (filesize 468264 bytes, MD5 F08A76C5E56BDB6F98F41BD22A4692E1)
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles(x86)%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0" (filesize 218408 bytes, MD5 D2A93F854393C7D3BA09893F1EA264CD)
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exeC:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe" (filesize 40048 bytes, MD5 66D4456C920E21BD2188F8CC33680DF5)
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exeC:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exeC:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exeC:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exec:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" (filesize 236016 bytes, MD5 B1FB1C4396A9D0FB074D8E90369F5129)
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min (filesize 209153 bytes, MD5 29680A793F690EEF4AAA68479D2A6DF8)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe" (filesize 149280 bytes, MD5 90E0F7FDCAC66FB50C1CE1A1C7396642)
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exeC:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin (filesize 611712 bytes, MD5 E43A851F7B12DE589424D6C656155CFC)
    O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" (filesize 38768 bytes, MD5 81A990CA9644D2CCB9D903183D9A0F58)
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" (filesize 640376 bytes, MD5 A1ED44DABCD252B95CD09487B65F734C)
    O4 - HKLM\..\Run: [Adobe_ID0ENQBO] C:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXEC:\PROGRA~2\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime (filesize 417792 bytes, MD5 55D7A219AD8D0DB8980528944152A6FD)
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" (filesize 141608 bytes, MD5 8DC7685764B22DB97891012026FA7ED1)
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" (filesize 935288 bytes, MD5 3103FE27C967675B019E880AA6DA3D6D)
    O4 - HKLM\..\Run: [VERIZONDM] "C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe" /P VERIZONDM (filesize 206120 bytes, MD5 0153701206D2CF9A43F88B40AF1FBC22)
    O4 - HKLM\..\Run: [Online Backup Auto Update] "C:\Program Files (x86)\Verizon\Online Backup & Sharing\Auto Update\OnlineBackup.UpdateSystemTray.exe" (filesize 233472 bytes, MD5 D5420C4E17E34BE1A30858D697B38492)
    O4 - HKLM\..\Run: [Vault Explorer Cache Watcher] "C:\Program Files (x86)\Verizon\Online Backup & Sharing\vewatch.exe" (filesize 28672 bytes, MD5 870DFA3469F6C9A0C6EE0C13D062B692)
    O4 - HKLM\..\Run: [ICF] "C:\Program Files (x86)\Internet Content Filter\mfp.exe" -noact (filesize 1275408 bytes, MD5 91443B66F7492A4F66D456522120A132)
    O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files (x86)\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN (filesize 4269296 bytes, MD5 BC5F401099CEA5F55879E0F24E5584B4)
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (filesize 1555968 bytes, MD5 5213EB5405A886A9B4FED6724C392C07)
    O4 - HKCU\..\Run: [lightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (filesize 455968 bytes, MD5 3C62EAE05B76BA809FA1DE327922E846)
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exeC:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (filesize 39408 bytes, MD5 5D61BE7DB55B026A5D61A3EED09D0EAD)
    O4 - HKCU\..\Run: [rjyqbvyn] C:\Users\Lisa\AppData\Local\tconxtygj\yqidoqdshdw.exeC:\Users\Lisa\AppData\Local\tconxtygj\yqidoqdshdw.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exeC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll (filesize 152928 bytes, MD5 A1230D9DFAEF1219CDA8E4FA122F106A)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (filesize 39464 bytes, MD5 AEF204E782BFA2C8448CB43A58960744)
    O10 - Unknown file in Winsock LSP: c:\windows\syswow64\icf.dll
    O10 - Unknown file in Winsock LSP: c:\windows\syswow64\icf.dll
    O10 - Unknown file in Winsock LSP: c:\windows\syswow64\icf.dll
    O10 - Unknown file in Winsock LSP: c:\windows\syswow64\icf.dll
    O10 - Unknown file in Winsock LSP: c:\windows\syswow64\icf.dll
    O13 - Gopher Prefix:
    O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/62.12/uploader2.cab
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
    O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (filesize 1959208 bytes, MD5 1E79B48BC50B99FDC0066860BCEFBC23)
    O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXEC:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeC:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exeC:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exeC:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exeC:\Program Files (x86)\Bonjour\mDNSResponder.exe
    O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exeC:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
    O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
    O23 - Service: Filesystem Watcher (FilesystemWatcher) - DigiData Corp. - C:\Program Files (x86)\Verizon\Online Backup & Sharing\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exeC:\Program Files (x86)\Verizon\Online Backup & Sharing\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeC:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exeC:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
    O23 - Service: Family Protection Update Service (fpUpdateSvc) - McAfee, Inc. - C:\Program Files (x86)\Internet Content Filter\UpdateService.exeC:\Program Files (x86)\Internet Content Filter\UpdateService.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exeC:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exeC:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exec:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exeC:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exeC:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeC:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeC:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exeC:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files (x86)\Common Files\Motive\McciCMService.exeC:\Program Files (x86)\Common Files\Motive\McciCMService.exe
    O23 - Service: McciCMService64 - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exeC:\Program Files\Common Files\Motive\McciCMService.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
    O23 - Service: Online Backup Scheduler (OnlineBackupSchedulerService) - Unknown owner - C:\Program Files (x86)\Verizon\Online Backup & Sharing\Scheduler\OnlineBackup.SchedulerService.exeC:\Program Files (x86)\Verizon\Online Backup & Sharing\Scheduler\OnlineBackup.SchedulerService.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exeC:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
    O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exeC:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exeC:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exeC:\Program Files (x86)\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
    O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exeC:\Program Files (x86)\Roxio\Digital Home 9\RoxioUpnpService9.exe
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exeC:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exeC:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exeC:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: ServicepointService - Radialpoint Inc. - C:\Program Files (x86)\Verizon\VSP\ServicepointService.exeC:\Program Files (x86)\Verizon\VSP\ServicepointService.exe
    O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: SupportSoft Sprocket Service (verizondm) (sprtsvc_verizondm) - SupportSoft, Inc. - C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exeC:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe
    O23 - Service: SupportSoft Repair Service (verizondm) (tgsrvc_verizondm) - SupportSoft, Inc. - C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exeC:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

    --
    End of file - 22393 bytes


    OK, now I am very proud of myself - haha
    Quote

    OK, now I am very proud of myself - haha
    Good job well done!

    Update Your Java (JRE)

    Old versions of Java have vulnerabilities that malware can use to infect your system.

    First Verify your Java Version

    If there are any other version(s) installed then update now.

    Get the new version (if needed)

    If your version is out of date install the newest version of the Sun Java Runtime Environment.

    Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Be sure to close ALL open web browsers before starting the installation.

    Remove any old versions

    1. Download JavaRa and unzip the file to your Desktop.
    2. Open JavaRA.exe and choose Remove Older Versions
    3. Once complete exit JavaRA.
    4. Run CCleaner.

    Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.

    *************************************

    Please download the newest version of Adobe Acrobat Reader from Adobe.com

    Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs.
    Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

    Once old versions are gone, please install the newest version.

    ***************************************

    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O4 - HKCU\..\Run: [rjyqbvyn]


    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ****************************************

    Download ComboFix by sUBs from one of the below links.

    Important! You MUST save ComboFix to your desktop

    link # 1
    Link # 2

    Temporarily disable your Anti-virus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click on ComboFix.exe & follow the prompts.

    Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)

    Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

    When the scan completes it will open a text window.

    Post the contents of that log in your next reply.

    Remember to re-enable your Anti-virus and Antispyware protection when ComboFix is complete.I did everything, except ComboFix will not install is pops u[ an Error - Win32 only.

    I have 64 bit, Vista.Quote
    I have 64 bit, Vista.
    Oops. 64 bit machines severely limits the number of tools I can use to clean your computer. Sorry.

    Download OTL to your Desktop
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Under the Custom Scan box paste this in
    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %SYSTEMDRIVE%\*.exe
    %systemroot%\*. /mp /s
    c:\$recycle.bin\*.* /s
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    nvstor32.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    explorer.exe
    svchost.exe
    userinit.exe
    qmgr.dll
    ws2_32.dll
    proquota.exe
    imm32.dll
    kernel32.dll
    ndis.sys
    autochk.exe
    spoolsv.exe
    xmlprov.dll
    ntmssvc.dll
    mswsock.dll
    Beep.SYS
    ntfs.sys
    termsrv.dll
    sfcfiles.dll
    st3shark.sys
    ahcix86.sys
    srsvc.dll
    nvrd32.sys
    /md5stop
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles

    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
      • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
      • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time
    ok, sorry I've been delinquent! The computer at this point seems to be working ok but not sure the problem is 100% solved (ya never know right??).

    Here is the OTL log:

    OTL logfile created on: 8/22/2010 1:14:00 PM - Run 1
    OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Lisa\Desktop
    64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18943)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 52.00% Memory free
    8.00 Grb Paging File | 6.00 Gb Available in Paging File | 73.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 219.91 Gb Total Space | 68.89 Gb Free Space | 31.32% Space Free | Partition Type: NTFS
    Drive D: | 12.97 Gb Total Space | 2.43 Gb Free Space | 18.77% Space Free | Partition Type: NTFS
    Drive E: | 7.24 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: LISA-LAPTOP
    Current User Name: Lisa
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Include 64bit Scans
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Processes (SafeList) ==========

    PRC - [2010/08/22 13:10:52 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Lisa\Desktop\OTL.exe
    PRC - [2010/06/19 12:36:46 | 000,640,440 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
    PRC - [2010/06/11 09:37:26 | 000,185,640 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe
    PRC - [2010/06/11 09:37:24 | 000,206,120 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe
    PRC - [2010/06/11 09:37:10 | 000,206,120 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe
    PRC - [2010/05/14 11:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    PRC - [2010/04/22 10:25:38 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    PRC - [2010/03/17 16:53:24 | 000,207,872 | ---- | M] (Alcatel-Lucent) -- C:\Program Files (x86)\Common Files\Motive\McciContextHookShim.exe
    PRC - [2010/02/12 11:02:08 | 000,240,992 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe
    PRC - [2010/02/09 17:07:22 | 001,275,408 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\Internet Content Filter\mfp.exe
    PRC - [2010/01/26 20:58:38 | 000,256,280 | R--- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10e.exe
    PRC - [2009/11/18 10:50:40 | 000,668,912 | ---- | M] (Radialpoint Inc.) -- C:\Program Files (x86)\Verizon\VSP\ServicepointService.exe
    PRC - [2009/11/18 10:50:32 | 000,468,208 | ---- | M] (Radialpoint Inc.) -- C:\Program Files (x86)\Verizon\VSP\VerizonServicepointComHandler.exe
    PRC - [2009/11/18 10:50:30 | 004,269,296 | ---- | M] (Verizon) -- C:\Program Files (x86)\Verizon\VSP\VerizonServicepoint.exe
    PRC - [2009/08/05 22:11:05 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
    PRC - [2009/05/13 16:48:22 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
    PRC - [2009/04/11 02:28:15 | 000,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
    PRC - [2009/03/02 13:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
    PRC - [2008/08/01 20:10:54 | 000,675,840 | ---- | M] (Sonix) -- C:\Windows\vsnp2uvc.exe
    PRC - [2008/04/15 18:54:42 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    PRC - [2008/04/15 18:54:40 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe


    ========== Modules (SafeList) ==========

    MOD - [2010/08/22 13:10:52 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Lisa\Desktop\OTL.exe
    MOD - [2008/01/20 22:50:01 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx


    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - [2010/06/29 13:49:27 | 000,128,752 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
    SRV:64bit: - [2009/10/28 10:05:15 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
    SRV:64bit: - [2009/08/18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
    SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV - [2010/06/11 09:37:26 | 000,185,640 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe -- (tgsrvc_verizondm) SupportSoft Repair Service (verizondm)
    SRV - [2010/06/11 09:37:24 | 000,206,120 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe -- (sprtsvc_verizondm) SupportSoft Sprocket Service (verizondm)
    SRV - [2010/05/14 11:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
    SRV - [2010/03/18 14:27:14 | 001,020,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
    SRV - [2010/03/18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
    SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/02/10 19:11:00 | 000,020,480 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Verizon\Online Backup & Sharing\Scheduler\OnlineBackup.SchedulerService.exe -- (OnlineBackupSchedulerService)
    SRV - [2010/02/09 17:13:32 | 000,275,456 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\Internet Content Filter\UpdateService.exe -- (fpUpdateSvc)
    SRV - [2010/02/02 20:02:52 | 000,024,576 | ---- | M] (DigiData Corp.) [Auto | Running] -- C:\Program Files (x86)\Verizon\Online Backup & Sharing\Filesystem Watcher\DigiData.FilesystemWatcher.Service.Watcher.exe -- (FilesystemWatcher)
    SRV - [2009/11/18 10:50:40 | 000,668,912 | ---- | M] (Radialpoint Inc.) [Auto | Running] -- C:\Program Files (x86)\Verizon\VSP\ServicepointService.exe -- (ServicepointService)
    SRV - [2009/10/28 10:02:52 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
    SRV - [2009/08/05 22:11:05 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
    SRV - [2009/05/13 16:48:22 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
    SRV - [2008/08/15 05:46:20 | 000,284,016 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe -- (Adobe Version Cue CS4)
    SRV - [2008/04/15 18:54:42 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
    SRV - [2007/03/05 13:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\SymIM.sys -- (SymIMMP)
    DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\SymIM.sys -- (SymIM)
    DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
    DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
    DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\ipinip.sys -- (IpInIp)
    DRV:64bit: - [2009/12/07 10:30:10 | 000,074,880 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\DRIVERS\avgntflt.sys -- (avgntflt)
    DRV:64bit: - [2009/09/30 20:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
    DRV:64bit: - [2009/08/28 20:42:52 | 000,049,152 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2009/06/09 17:16:06 | 003,557,376 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
    DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009/04/11 01:03:32 | 000,111,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\sdbus.sys -- (sdbus)
    DRV:64bit: - [2008/07/07 13:23:56 | 000,025,600 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\NwUsbCdFil64.sys -- (NWUSBCDFIL64)
    DRV:64bit: - [2008/06/02 17:28:52 | 000,247,808 | ---- | M] (Novatel Wireless Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\NWADIenum.sys -- (NWADI)
    DRV:64bit: - [2008/05/09 12:08:40 | 000,213,120 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwusbser2.sys -- (NWUSBPort2)
    DRV:64bit: - [2008/05/09 12:08:40 | 000,213,120 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwusbser.sys -- (NWUSBPort)
    DRV:64bit: - [2008/05/09 12:08:40 | 000,213,120 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwusbmdm.sys -- (NWUSBModem)
    DRV:64bit: - [2008/04/15 18:54:16 | 000,388,120 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\iaStor.sys -- (iaStor)
    DRV:64bit: - [2008/01/20 22:49:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RootMdm.sys -- (ROOTMODEM)
    DRV:64bit: - [2008/01/20 22:46:57 | 001,523,712 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS -- (HSF_DPV)
    DRV:64bit: - [2008/01/20 22:46:57 | 000,724,480 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS -- (winachsf)
    DRV:64bit: - [2008/01/20 22:46:57 | 000,286,720 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS -- (HSFHWAZL)
    DRV:64bit: - [2008/01/18 07:31:30 | 000,320,560 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\SynTP.sys -- (SynTP)
    DRV:64bit: - [2007/09/17 19:17:46 | 000,135,680 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169)
    DRV:64bit: - [2007/07/11 13:30:34 | 000,009,088 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\HpqRemHid.sys -- (HpqRemHid)
    DRV:64bit: - [2007/06/28 11:09:56 | 003,148,288 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\NETw4v64.sys -- (NETw4v64) Intel(R)
    DRV:64bit: - [2007/06/18 20:13:12 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys -- (HpqKbFiltr)
    DRV:64bit: - [2007/05/31 14:39:32 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RimUsb_AMD64.sys -- (RimUsb)
    DRV:64bit: - [2007/05/01 04:00:00 | 000,052,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\PxHlpa64.sys -- (PxHlpa64)
    DRV:64bit: - [2007/03/26 22:48:24 | 000,055,808 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\rixdpx64.sys -- (rismxdp)
    DRV:64bit: - [2007/03/19 15:09:36 | 000,055,808 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\rimmpx64.sys -- (rimmptsk)
    DRV:64bit: - [2007/02/27 19:10:38 | 000,053,760 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\rimspx64.sys -- (rimsptsk)
    DRV:64bit: - [2007/01/18 16:10:22 | 000,030,336 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\RimSerial_AMD64.sys -- (RimVSerPort)
    DRV:64bit: - [2007/01/17 09:48:30 | 001,455,616 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\smserial.sys -- (smserial)
    DRV:64bit: - [2006/10/09 22:09:03 | 000,742,696 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nvm60x64.sys -- (NVENETFD)
    DRV:64bit: - [2006/10/06 22:13:22 | 000,550,912 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\bcmwl664.sys -- (BCM43XV)
    DRV:64bit: - [2006/09/18 17:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\Wbem\ntfs.mof -- (Ntfs)
    DRV - [2010/03/17 16:53:38 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Motive\MREMP50.sys -- (MREMP50)
    DRV - [2010/03/17 16:53:22 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Motive\MRESP50.sys -- (MRESP50)
    DRV - [2009/03/20 20:03:36 | 000,043,032 | ---- | M] (Smith Micro Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Verizon Wireless\VZAccess Manager\SMSIVZAM5X64.sys -- (SMSIVZAM5X64)
    DRV - [2008/08/14 07:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0unattached&bm=ho_central
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&bw=fiber&cd=7.0unattached&bm=ho_central"
    FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
    FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546


    FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/08/20 03:03:48 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/16 22:44:40 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/19 22:19:51 | 000,000,000 | ---D | M]

    [2008/08/29 16:19:26 | 000,000,000 | ---D | M] -- C:\Users\Lisa\AppData\Roaming\Mozilla\Extensions
    [2010/08/16 21:10:08 | 000,000,000 | ---D | M] -- C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\extensions
    [2009/09/03 12:31:02 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    [2009/09/24 21:08:55 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\wo7p8zwu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    [2010/08/18 22:12:34 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2010/08/18 22:12:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
    [2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

    O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
    O1 - Hosts: 127.0.0.1 localhost
    O1 - Hosts: ::1 localhost
    O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
    O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
    O2 - BHO: (MSN Toolbar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN Toolbar\Platform\4.0.0401.0\npwinext.dll (Microsoft Corporation)
    O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
    O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\Program Files (x86)\MSN Toolbar\Platform\4.0.0401.0\npwinext.dll (Microsoft Corporation)
    O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O4:64bit: - HKLM..\Run: [HP Health Check Scheduler] File not found
    O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
    O4:64bit: - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
    O4:64bit: - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix)
    O4:64bit: - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
    O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
    O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [Adobe_ID0ENQBO] C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4Tray.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
    O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
    O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
    O4 - HKLM..\Run: [ICF] C:\Program Files (x86)\Internet Content Filter\mfp.exe (McAfee, Inc.)
    O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [MSN Toolbar] c:\Program Files (x86)\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe (Microsoft Corp.)
    O4 - HKLM..\Run: [Online Backup Auto Update] C:\Program Files (x86)\Verizon\Online Backup & Sharing\Auto Update\OnlineBackup.UpdateSystemTray.exe ()
    O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
    O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
    O4 - HKLM..\Run: [Vault Explorer Cache Watcher] C:\Program Files (x86)\Verizon\Online Backup & Sharing\vewatch.exe (DigiData Corp.)
    O4 - HKLM..\Run: [VERIZONDM] C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe (SupportSoft, Inc.)
    O4 - HKLM..\Run: [VerizonServicepoint.exe] C:\Program Files (x86)\Verizon\VSP\VerizonServicepoint.exe (Verizon)
    O4 - HKCU..\Run: [AdobeBridge] File not found
    O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
    O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8:64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
    O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
    O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files (x86)\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\SYSWOW64\icf.dll (McAfee, Inc.)
    O13 - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com/s/v/62.12/uploader2.cab (UploadListView Class)
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab (DLM Control)
    O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab (Verizon Wireless Media Upload)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
    O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 71.250.0.12
    O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
    O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\HPSplash.jpg
    O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\HPSplash.jpg
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2005/09/11 11:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
    O33 - MountPoints2\{0d1e4c97-6bbf-11de-818e-001e68767086}\Shell - "" = AutoRun
    O33 - MountPoints2\{60aed025-a83a-11de-9cc3-001e68767086}\Shell - "" = AutoRun
    O33 - MountPoints2\{b9b5e17e-5c46-11de-8b9b-001e68767086}\Shell - "" = AutoRun
    O33 - MountPoints2\{dc3f7eeb-ef0c-11de-8248-001e68767086}\Shell - "" = AutoRun
    O33 - MountPoints2\{dc3f7f27-ef0c-11de-8248-001e68767086}\Shell - "" = AutoRun
    O33 - MountPoints2\{dc3f7f27-ef0c-11de-8248-001e68767086}\Shell\AutoRun\command - "" = F:\VZAccess_Manager.exe -- File not found
    O33 - MountPoints2\F\Shell - "" = AutoRun
    O33 - MountPoints2\G\Shell - "" = AutoRun
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*



    SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
    SafeBootMin:64bit: AppMgmt - Service
    SafeBootMin:64bit: Base - Driver Group
    SafeBootMin:64bit: Boot Bus Extender - Driver Group
    SafeBootMin:64bit: Boot file system - Driver Group
    SafeBootMin:64bit: File system - Driver Group
    SafeBootMin:64bit: Filter - Driver Group
    SafeBootMin:64bit: HelpSvc - Service
    SafeBootMin:64bit: mcmscsvc - Service
    SafeBootMin:64bit: MCODS - Service
    SafeBootMin:64bit: PCI Configuration - Driver Group
    SafeBootMin:64bit: PEVSystemStart - Service
    SafeBootMin:64bit: PNP Filter - Driver Group
    SafeBootMin:64bit: Primary disk - Driver Group
    SafeBootMin:64bit: procexp90.Sys - Driver
    SafeBootMin:64bit: sacsvr - Service
    SafeBootMin:64bit: SCSI Class - Driver Group
    SafeBootMin:64bit: System Bus Extender - Driver Group
    SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
    SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
    SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
    SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
    SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
    SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
    SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
    SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
    SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
    SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
    SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
    SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
    SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
    SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
    SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
    SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
    SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
    SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
    SafeBootMin: AppMgmt - Service
    SafeBootMin: Base - Driver Group
    SafeBootMin: Boot Bus Extender - Driver Group
    SafeBootMin: Boot file system - Driver Group
    SafeBootMin: File system - Driver Group
    SafeBootMin: Filter - Driver Group
    SafeBootMin: HelpSvc - Service
    SafeBootMin: mcmscsvc - Service
    SafeBootMin: MCODS - Service
    SafeBootMin: PCI Configuration - Driver Group
    SafeBootMin: PEVSystemStart - Service
    SafeBootMin: PNP Filter - Driver Group
    SafeBootMin: Primary disk - Driver Group
    SafeBootMin: procexp90.Sys - Driver
    SafeBootMin: sacsvr - Service
    SafeBootMin: SCSI Class - Driver Group
    SafeBootMin: System Bus Extender - Driver Group
    SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
    SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
    SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
    SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
    SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
    SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
    SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
    SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
    SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
    SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
    SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
    SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
    SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
    SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
    SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
    SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
    SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

    SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
    SafeBootNet:64bit: AppMgmt - Service
    SafeBootNet:64bit: Base - Driver Group
    SafeBootNet:64bit: Boot Bus Extender - Driver Group
    SafeBootNet:64bit: Boot file system - Driver Group
    SafeBootNet:64bit: File system - Driver Group
    SafeBootNet:64bit: Filter - Driver Group
    SafeBootNet:64bit: HelpSvc - Service
    SafeBootNet:64bit: mcmscsvc - Service
    SafeBootNet:64bit: MCODS - Service
    SafeBootNet:64bit: Messenger - Service
    SafeBootNet:64bit: MpfService - Service
    SafeBootNet:64bit: NDIS Wrapper - Driver Group
    SafeBootNet:64bit: NetBIOSGroup - Driver Group
    SafeBootNet:64bit: NetDDEGroup - Driver Group
    SafeBootNet:64bit: Network - Driver Group
    SafeBootNet:64bit: NetworkProvider - Driver Group
    SafeBootNet:64bit: PCI Configuration - Driver Group
    SafeBootNet:64bit: PEVSystemStart - Service
    SafeBootNet:64bit: PNP Filter - Driver Group
    SafeBootNet:64bit: PNP_TDI - Driver Group
    SafeBootNet:64bit: Primary disk - Driver Group
    SafeBootNet:64bit: procexp90.Sys - Driver
    SafeBootNet:64bit: rdsessmgr - Service
    SafeBootNet:64bit: sacsvr - Service
    SafeBootNet:64bit: SCSI Class - Driver Group
    SafeBootNet:64bit: Streams Drivers - Driver Group
    SafeBootNet:64bit: System Bus Extender - Driver Group
    SafeBootNet:64bit: TDI - Driver Group
    SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
    SafeBootNet:64bit: WudfPf - Driver
    SafeBootNet:64bit: WudfUsbccidDriver - Driver
    SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
    SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
    SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
    SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
    SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
    SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
    SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
    SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
    SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
    SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
    SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
    SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
    SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
    SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
    SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
    SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart CARD readers
    SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
    SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
    SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
    SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
    SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
    SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
    SafeBootNet: AppMgmt - Service
    SafeBootNet: Base - Driver Group
    SafeBootNet: Boot Bus Extender - Driver Group
    SafeBootNet: Boot file system - Driver Group
    SafeBootNet: File system - Driver Group
    SafeBootNet: Filter - Driver Group
    SafeBootNet: HelpSvc - Service
    SafeBootNet: mcmscsvc - Service
    SafeBootNet: MCODS - Service
    SafeBootNet: Messenger - Service
    SafeBootNet: MpfService - Service
    SafeBootNet: NDIS Wrapper - Driver Group
    SafeBootNet: NetBIOSGroup - Driver Group
    SafeBootNet: NetDDEGroup - Driver Group
    SafeBootNet: Network - Driver Group
    SafeBootNet: NetworkProvider - Driver Group
    SafeBootNet: PCI Configuration - Driver Group
    SafeBootNet: PEVSystemStart - Service
    SafeBootNet: PNP Filter - Driver Group
    SafeBootNet: PNP_TDI - Driver Group
    SafeBootNet: Primary disk - Driver Group
    SafeBootNet: procexp90.Sys - Driver
    SafeBootNet: rdsessmgr - Service
    SafeBootNet: sacsvr - Service
    SafeBootNet: SCSI Class - Driver Group
    SafeBootNet: Streams Drivers - Driver Group
    SafeBootNet: System Bus Extender - Driver Group
    SafeBootNet: TDI - Driver Group
    SafeBootNet: WudfPf - Driver
    SafeBootNet: WudfUsbccidDriver - Driver
    SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
    SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
    SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
    SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
    SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
    SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
    SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
    SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
    SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
    SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
    SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
    SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
    SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
    SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
    SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
    SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
    SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
    SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
    SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
    SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
    SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
    SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

    ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
    ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
    ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
    ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
    ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
    ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
    ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
    ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
    ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
    ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
    ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
    ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
    ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
    ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
    ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
    ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
    ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
    ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
    ActiveX:64bit: {96BFD4F7-F575-5C17-05D3-688924F854EB} - Browser Customizations
    ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
    ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
    ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
    ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
    ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
    ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
    ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
    ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
    ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
    ActiveX: {03F998B2-0E00-11D3-A498-00104B6EB52E} - Viewpoint Media Player
    ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
    ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
    ActiveX: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - Viewpoint Media Player
    ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player
    ActiveX: {25E8E74C-C20D-210C-870C-510830400FBC} - Microsoft Windows Media Player
    ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
    ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
    ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
    ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
    ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
    ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
    ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
    ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
    ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
    ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
    ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
    ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
    ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
    ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
    ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
    ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
    ActiveX: {B466C5AD-B9F4-24CE-66A7-2AF39C67E7A7} - Microsoft VM
    ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
    ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
    ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
    ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
    ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
    ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
    ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
    ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP

    Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: vidc.3IV2 - C:\Windows\SysWow64\3ivxVfWCodec.dll (3ivx Technologies Pty. Ltd.)
    Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

    ========== Files/Folders - Created Within 90 Days ==========

    [2010/08/22 13:10:48 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Lisa\Desktop\OTL.exe
    [2010/08/20 03:24:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Portable Devices
    [2010/08/20 03:24:28 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
    [2010/08/20 03:03:46 | 000,000,000 | -HSD | C] -- C:\Config.Msi
    [2010/08/19 11:00:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\vi-VN
    [2010/08/19 11:00:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\eu-ES
    [2010/08/19 11:00:37 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\eu-ES
    [2010/08/19 11:00:37 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ca-ES
    [2010/08/19 11:00:37 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ca-ES
    [2010/08/19 11:00:33 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\vi-VN
    [2010/08/19 10:31:01 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\virus stuff
    [2010/08/18 22:37:52 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\TURTLE template 8610-446 *censored*
    [2010/08/18 22:32:10 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW
    [2010/08/18 22:23:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
    [2010/08/18 22:23:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSN Toolbar
    [2010/08/18 22:17:02 | 000,000,000 | ---D | C] -- C:\Windows\Sun
    [2010/08/18 22:14:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSN Toolbar Installer
    [2010/08/18 22:14:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
    [2010/08/17 10:49:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
    [2010/08/17 08:11:37 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Roaming\SUPERAntiSpyware.com
    [2010/08/17 08:11:27 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
    [2010/08/14 15:18:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner
    [2010/08/13 22:14:55 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Roaming\Malwarebytes
    [2010/08/13 22:14:43 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    [2010/08/13 22:14:41 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2010/08/13 22:14:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2010/08/13 22:14:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2010/08/13 13:47:10 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
    [2010/08/13 13:47:05 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
    [2010/08/13 09:58:32 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\INNOVATION
    [2010/08/12 23:03:56 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Local\tconxtygj
    [2010/08/12 09:38:16 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\Converted
    [2010/08/10 16:15:47 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Documents\Joe Z Banner file (3)
    [2010/08/04 20:23:07 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Documents\personal and confidential
    [2010/07/30 15:33:44 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\File Folders USB Files
    [2010/07/30 15:15:18 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Documents\Resumes
    [2010/07/30 15:14:42 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Documents\Personal
    [2010/07/27 11:57:24 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\SOE documents
    [2010/07/26 09:24:45 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Roaming\Motive
    [2010/07/26 09:24:42 | 000,000,000 | ---D | C] -- C:\Program Files\Verizon
    [2010/07/22 10:33:07 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\Verizon
    [2010/07/21 18:53:39 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Roaming\Verizon
    [2010/07/21 18:53:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Radialpoint
    [2010/07/21 18:53:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Verizon
    [2010/07/21 18:53:28 | 000,000,000 | ---D | C] -- C:\Windows\bin
    [2010/07/21 18:52:45 | 000,409,928 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\seinst.dll
    [2010/07/21 18:52:45 | 000,378,696 | ---- | C] (McAfee, Inc.) -- C:\Windows\sediag.exe
    [2010/07/21 18:52:45 | 000,318,280 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysWow64\seinst.dll
    [2010/07/21 18:52:45 | 000,299,024 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysWow64\ICF.dll
    [2010/07/21 18:52:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Internet Content Filter
    [2010/07/21 18:52:42 | 000,335,376 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\ICF.dll
    [2010/07/21 18:51:45 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Local\Citrix
    [2010/07/21 18:50:44 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Local\Apps
    [2010/07/21 18:50:41 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Local\Deployment
    [2010/07/21 18:47:14 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
    [2010/07/21 18:46:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\verizon_broad
    [2010/07/21 18:46:54 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Roaming\DigiData
    [2010/07/21 18:46:26 | 000,000,000 | ---D | C] -- C:\ProgramData\DigiData
    [2010/07/21 18:46:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Verizon Online Backup
    [2010/07/21 18:44:21 | 000,000,000 | ---D | C] -- C:\Windows\FIOS
    [2010/07/21 18:13:48 | 000,000,000 | ---D | C] -- C:\Users\Lisa\AppData\Local\SupportSoft
    [2010/07/21 18:13:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VERIZONDM
    [2010/07/21 18:13:30 | 000,000,000 | ---D | C] -- C:\ProgramData\SupportSoft
    [2010/07/21 18:13:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SupportSoft
    [2010/07/21 17:19:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Motive
    [2010/07/21 17:19:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Motive
    [2010/07/21 17:19:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Motive
    [2010/07/21 17:15:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Verizon
    [2010/07/14 12:49:07 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Documents\Aurobindo Generics Support Catalogue and Monograph (2)
    [2010/06/15 09:51:36 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\RE new ecard_files
    [2010/05/26 09:55:20 | 000,000,000 | ---D | C] -- C:\Users\Lisa\Desktop\Repository
    [1 C:\Users\Lisa\Desktop\*.tmp files -> C:\Users\Lisa\Desktop\*.tmp -> ]

    ========== Files - Modified Within 90 Days ==========

    [2010/08/22 13:14:08 | 004,718,592 | -HS- | M] () -- C:\Users\Lisa\NTUSER.DAT
    [2010/08/22 13:10:52 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Lisa\Desktop\OTL.exe
    [2010/08/22 12:38:35 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2010/08/22 12:38:34 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2010/08/22 12:22:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2010/08/22 10:38:50 | 000,060,096 | ---- | M] () -- C:\ProgramData\nvModes.dat
    [2010/08/22 10:38:48 | 000,060,096 | ---- | M] () -- C:\ProgramData\nvModes.001
    [2010/08/22 10:38:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2010/08/21 17:04:43 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2010/08/20 09:54:01 | 000,000,703 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
    [2010/08/20 03:35:23 | 000,703,388 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2010/08/20 03:35:23 | 000,604,502 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2010/08/20 03:35:23 | 000,104,170 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2010/08/20 03:27:37 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
    [2010/08/20 03:26:56 | 4293,320,704 | -HS- | M] () -- C:\hiberfil.sys
    [2010/08/20 03:24:03 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
    [2010/08/20 03:23:46 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
    [2010/08/20 03:23:39 | 000,524,288 | -HS- | M] () -- C:\Users\Lisa\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
    [2010/08/20 03:23:39 | 000,065,536 | -HS- | M] () -- C:\Users\Lisa\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
    [2010/08/20 03:23:34 | 001,526,296 | -H-- | M] () -- C:\Users\Lisa\AppData\Local\IconCache.db
    [2010/08/19 22:38:11 | 000,115,850 | ---- | M] () -- C:\Users\Lisa\Desktop\Innovation logo.jpg
    [2010/08/19 22:22:25 | 000,113,221 | ---- | M] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v4.jpg
    [2010/08/19 15:42:33 | 000,417,024 | ---- | M] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v3.jpg
    [2010/08/19 15:36:42 | 000,398,052 | ---- | M] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v2.jpg
    [2010/08/19 15:30:16 | 000,421,005 | ---- | M] () -- C:\Users\Lisa\Desktop\Static Innovation eCard.jpg
    [2010/08/19 11:10:19 | 003,824,136 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2010/08/18 22:43:35 | 000,013,618 | ---- | M] () -- C:\Users\Lisa\Desktop\IndiaVisaApplication_Carco_Matthew_15YL.pdf
    [2010/08/13 22:05:57 | 000,000,680 | ---- | M] () -- C:\Users\Lisa\AppData\Local\d3d9caps.dat
    [2010/08/12 23:50:14 | 000,032,256 | ---- | M] () -- C:\Users\Lisa\Desktop\WE Innovate Posters - Print Grid 8-11-10 v2.xls
    [2010/08/12 19:26:52 | 065,744,817 | ---- | M] () -- C:\Users\Lisa\Desktop\I-innovate - flower resized.psd
    [2010/08/12 13:32:40 | 090,099,109 | ---- | M] () -- C:\Users\Lisa\Desktop\I-innovate - SEEK2 resized.psd
    [2010/08/11 23:43:30 | 065,278,521 | ---- | M] () -- C:\Users\Lisa\Desktop\I-innovate mohawk mirror resized.psd
    [2010/08/11 23:05:46 | 001,706,233 | ---- | M] () -- C:\Users\Lisa\Desktop\Ryan family background.ai
    [2010/08/10 13:11:52 | 000,045,568 | ---- | M] () -- C:\Users\Lisa\Documents\calendar INNOVATION dates.doc
    [2010/08/07 13:53:42 | 000,205,312 | ---- | M] () -- C:\Users\Lisa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/08/06 20:30:58 | 000,012,455 | ---- | M] () -- C:\Users\Lisa\Documents\HBO job.docx
    [2010/08/04 20:27:56 | 000,066,982 | ---- | M] () -- C:\Users\Lisa\Desktop\Volunteer-Abroad-US[1].pdf
    [2010/08/03 18:02:19 | 000,101,858 | ---- | M] () -- C:\Users\Lisa\Desktop\Horizon billing form.pdf
    [2010/08/01 21:21:12 | 000,794,320 | ---- | M] () -- C:\Users\Lisa\Desktop\our_path_forward_2009.pdf
    [2010/07/28 18:38:26 | 000,041,404 | ---- | M] () -- C:\Users\Lisa\Documents\Engagement via SkipLevelLunchesWithTheCEO.pdf
    [2010/07/27 10:16:03 | 000,184,333 | ---- | M] () -- C:\Users\Lisa\Documents\Matt EOB 7_24_2010.pdf
    [2010/07/21 18:51:45 | 000,103,720 | ---- | M] () -- C:\Users\Lisa\GoToAssistDownloadHelper.exe
    [2010/07/21 18:51:44 | 000,000,251 | ---- | M] () -- C:\Windows\win.ini
    [2010/07/19 23:13:40 | 000,000,162 | -H-- | M] () -- C:\Users\Lisa\Desktop\~$oxicillin_WIP_7-14-2010_v2.docx
    [2010/07/14 12:49:53 | 000,000,162 | -H-- | M] () -- C:\Users\Lisa\Desktop\~$robindo Generics Support Catalogue and Monograph_Amoxicillin_WIP_7-14-2010.doc
    [2010/07/12 19:38:01 | 000,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
    [2010/07/09 18:47:42 | 001,535,488 | ---- | M] () -- C:\Users\Lisa\Desktop\Prescriber-Based Multi-Channel Non-Personal PROMOTION.ppt
    [2010/07/09 18:46:00 | 001,751,552 | ---- | M] () -- C:\Users\Lisa\Desktop\PAH Promotion Resource Optimization Proposal by ZS v3.0.ppt
    [2010/06/14 22:11:00 | 000,274,144 | ---- | M] () -- C:\Users\Lisa\AppData\Local\GDIPFONTCACHEV1.DAT
    [2010/06/11 22:16:54 | 009,830,400 | ---- | M] () -- C:\Windows\VerizonDM.msi
    [2010/06/09 10:53:29 | 000,726,349 | ---- | M] () -- C:\Users\Lisa\Documents\Kidnapped 3rd edition.pdf
    [2010/05/27 12:25:25 | 000,000,732 | ---- | M] () -- C:\Users\Lisa\AppData\Local\d3d9caps64.dat
    [1 C:\Users\Lisa\Desktop\*.tmp files -> C:\Users\Lisa\Desktop\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2010/08/20 03:24:03 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
    [2010/08/20 03:23:46 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
    [2010/08/19 22:38:09 | 000,115,850 | ---- | C] () -- C:\Users\Lisa\Desktop\Innovation logo.jpg
    [2010/08/19 15:43:44 | 000,113,221 | ---- | C] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v4.jpg
    [2010/08/19 15:42:31 | 000,417,024 | ---- | C] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v3.jpg
    [2010/08/19 15:36:40 | 000,398,052 | ---- | C] () -- C:\Users\Lisa\Desktop\Static Innovation eCard v2.jpg
    [2010/08/19 15:30:12 | 000,421,005 | ---- | C] () -- C:\Users\Lisa\Desktop\Static Innovation eCard.jpg
    [2010/08/18 22:43:26 | 000,01And here is the other.

    OTL Extras logfile created on: 8/22/2010 1:14:00 PM - Run 1
    OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Lisa\Desktop
    64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18943)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 52.00% Memory free
    8.00 Gb Paging File | 6.00 Gb Available in Paging File | 73.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 219.91 Gb Total Space | 68.89 Gb Free Space | 31.32% Space Free | Partition Type: NTFS
    Drive D: | 12.97 Gb Total Space | 2.43 Gb Free Space | 18.77% Space Free | Partition Type: NTFS
    Drive E: | 7.24 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: LISA-LAPTOP
    Current User Name: Lisa
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Include 64bit Scans
    Company Name Whitelist: On
    Skip Microsoft Files: On
    File Age = 90 Days
    Output = Standard
    Quick Scan

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

    [HKEY_CURRENT_USER\SOFTWARE\Classes\]
    .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
    batfile [open] -- "%1" %* File not found
    cmdfile [open] -- "%1" %* File not found
    comfile [open] -- "%1" %* File not found
    exefile [open] -- "%1" %* File not found
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
    htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %* File not found
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1" File not found
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S File not found
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
    htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "UacDisableNotify" = 0
    "InternetSettingsDisableNotify" = 0
    "AutoUpdateDisableNotify" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
    "VistaSp2" = 17 66 AF 91 B1 3F CB 01 [binary data]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "oobe_av" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0
    "DoNotAllowExceptions" = 0

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink -- (EarthLink, Inc.)
    "C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink -- (EarthLink, Inc.)


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{5625AE28-4574-41FB-A4DE-1CC871FAF451}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server |
    "{5E892D33-CFF7-40D7-A4E4-824AD5251D47}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
    "{8DA6F7F6-CA3D-4CEE-A3BB-DEA851E17C9F}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server |
    "{8E995BE9-4939-4533-B171-9A54CDC0979A}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server |
    "{A65378CF-363F-40F9-914E-6D89560ABDB9}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
    "{BE1FEBAB-975B-4588-80C8-932CF374934D}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{23A3F5AC-386D-4A57-81F0-8A37F0A47244}" = protocol=17 | dir=in | app=c:\program files (x86)\verizon\vsp\servicepointservice.exe |
    "{2DD8283C-15DF-4A15-BED3-964E69FFDC73}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
    "{30ABFFFF-488F-43AD-996C-B6F5EA10E71B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
    "{34276E30-E762-4410-A4FA-28E892D9CA3A}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
    "{3915D1B0-AF9B-4E63-A0D3-9C9D163407FF}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{433A6A18-2AD5-45B9-A8A0-298C95484410}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
    "{4E37717E-3A3F-4A82-874A-4FFB80A97219}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
    "{5EB2E882-0441-4BA0-9F5A-EEC7FC24553C}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
    "{68258586-E440-4BA9-B667-B490D866971E}" = protocol=6 | dir=in | app=c:\program files (x86)\verizon\vsp\servicepointservice.exe |
    "{731E5AD2-37AB-4D8F-A03F-2F1EFB658B87}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
    "{827F11E7-010A-4F53-919F-B6D5690315D6}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
    "{9CFD211B-FCB0-42A7-8F90-EC8202E47207}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
    "{A6DA8734-DE4B-4E23-9DA1-B4E0D54F7009}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
    "{AFF0FA27-3D85-4CC4-818C-D60013EC36A8}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{BF5CA861-59EE-442F-8135-907F35F3C52C}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
    "{C963D5FD-CC67-4899-A390-155F9368A8AA}" = dir=in | app=c:\program files (x86)\hp\quickplay\qp.exe |
    "{D240A1BF-E625-4A99-B27A-DDAAA7B6DB62}" = dir=in | app=c:\program files (x86)\hp\quickplay\qpservice.exe |
    "{E6EDE86C-A88D-4A2A-96B9-D03F6E5BB1A0}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
    "{EB743B3C-82ED-4D04-8BB0-18DCE5633780}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
    "{EDED57E6-1299-44B0-9492-0843BF83102F}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
    "TCP Query User{034AB4B4-31EB-47E6-9060-EFF85738A9C9}C:\program files (x86)\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
    "TCP Query User{95ED204A-58C2-47F7-A973-FF64EF774398}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
    "TCP Query User{CF882BE5-FAC7-4DA9-9718-2665997523CF}C:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
    "UDP Query User{14BC8FCA-DF02-46E0-A18F-685ADA7A066C}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
    "UDP Query User{4D1D29DC-A63E-40C8-9D5A-D359936F874B}C:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
    "UDP Query User{9268EB9E-E61C-4A3D-9742-111F7462D417}C:\program files (x86)\itunes\itunes.exe" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{11192F89-510C-4E23-A62A-D3BEA9139596}" = HP QuickTouch 1.00 C3
    "{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
    "{22ABA92B-6C1B-46D8-AC2B-C48EEAE172A9}" = VD64Inst
    "{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
    "{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
    "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
    "{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
    "{68451E5C-0A9C-4D5C-8D06-6E296242E908}" = 64 Bit HP CIO Components Installer
    "{84BC87D4-0480-4E10-B15D-1E7886D55180}" = iTunes
    "{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
    "{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
    "{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
    "{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
    "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
    "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
    "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
    "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
    "{90B5B05F-AFDA-4922-A153-45B14200BA77}" = SPBBC 64bit
    "{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
    "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
    "{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support
    "{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
    "{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64
    "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
    "{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
    "{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "HP Photosmart Essential" = HP Photosmart Essential 2.5
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "NVIDIA Drivers" = NVIDIA Drivers
    "SMSERIAL" = Motorola SM56 Data Fax Modem
    "SynTPDeinstKey" = Synaptics Pointing Device Driver

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    "{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
    "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
    "{03DEEAD2-F3B7-45BF-9006-A25D015F00D2}" = Adobe Flash Player 10 Plugin
    "{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
    "{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
    "{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
    "{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
    "{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = MSN Toolbar
    "{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
    "{082F8ABA-84D5-4837-9DFC-F365D91A07D4}" = HP Smart Web Printing
    "{08DE682A-3858-4591-9EBB-E5290E4DC3DD}" = Family Protection
    "{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
    "{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
    "{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
    "{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
    "{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
    "{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
    "{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
    "{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
    "{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
    "{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
    "{1A21FC72-611F-4ADC-B6A6-795E06D72324}" = Verizon Download Manager
    "{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
    "{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
    "{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
    "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
    "{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
    "{2656D0AB-9EA4-4C58-A117-635F3CED8B93}" = Microsoft UI Engine
    "{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java(TM) 6 Update 21
    "{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
    "{303379C9-8610-4CCF-AF37-C4BF8998C591}" = Roxio Media Manager
    "{303F7619-4E67-450F-985A-A2DF51B30AC8}" = Adobe Setup
    "{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support
    "{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
    "{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java(TM) 6 Update 4
    "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
    "{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
    "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
    "{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
    "{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
    "{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
    "{3AC54383-31D1-4907-961B-B12CBB1D0AE8}" = MobileMe Control Panel
    "{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
    "{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
    "{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
    "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
    "{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
    "{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
    "{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
    "{4D49757C-367A-4333-BDB3-68966162B14E}" = HP User Guides 0087
    "{535A4F3D-06C3-446C-A2AA-DBB71EC192B8}" = LightScribe Applications
    "{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
    "{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
    "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
    "{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
    "{5F89E4AF-07EF-48C7-9F3D-46E96E338D1D}" = Verizon Online Backup and Sharing
    "{61BEA823-ECAF-49F1-8378-A59B3B8AD247}" = Microsoft Default Manager
    "{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
    "{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
    "{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
    "{66468F4D-BC4E-470C-9093-B3B6A1BB378C}" = MSN Toolbar Platform
    "{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
    "{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
    "{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
    "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{7641FD7D-E94E-424E-A95C-0593C84DC0C0}" = VZAccess Manager
    "{76A38425-741A-415C-96CF-AAD907FAB421}" = Vz In Home Agent
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7B2ADCB5-3F3D-478A-90A9-A8C04EF82BF6}" = Mobile Broadband Generic Drivers
    "{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
    "{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
    "{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
    "{82CA0A0C-A3EC-4167-B694-909205B2EDEC}" = muvee Plugin 1.0
    "{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
    "{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
    "{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
    "{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90120000-002A-0000-1000-0000000FF1CE}_STANDARDR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-002A-0409-1000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00B0-0409-0000-0000000FF1CE}" = Microsoft Save as PDF Add-in for 2007 Microsoft Office programs
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0116-0409-1000-0000000FF1CE}_STANDARDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
    "{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
    "{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
    "{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
    "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AC388C78-2619-452C-BFBE-FABCC3194387}" = Microsoft Office Live Meeting 2007
    "{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
    "{AC76BA86-1033-F400-7760-000000000004}_934" = Adobe Acrobat 9.3.4 - CPSID_83708
    "{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
    "{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
    "{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
    "{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
    "{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
    "{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
    "{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
    "{B7F98125-4955-41E3-8A71-4CE11CE9C198}" = KODAK Gallery Upload Software
    "{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
    "{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
    "{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
    "{BC7E2C06-D255-4300-AA12-33AB54D009AC}" = Adobe Creative Suite 4 Design Standard
    "{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
    "{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
    "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
    "{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
    "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
    "{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
    "{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
    "{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
    "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
    "{D793A12F-E362-48BB-B332-1DA5E936B52D}" = BlackBerry Desktop Software 4.3
    "{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
    "{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
    "{E63E34A7-E552-412B-9E40-FD6FC5227ABA}_is1" = Uniblue RegistryBooster 2010
    "{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
    "{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
    "{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
    "{FCBE0690-CBE1-4C60-87B0-4A70A6F5434E}" = LightScribe Template Labeler
    "{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
    "3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only)
    "Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe SVG Viewer" = Adobe SVG Viewer 3.0
    "Adobe_1e3ba55b33b1e8227645fb9c82acca3" = Adobe Creative Suite 4 Design Standard
    "Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.9
    "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
    "BlackBerry_{D793A12F-E362-48BB-B332-1DA5E936B52D}" = BlackBerry Desktop Software 4.3
    "CCleaner" = CCleaner
    "com.adobe.amp.4875E02D9FB21EE389F73B8D1 702B320485DF8CE.1" = Adobe Media Player
    "com.adobe.mauby.4875E02D9FB21EE389F73B8 D1702B320485DF8CE.1" = Acrobat.com
    "Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
    "HijackThis" = HijackThis 2.0.2
    "HP Smart Web Printing" = HP Smart Web Printing
    "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
    "InstallShield_{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
    "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Mobile Broadband Generic Drivers" = Mobile Broadband Generic Drivers
    "Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
    "RadialpointClientGateway_is1" = Verizon Servicepoint 3.5.10
    "SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
    "SpiceFX for Movie Maker" = SpiceFX for Movie Maker
    "STANDARDR" = Microsoft Office Standard 2007
    "Verizon FiOS Activation_is1" = Verizon FiOS Activation
    "Verizon Help and Support" = Verizon Help and Support Tool
    "Xilisoft Video Converter Platinum" = Xilisoft Video Converter Platinum

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "ActiveTouchMeetingClient" = WebEx
    "GoToMeeting" = GoToMeeting 4.1.0.366
    "Move Media Player" = Move Media Player

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 8/17/2010 3:36:25 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 | ID = 2000
    Description = Accepted Safe Mode action : Microsoft Office Outlook.

    Error - 8/18/2010 10:57:41 PM | Computer Name = Lisa-laptop | Source = Application Error | ID = 1000
    Description = Faulting application iexplore.exe, version 8.0.6001.18943, time stamp
    0x4c25813d, faulting module Flash10e.ocx, version 10.0.45.2, time stamp 0x4b5f8faa,
    exception code 0xc0000005, fault offset 0x001582b2, process id 0x1a98, application
    start time 0x01cb3f49cd978970.

    Error - 8/19/2010 11:10:58 AM | Computer Name = Lisa-laptop | Source = WinMgmt | ID = 10
    Description =

    Error - 8/19/2010 11:14:47 AM | Computer Name = Lisa-laptop | Source = WinMgmt | ID = 10
    Description =

    Error - 8/19/2010 11:22:05 AM | Computer Name = Lisa-laptop | Source = Google Update | ID = 20
    Description =

    Error - 8/19/2010 11:29:01 AM | Computer Name = Lisa-laptop | Source = ESENT | ID = 215
    Description = WinMail (4116) WindowsMail0: The backup has been stopped because it
    was halted by the client or the connection with the client failed.

    Error - 8/19/2010 11:29:44 AM | Computer Name = Lisa-laptop | Source = SideBySide | ID = 16842830
    Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
    9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
    . A component version required by the application conflicts with another component
    version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_1509f8bef40ee4da.manifest.
    Component
    2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0.manifest.

    Error - 8/19/2010 12:29:30 PM | Computer Name = Lisa-laptop | Source = Google Update | ID = 20
    Description =

    Error - 8/19/2010 9:10:16 PM | Computer Name = Lisa-laptop | Source = Google Update | ID = 20
    Description =

    Error - 8/19/2010 9:22:11 PM | Computer Name = Lisa-laptop | Source = Google Update | ID = 20
    Description =

    [ OSession Events ]
    Error - 9/5/2009 3:17:17 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
    Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session
    lasted 3354 seconds with 1740 seconds of active time. This session ended with a
    crash.

    Error - 10/2/2009 8:30:18 AM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 533
    seconds with 420 seconds of active time. This session ended with a crash.

    Error - 11/8/2009 7:52:21 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8
    seconds with 0 seconds of active time. This session ended with a crash.

    Error - 11/8/2009 7:52:48 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
    12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 9
    seconds with 0 seconds of active time. This session ended with a crash.

    Error - 11/13/2009 12:59:38 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
    Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session
    lasted 7918 seconds with 5040 seconds of active time. This session ended with a
    crash.

    Error - 12/3/2009 10:20:04 AM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2189
    seconds with 780 seconds of active time. This session ended with a crash.

    Error - 1/12/2010 4:20:35 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 118044
    seconds with 13860 seconds of active time. This session ended with a crash.

    Error - 3/1/2010 10:54:26 AM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2409
    seconds with 600 seconds of active time. This session ended with a crash.

    Error - 4/19/2010 8:20:15 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
    12.0.6524.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 188234
    seconds with 3840 seconds of active time. This session ended with a crash.

    Error - 4/23/2010 12:58:18 PM | Computer Name = Lisa-laptop | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
    12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 97760
    seconds with 13260 seconds of active time. This session ended with a crash.

    [ System Events ]
    Error - 6/4/2009 8:59:23 PM | Computer Name = Lisa-laptop | Source = HTTP | ID = 15016
    Description =

    Error - 6/4/2009 9:00:58 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7022
    Description =

    Error - 6/4/2009 9:00:59 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7001
    Description =

    Error - 6/6/2009 5:02:04 PM | Computer Name = Lisa-laptop | Source = EventLog | ID = 6008
    Description = The previous system shutdown at 5:00:04 PM on 6/6/2009 was unexpected.

    Error - 6/6/2009 5:02:05 PM | Computer Name = Lisa-laptop | Source = HTTP | ID = 15016
    Description =

    Error - 6/6/2009 5:03:52 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7022
    Description =

    Error - 6/6/2009 5:03:53 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7001
    Description =

    Error - 6/6/2009 5:29:49 PM | Computer Name = Lisa-laptop | Source = HTTP | ID = 15016
    Description =

    Error - 6/6/2009 5:31:23 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7022
    Description =

    Error - 6/6/2009 5:31:24 PM | Computer Name = Lisa-laptop | Source = Service Control Manager | ID = 7001
    Description =


    < End of report >
    You have Viewpoint installed.

    Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

    More INFORMATION:

    * ViewMgr.exe - Useless
    * Viewpoint to Plunge Into Adware

    It is suggested to remove the program now. Go to Start > Control Panel > Add/Remove Programs - (Vista & Win7 is Programs and Features) and remove the following programs if present.

    * Viewpoint
    * Viewpoint Manager
    * Viewpoint Media Player
    * Viewpoint Toolbar
    * Viewpoint Experience Technology

    *************************************

    You can also remove these from your programs:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 4
    Java(TM) 6 Update 7
    *****************************************

    * Open OTL
    * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

    Code: [Select]:OTL

    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.

    :COMMANDS
    [resethosts]
    [purity]
    [clearrestorepoints]
    [emptytemp]
    [start explorer]

    * Click Run Fix
    * OTLI2 may ask to reboot the machine. Please do so if asked.
    * Click OK
    * A report will open. Copy and Paste that report in your next reply.

    **********************************************

    I'd like to scan your machine with ESET OnlineScan

    •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
    •Click the button.
    •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.
    •Check
    •Click the button.
    •Accept any security warnings from your browser.
    •Check
    •Push the Start button.
    •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    •When the scan completes, push
    •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    •Push the button.
    •Push
    A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

    Viewpoint is not in the list of currently installed programs (fromthe control panel).

    Is there some way it can be hidden?

    Should I continue with the next steps without uninstalling it?

    Please let me know. Thanks....
    LisaHere is the OTL log:

    All processes killed
    ========== OTL ==========
    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
    ========== COMMANDS ==========
    File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
    HOSTS file reset successfully
    Error: Unable to interpret <[clearrestorepoints]> in the current context!

    [EMPTYTEMP]

    User: Administrator

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Lisa
    ->Temp folder emptied: 12351101 bytes
    ->Temporary Internet Files folder emptied: 1547608380 bytes
    ->Java cache emptied: 80336527 bytes
    ->FireFox cache emptied: 36530560 bytes
    ->Flash cache emptied: 202717 bytes

    User: Public

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 52115250 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 17307307 bytes
    %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 7620233 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
    RecycleBin emptied: 816013 bytes

    Total Files Cleaned = 1,674.00 mb


    OTL by OldTimer - Version 3.2.10.0 log created on 08222010_233947

    Files\Folders moved on Reboot...
    File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\hover[6].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\ifr[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\ifr[2].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\ifr[3].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\index[5].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\msnbc_msn_com[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N7IDM4YU\wrap-widget[2].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\5731[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\7454-43775-2060-322[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\huffingtonpost_com[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\ifr[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\ifr[2].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\ifr[3].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\ifr[4].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\ig[1].txt not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\mailhome[2].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\pid=NBCFC1_A[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GA2P6UL0\xd_proxy[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\1234569222[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\all[1].html not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\bind[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\google_ads_iframe_loader[1].html not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\hips=1;sex=1;sex-advice=1;sexuality=1;women=1;global=1;cap_12=n;qcs=D;;load_mode=inline;page_type=bpage;pos=leaderboard_top;sz=728x90;tile=1;ord=7841259748[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\ifr[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\ifr[2].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\ifr[3].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\mole[6].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B0OZU93S\rpc_relay[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\01[2].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\AdDisplayTrackerServlet[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\flash[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\flash[2].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\freq[1].html not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\ifr[1].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\notifierclient[2].htm not found!
    File\Folder C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4I0ECJGQ\SetGridCookie[1].htm not found!
    C:\Users\Lisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

    Registry entries deleted on Reboot...
    ESET LOG:
    C:\SWSetup\AOLIMS\setup.exeprobably a variant of Win32/Agent.HZHBURL trojancleaned by deleting - quarantined
    C:\Users\Lisa\AppData\Local\Temp\jar_cache8398643626540035938.tmpa variant of Java/TrojanDownloader.Agent.NAC trojandeleted - quarantined
    Quote
    Viewpoint is not in the list of currently installed programs (fromthe control panel).

    Is there some way it can be hidden?
    Please try this to see if you can find it there.

    Delete An Uninstall Entry

    •Start HijackThis

    •Click on the Open the Misc Tools section

    •Click on the Open Uninstall Manager button.

    •Highlight the entry you want to remove.
    •Click Delete this entry
    313.

    Solve : programs close for no reason. :S :( Need help!?

    Answer» ESET Online Scan

    Please run a free online scan with the ESET Online Scanner
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • When asked, allow the ActiveX control to install
    • Click Start
    • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, you may close the window
    • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    • Copy and paste that log as a reply to this topic
    [emailprotected] as CAB hook log:
    OnlineScanner.ocx - registred OK
    # version=7
    # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
    # OnlineScanner.ocx=1.0.0.6211
    # api_version=3.0.2
    # EOSSerial=4cc7483854806345a03a64acb250f7bd
    # end=finished
    # remove_checked=true
    # archives_checked=false
    # unwanted_checked=true
    # unsafe_checked=false
    # antistealth_checked=true
    # utc_time=2010-08-07 02:38:48
    # local_time=2010-08-07 08:08:48 (+0530, India Standard Time)
    # country="United States"
    # lang=1033
    # osver=5.1.2600 NT Service Pack 3
    # compatibility_mode=512 16777215 100 0 795555 795555 0 0
    # compatibility_mode=1280 16777175 100 0 20360950 20360950 0 0
    # compatibility_mode=8192 67108863 100 0 94219 94219 0 0
    # scanned=75585
    # found=0
    # cleaned=0
    # scan_time=16627Any more SIGNS of infection?signs?
    if you MEAN the programs not closing thing?
    its gone.
    but a folder named recycler sometimes appears in drive F. :S
    its not there today, maybe its gone as well.
    i delete the folder whenever i see it.That folder is the Recycle Bin on that drive. It should be hidden, correct?

    Clean up System RESTORE

    Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."
    • Select Start > All Programs > Accessories > System tools > System Restore.
    • On the dialogue box that appears select Create a Restore Point
    • Click NEXT
    • Enter a name e.g. Clean
    • Click CREATE
    You now have a clean restore point, to get rid of the bad ones:
    • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
    • In the Drop down box that appears select your main drive e.g. C
    • Click OK
    • The System will do some calculation and the display a dialogue box with TABS
    • Select the More Options Tab.
    • At the bottom will be a system restore box with a CLEANUP button click this
    • Accept the Warning and select OK again, the program will close and you are done
    Run OTC to remove our tools

    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    Purge old temporary files

    Please download TFC by OldTimer to your desktop
    • Please double-click TFC.exe to run it. (Note: If you are RUNNING on Vista, right-click on the file and choose Run As Administrator).
    • It will close all programs when run, so make sure you have saved all your work before you begin.
    • Click the Start
      button to begin the process. Depending on how often you clean temp
      files, execution time should be anywhere from a few seconds to a minute
      or two. Let it run uninterrupted to completion.
    • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
    Security Check

    Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    Tell me in your next reply, if you have completed these tasks:
    • Cleaned System Restore
    • Ran OTC
    • Ran TFC
    • Ran Security Check
    Also, let me know how your computer is running, and don't forget to post the contents of the Security Check log.
    314.

    Solve : need help with spyware?

    Answer» HI.

    Could you please re-run ComboFix in Safe Mode with Networking by rebooting, tapping F8 until is asks you which mode to boot into please choose Safe mode with Networking and re-run ComboFix.hi i run windows in safe mode with networking.. re-run commy and nothing different happens... it LOADS and no windows open... any solutions?... thanksHi.

    I will SEND you a PM of instructions.hi Sneakyone .. i will be on holiday for 5-7 DAYS so please post ur instructions and i will try to do it as fast as possible.. thanksHi.

    I thought I sent you a PM with instructions, but I will do it again. hi i sent u a personal message... please reply:D
    315.

    Solve : File cannot be executed...?

    Answer»

    Hi guys, I'm new here and not fantastic with computers. I've recently been having some issues, some lame spyware DEAL that I got fixed and now this "File cannot be executed" issue. I don't know where to start and could really use some help. Anything would be APPRECIATED! Thanks. Sorry for the delay, we are busy here on the boards. If you are still having issues, please do the following:


    Please download Malwarebytes Anti-Malware from here.

    Double Click mbam-setup.exe to install the application.

    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Full Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click REMOVE Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
    • Please save the log to a location you will remember.
    • The log is automatically SAVED by MBAM and can be viewed by clicking the LOGS tab in MBAM.
    • Copy and paste the entire report in your next reply.
    Extra Note:

    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
    316.

    Solve : Possible infection??

    Answer»

    Hi there,
    THANK you for your great web site! I'v been following your instructions for virus and spyware removal and am not sure what to do next. My computer boots incredibly slowly, it sounds like it's always "running" something, and the fan seems to be working too much. I was able to do all the steps. However, I had to un-install my Ad-Aware program before downloading the HJT program. Please let me know what to do next. Here are the logs:

    -SuperAntispyware log
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 08/06/2010 at 03:31 PM

    Application Version : 4.41.1000

    Core Rules Database Version : 5328
    Trace Rules Database Version: 3140

    Scan type : Complete Scan
    Total Scan Time : 01:45:50

    Memory items scanned : 479
    Memory threats detected : 0
    Registry items scanned : 6029
    Registry threats detected : 0
    File items scanned : 128631
    File threats detected : 34

    Adware.Tracking Cookie
    C:\Documents and Settings\Owner\Cookies\[emailprotected][3].txt
    C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
    enhance.com [ C:\Documents and Settings\Gradon\Application Data\Macromedia\Flash Player\#SharedObjects\M63NSDH4 ]
    memecounter.com [ C:\Documents and Settings\Gradon\Application Data\Macromedia\Flash Player\#SharedObjects\M63NSDH4 ]
    C:\Documents and Settings\Gradon\Cookies\[emailprotected][1].txt
    interclick.com [ C:\Documents and Settings\Katie\Application Data\Macromedia\Flash Player\#SharedObjects\BJ2KZ8CP ]
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][1].txt
    C:\Documents and Settings\Katie\Cookies\[emailprotected][2].txt
    .sonyonlineentertainment.112.2o7.net [ C:\Documents and Settings\Owner\Application Data\Sony Online Entertainment\Installed Games\Free Realms\mozilla\cookies.txt ]
    C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt
    C:\Documents and Settings\Owner\Cookies\[emailprotected][3].txt

    Application.PowerReg Scheduler
    C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\8B0A1FC\BACKUP\POWERREG SCHEDULER V3.EXE
    C:\DOCUMENTS AND SETTINGS\OWNER\START MENU\PROGRAMS\STARTUP\POWERREG SCHEDULER V3.EXE
    C:\WINDOWS\Prefetch\POWERREG SCHEDULER V3.EXE-1DAD6551.pf


    -Malwarebyet log

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4401

    Windows 5.1.2600 Service PACK 2
    Internet Explorer 6.0.2900.2180

    08/06/2010 4:21:05 PM
    mbam-log-2010-08-06 (16-21-05).txt

    Scan type: Quick scan
    Objects scanned: 166824
    Time elapsed: 13 minute(s), 8 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    -HijackThis log
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 7:48:09 AM, on 08/07/2010
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\netdde.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Digital Media Reader\shwiconem.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
    C:\Program Files\Common Files\New BOUNDARY\PrismXL\PRISMXL.SYS
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\UAService7.exe
    C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\InetCntrl\InetCntrl.exe
    C:\PROGRA~1\Crawler\Smileys\CSmileysIM.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Creative\Software Update 3\SoftAuto.exe
    C:\Program Files\BigFix\BigFix.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
    C:\PROGRA~1\Crawler\Smileys\CSMILE~1.EXE
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\Trend Micro\HiJackThis\Sniper.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gatewaybiz.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80114
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80114
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gatewaybiz.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80114
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80114
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: ALOT Toolbar BHO - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files\alot\bin\alot.dll
    O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
    O2 - BHO: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Bsecure Popup Blocker - {E0019445-4C1F-414D-A70E-AD80F231C584} - C:\WINDOWS\system32\InetCntrl\PopupKil\BsafeBHO.dll
    O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
    O3 - Toolbar: &Inbox Toolbar - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\PROGRA~1\INBOXT~1\Inbox.dll
    O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
    O4 - HKLM\..\Run: [Gateway Extended Warranty] "C:\Program Files\Gateway\GWCares\GWCares.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [NVCPLDAEMON] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
    O4 - HKLM\..\Run: [InetCntrl] C:\WINDOWS\system32\InetCntrl\InetCntrl.exe
    O4 - HKLM\..\Run: [CSmileys] "C:\PROGRA~1\Crawler\Smileys\CSmileysIM.exe"
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
    O4 - HKCU\..\Run: [CTZDetec.exe] "C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [CSmileys] "C:\PROGRA~1\Crawler\Smileys\CSmileysIM.exe"
    O4 - HKCU\..\Run: [SoftAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe"
    O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1150596.exe -Update -1150596 -"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; GTB6.3; .NET CLR 1.1.4322; [xSP_2:73a5c0c6bd31649acf2e6abe8b913f7e_212]; 988700803)" -"http://www.americangirl.com/fun/travel/bz/index.php?section=game"
    O4 - Startup: Epson all-in-one Registration.lnk = E:\Titles\Ereg\EPSONREG.EXE
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: Crawler Search - tbr:iemenu
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: inetcntrl0013.dll
    O10 - Unknown file in Winsock LSP: inetcntrl0013.dll
    O10 - Unknown file in Winsock LSP: inetcntrl0013.dll
    O10 - Unknown file in Winsock LSP: inetcntrl0013.dll
    O10 - Unknown file in Winsock LSP: inetcntrl0013.dll
    O10 - Unknown file in Winsock LSP: inetcntrl0013.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1257353991492
    O18 - Protocol: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll
    O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
    O23 - Service: Creative Centrale Media Server (CTUPnPSv) - Creative Technology Ltd - C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: SMSv3_0_2hs - Alexandria Software Consulting - C:\Program Files\Rosetta Stone\SMS v3.0.2hs\Service\JavaSrvc.exe
    O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

    --
    End of file - 12780 bytes


    Sorry for the delay. We are busy here on the boards. If you are still having issues, please do the following, if possible:

    Please download MySystem-Search from here: Download mirror

    • Save the file to your Desktop.
    • Double-click on mss.exe
    • Allow it to run, and follow the prompts.
    • Once done, it will launch a log.
    • Post it in your next reply.
    Note: the logs are long. Please use more than one post, if necessary.
    317.

    Solve : Application cannot be executed. The file "****.exe" is infected?

    Answer»

    almost every application i have except firefox (WOW) that i try to open, i GET a windows security alert saying "Application cannot be executed. The file "winamp.exe" is infected" and wats weird is my IE wont let me go to any sites but 5 mins later itll show up with a popup from www.*adult URL* or sum other retarded site. please helpSorry for the delay. We are busy here on the boards. If you are still having issues, please do the following, if possible:

    Please download MySystem-Search from here: Download mirror

    • Save the file to your Desktop.
    • Double-click on mss.exe
    • Allow it to run, and follow the prompts.
    • Once done, it will launch a log.
    • Post it in your NEXT reply.
    Note: the logs are long. Please use more than ONE post, if necessary.
    318.

    Solve : avira / advanced registry optimizer?

    Answer»
    hi all i am having probs with the computer when i am on the web (sky) every now and then the computer freezes and / or crashes totally and throws up a blue screen with white writing?!?!

    i am CONVINCED i have picked up some viruses... only when i run Avira it says no viruses found

    when i run my advanced registry optimizer which i paid for last yr it straight away found 44! viruses!
    then a day later another 14...

    i am a little confused why one is finding and the other isnt? my understanding was the antivirus (avira) would stop any viruses coming in.... where as the advanced thing got RID once you actually had them?! please correct me if i am wrong or using the wrong programmes

    could someone anyone please advise what is best and even after keep getting rid of these viruses its finding am i still having problems !! arghhhhhh! many thanks in advance, MEL
    1) Avira is an anti virus utility
    2) Advanced registry optimizer is NOT an anti virus utility
    3) Advanced registry optimizer is a waste of your money. You should never use ANY registry optimizers or cleaners. They are not only worthless, but they often cause major problems.
    4) What is the blue screen error message you get? And what OS are you using so I can move this to the correct forum?
    thanks for your quick reply

    its a shame ive wasted my money on the A R O, so is it NOT actually finding errors and viruses then? its telling me it is, and then telling me im cleaning them up! bit confused...
    am i best to delete it entirely, if you think its causing problems in itself??
    to be honest i havent written down the blue screen errors, i will deffo do so as soon as it happens again. not good on my part i know, but this HAPPENED yesterday and this morning and i only thought to JOIN this forum and send a message tonite.
    i am operating on vista i believe although not 100% abt that as someone else set it all up for me.
    thank you again melYour software is not telling you that it's finding viruses. What makes you think it is? It's telling you that it's finding "registry errors" (which is nonsense, by the way). I don't know what is causing your problems, but I would not be surprised if it is the registry utility. Just let us know what the blue screen error says.
    oh ok maybe it has a devious way of making you think that its viruses that its found!
    i will stop using it, thanks for this adivce
    wont waste your time any more tonite, i will deffo write the error down as soon as it happens again
    thanks mel
    319.

    Solve : Infected laptop - corrupted search engines?

    Answer»

    Thanks in advance for the information and HELP. I'm hoping to avoid a reformat. Here is what I experience:

    Symptoms:
    --when I run a web search with Google or Bing, the first page of results that I get have generic names related to whatever I run a search on but the actual URL that each of them links to the following (I ran a search on Chicago) (further below are copies of all the shortcuts).
    --The SECOND page of the results SEEM to be alright however all of the “advertising” seem to be corrupted regardless of what page it shows up on
    --If I keep trying to work with search and try to figure out what is going on I get some error messages
    --When these errors show up, I loose connectivity between Outlook and the server and between all browsers and the internet (even though my wireless connection remains strong)
    --Also, I can’t launch programs, open taskmanager (even from Cntrl Alt Del – I can click on the option but no response) or shutdown the COMPUTER. I have to do a “Hard Shutdown” with the power button

    Copies of Shortcuts from first page of results from Google Search (similar regardless of what I search on)
    http://bitstub.com/public/go.php?to=874623
    http://bitstub.com/public/go.php?to=874624
    http://bitstub.com/public/go.php?to=874626
    http://109.235.49.54:81/a/click.php?s=eAEFwUdyo0BcMFwwwL_4js0MIMBbW1sEgQhcIojMhVwiXCchcnz9ds-_JMB-v6plGX5_fm74N1ww4BsC-A0x_Fwn_R6q4d_8N9f6xZmh3rdMUHCMHSXEehNxPQUsyjK2Q73SrYO3MnTY_WiFw-Yjqp1h53y8ASjeaLUGIyyHGT6v-xBEDxBN2s5yEgUoWWK4Tyk1TtYeXFw9XCL3jc_HHJsvSzYFZTXieyW9PU16NUtI8L10Kj1P3QOlrjJVcVhNdvDgOXpPVq9H124JyyTKSu6RjQRQpN6nfiBGMORSM8qFxpXJA7Ps-NCyN1nQO_4msPZAwG2WEkjjyUSrbz-RtoWa6sTfwk9Io1GL-jOGaTYCrcVVczLhLLtwJHqiLjmdOspgRdFelxeBTjuIPZD5kZC6bVMUDxcIQrR9XFxLWfFH8Ww72ncPfSyTOhvorknuziHEg7b7SVOsyLRi7miRcw5YhLgIGTrFoobxiYrdZJ-iBiSPXCfWPqU2ugWbtFCb2xt2EBvvljJX77zVXR9ZO4dW_nGlZ0pPczCIHzMPk8NTHwnmqjAZQl2nhi77jDc5LKQ6uhBdHZBdKREX0Q8U3aQKbgm6INaE-3eIYUGYlauptLYOzwWe5MWXtLOr121bhmbCdEwgLaM0c3riRP1V19L-bO2FP0oYFL3yDBtrRm1So3EvDoiHhsMlOHYEkKux83gcDyrBWA21I8lLfcVMxDCN6FClYBJcXMwcWaqHY_WxhNN-gYbASUt6dGMeEvHmDW0rptQSV6aSZRGTTcix719__gPvRvBcJw,,&aff=625&as=1
    http://bitstub.com/public/go.php?to=874628
    http://bitstub.com/public/go.php?to=874629
    http://bitstub.com/public/go.php?to=874630
    http://bitstub.com/public/go.php?to=874632
    http://109.235.49.54:81/a/click.php?s=eAENysttwzAMXDDQXTKAwz8pF0VnkSgSKdqDgWZ_1Kd3eX9cJ5Gej9f7fZ3Pp8WBNg6TAxmf-fudP8f1ur7yc-1YWb5ojZI1dkOLhsLiKJ8BvjYP6umCBdoGggNFVblcMHPHLt2CsZ1sRjKzSUJ1ZRk4t3LLvaw45iAy15nCOYYSqjUJjTYE0ekEKVYNMyRVbNOmUW3OvqBxXCf6RAMLd8Z7Wda6eXz8A3wSP4A,&aff=625&as=1
    http://109.235.49.54:81/a/click.php?s=eAENzltqAzEMQNG9ZAEzeth6TCldiy3JJKQfA83-qf8Pl_t3EfXr8fx87us8xQ4UP6QdyHjG7yvex_28f-IbLdIQ2uTKlcNk9WSjlDAsbsBBfVS1RQRq6NA7OrGSMa0QLojtkyboiAwbZICtJZALVrqa41K1wiUk6dLnYM7Rw7eSkkoUVrAxXFzZbU3s1lAFaGr6mEa6RtkOUETfo1N1P8k0rtb08fUPEns-1Q,,&aff=625&as=1
    http://bitstub.com/public/go.php?to=874635


    Results of SuperSpyWare Scan:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 07/30/2010 at 06:24 PM

    Application Version : 4.41.1000

    Core Rules Database Version : 5291
    Trace Rules Database Version: 3103

    Scan type : Complete Scan
    Total Scan TIME : 01:53:17

    Memory items scanned : 610
    Memory threats detected : 0
    Registry items scanned : 7504
    Registry threats detected : 0
    File items scanned : 109328
    File threats detected : 0

    Results of Malware Scan:
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4372

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    7/30/10 06:37:19 PM
    mbam-log-2010-07-30 (18-37-19).txt

    Scan type: Quick scan
    Objects scanned: 145191
    Time elapsed: 8 minute(s), 28 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\system32\javaw.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Results of Hijack This scan:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 06:57:58 PM, on 7/30/10
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
    C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\IObit\Advanced Spyware Remover\ASRsrv.exe
    C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe
    C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\mfevtps.exe
    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Common Files\ICWM\Printer\RDIConverterService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
    C:\WINDOWS\system32\vmnat.exe
    C:\Program Files\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe
    C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
    C:\Program Files\VMware\VMware vCenter Converter Standalone\vmware-converter.exe
    C:\Program Files\Xobni\XobniService.exe
    C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
    C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
    C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\system32\vmnetdhcp.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
    C:\Program Files\IObit\Advanced Spyware Remover\ASRtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Apoint\HidFind.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\McAfee\VirusScan Enterprise\ShStat.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\FriendlyHijackThis\Sniper.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [vmware-tray] "C:\Program Files\VMware\VMware Workstation\vmware-tray.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [Advanced Spyware Remover] "C:\Program Files\IObit\Advanced Spyware Remover\ASRtray.exe" /autostart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
    O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\pmpta.dll
    O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} (Device Detection) - http://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
    O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (Lotus Quickr Class) - https://amqp1.ansell.com/qp2.cab
    O16 - DPF: {2202D225-22C1-4B8C-A4B8-6A7E7B7E1524} (ICWMInstallObj Class) - https://cpc.on.intercall.com/confmgr/installs/ICWMInstall.cab
    O16 - DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} (STCWeb Control) - https://vpn-am1.infor.com/CACHE/webvpn/stc/1/binaries/stcweb.cab
    O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
    O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} (Cisco AnyConnect VPN Client Web Control) - https://vpn-am1.infor.com/CACHE/stc/1/binaries/vpnweb.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199978753218
    O16 - DPF: {804F9BC5-0EAB-4150-8065-0DF485420670} (InstallShield Setup Player V11.5) - http://w2003e/deciweb/clientconfig/setup.exe
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.infuzer.com/IDC/client/player/isetup.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {DC7D77DA-E1AC-4D40-930B-B87B2954E034} (QuickMksAxCtl Class) - https://10.130.129.1/LabManager/ControlPanel/Machines/MachineDetails/ActiveXControls/ViewerXVNC/vmware-mks.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = infor.com
    O17 - HKLM\Software\..\Telephony: DomainName = infor.com
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = infor.com
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = infor.com,infor.com
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = infor.com
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = infor.com,infor.com
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = infor.com,infor.com
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: ASRservice - IObit - C:\Program Files\IObit\Advanced Spyware Remover\ASRsrv.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
    O23 - Service: SSA License Server (Master:6005) (BCLMD_M) - SSA Global - C:\Program Files\Baan\shared\bin\BclmServer.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
    O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
    O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: McAfee Engine Service (McAfeeEngineService) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
    O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: RDI Document Conversion Helper (RDIConverterPrintHelper) - Web Meeting - C:\Program Files\Common Files\ICWM\Printer\RDIConverterService.exe
    O23 - Service: Cisco Systems, Inc. STC Agent (STCAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
    O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
    O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
    O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
    O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
    O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
    O23 - Service: VMware vCenter Converter Agent (vmware-converter-agent) - VMware, Inc. - C:\Program Files\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe
    O23 - Service: VMware vCenter Converter Server (vmware-converter-server) - VMware, Inc. - C:\Program Files\VMware\VMware vCenter Converter Standalone\vmware-converter.exe
    O23 - Service: Cisco AnyConnect VPN Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
    O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe

    --
    End of file - 18424 bytes

    Duplicate post. Locked

    320.

    Solve : unable to get rid of adware and spyware?

    Answer»

    MBRCheck, version 1.1.1

    (c) 2010, AD



    \\.\C: --> \\.\PhysicalDrive0

    \\.\E: --> \\.\PhysicalDrive0



    Size Device Name MBR Status

    --------------------------------------------

    232 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)!





    Found non-standard or infected MBR.

    Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    Options:

    [1] Dump the MBR of a physical disk to file.

    [2] Restore the MBR of a physical disk with a standard boot code.

    [3] Exit.



    Enter your choice: Enter the physical disk number to fix (0-99, -1 to cancel): Available MBR codes:

    [ 0] Default (Windows XP)

    [ 1] Windows XP

    [ 2] Windows Server 2003

    [ 3] Windows Vista

    [ 4] Windows 2008

    [ 5] Windows 7

    [-1] Cancel



    Please select the MBR code to write to this drive:

    Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue: Successfully wrote new MBR code!

    Please reboot your computer to complete the fix.





    Done! Press ENTER to exit...

    Download Bootkit Remover to your Desktop.

    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip: http://www.7-zip.org/
    • After extracing remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator.
    • It will show a Black screen with some data on it.
    • Right click on the screen and click Select All.
    • Press CTRL C
    • Open a Notepad and press CTRL V
    • Post the output back here.
    Bootkit Remover version 1.0.0.1
    (c) 2009 eSage Lab
    www.esagelab.com

    \\.\C: -> \\.\PhysicalDrive0
    MD5: 6def5ffcbcdbdb4082f1015625e597bd
    \\.\E: -> \\.\PhysicalDrive0

    Size Device Name MBR Status
    --------------------------------------------
    232 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)


    Press any key to quit...
    Good. Now, are you still having the same issue?wow!! everything seems to be running normally now and i can boot up without any problems
    i really cannot thank you enough for all the time you've spent helping me i really appreciate it!Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some STAGE you will be clean. There are several ways to reset your restore points, but this is my method:
    • Select Start > All Programs > Accessories > System tools > System Restore.
    • On the dialogue box that appears select Create a Restore Point
    • Click NEXT
    • Enter a name e.g. Clean
    • Click CREATE
    You now have a clean restore point, to get rid of the bad ones:
    • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
    • In the Drop down box that appears select your main drive e.g. C
    • Click OK
    • The System will do some calculation and the display a dialogue box with TABS
    • Select the More Options Tab.
    • At the bottom will be a system restore box with a CLEANUP button click this
    • Accept the Warning and select OK again, the program will close and you are done
    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    ==

    Please download TFC by OldTimer to your desktop
    • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • It will close all programs when run, so make sure you have saved all your work before you begin.
    • Click the Start
      button to begin the process. Depending on how often you clean temp
      files, execution time should be anywhere from a few seconds to a minute
      or two. Let it run uninterrupted to completion.
    • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
    ==

    Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    Results of screen317's Security Check version 0.99.4
    Windows XP Service Pack 2
    Out of date service pack!!
    Internet Explorer 6 Out of date!
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    avast! Antivirus
    ESET Online Scanner v3
    Antivirus up to date!
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    Java(TM) 6 Update 11
    Java(TM) SE Runtime Environment 6 Update 1
    Out of date Java installed!
    Adobe Flash Player 9 (Out of date Flash Player installed!)
    Adobe Flash Player 10.0.45.2
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Alwil Software Avast4 aswUpdSv.exe
    Alwil Software Avast4 ashServ.exe
    Alwil Software Avast4 ashDisp.exe
    Alwil Software Avast4 ashMaiSv.exe
    Alwil Software Avast4 ashWebSv.exe
    ````````````````````````````````
    DNS Vulnerability Check:


    ``````````End of Log````````````
    Please upgrade to Windows XP SP3, because it includes all previously released updates. It also includes a small number of new functionalities. Some of the updates that Service Pack 3 provides, you may not have. It is now available via Windows Update.

    More info about SP3: http://www.geekpolice.net/operating-systems-f20/windows-xp-service-pack-3-information-t16956.htm

    ===========================================================

    Please download and install the newest version of Adobe Flash Player from Adobe.com

    ==

    Please download the newest version of Java from Java.com.

    Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still LEAVE you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
    Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

    Once old versions are gone, please install the newest version.

    =============================================

    Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

    Software recommendations

    Firewall
    • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
    • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
    • PC Tools Firewall Plus: free and excellent firewall.
    AntiSpyware
    • SpywareBlaster
      SpywareBlaster is a program that prevents spyware from installing on your computer. A tutorial on using SpywareBlaster may be found here.
    • Spybot - Search & Destroy.
      Spybot - Search & Destroy is a spyware and adware removal program. It also has realtime protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).
    NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

    Resident Protection help
    A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

    Securing your computer
    • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
    • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, MEANING it will be difficult to infect your computer in the future.
    Please CONSIDER using an alternate browser
    Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

    If you are interested:
    See this page for more info about malware and prevention.thank you so much ive taken your advice and i must say everything seems to be running better!!
    again thank you so much for all your help!!! You're welcome.
    321.

    Solve : Recently had a av suite virus (?) now things aren't right????

    Answer»

    I got the file you described on my desktop, but I don't know how to manually upload it?? All it opened was a page Getsysteminfo parser 2.96 and there is no place to upload anything? All it says is what's your problem, with a DROPDOWN menu. I'm also now getting tons of pop ups, even though my blocker is set at high, and every page or email, everything I go to has certain words underlined twice in green, and if I put my cursor on them, a gamevance ad pops up? What is that and how do I get rid of it?Seems LIKE adware.


    Please download ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe and save it to your Desktop. Do NOT perform a scan yet

    • Double-click on drweb-cureit.exe to start the program.
      An Express Scan of your PC notice will APPEAR.
    • Under Start the Express Scan Now, Click OK to start the scan.
      This is a short scan that will scan the files currently running in memory.
      If something is found, click the Yes button when it asks you if you want to cure it.
    • Once the short scan has finished, Click Options > Change settings
    • Choose the Scan tab and UNcheck Heuristic analysis
    • Back at the main window, click Custom Scan, then Select drives (a red dot will show which drives have been chosen).
    • Then click the Start/Stop Scanning button (green arrow on the right, and the scan will start.
    • When finished, a message will be displayed at the bottom advising if any viruses were found.
    • Click Yes to all if it asks if you want to cure/move the file.
    • When the scan has finished, look if you can see the icon next to the files found.

    If so, click it, then click the next icon right below and select Move incurable.
    (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
    • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
    • Save the DrWeb.csv report to your Desktop.
    • Exit Dr.Web Cureit when you have finished.
    • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
    When I click on DrWeb-CureIt I get an error message - Internet Explorer cannot display the page....etc....I fixed the link. Please try it again.Okay, here is the report, but I don't think the scan was complete. I STARTED this thing last night about 12:30 am, and at 9 am this morning it was STILL going. I had to end it, because I work from home online and needed my computer. So I have no idea if this will even be useful, since I don't think it was finished. I've never had a scan take so long. Is that a bad sign?


    gtdownde_110.ocx;C:\WINDOWS\system32;Probably DLOADER.Trojan;Incurable.Deleted.;
    SkillJamLoader.dll;C:\Documents and Settings\All Users\Application Data\SkillJam\SecurePlayer;Program.PopcapLoader.4;;
    SDFix.exe\SDFix\apps\Process.exe;C:\Documents and Settings\Christopher Apostle\Desktop\Unused Desktop Shortcuts\SDFix.exe;Tool.Killproc.3;;
    SDFix.exe;C:\Documents and Settings\Christopher Apostle\Desktop\Unused Desktop Shortcuts;Archive contains infected objects;Moved.;
    jar_cache1456766111123690851.tmp\AppleT.class;C:\Documents and Settings\Christopher Apostle\Local Settings\temp\jar_cache1456766111123690851.tmp;Exploit.Java.90;;
    jar_cache1456766111123690851.tmp;C:\Documents and Settings\Christopher Apostle\Local Settings\temp;Archive contains infected objects;Moved.;
    WmaInfo.dll;C:\Program Files\AMT;BackDoor.Click.679;Deleted.;
    Let's move to a different tool.

    Save these instructions so you can have access to them while in Safe Mode.

    Please click here to download AVP Tool by Kaspersky.
    • Save it to your desktop.
    • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    • Double click the setup file to run it.
    • Click Next to continue.
    • Accept the License agreement and click on next.
    • It will, by default, install it to your desktop folder. Click Next.
    • It will then open a box There will be a tab that says Automatic scan.
    • Under Automatic scan make sure these are checked.
      • Hidden Startup Objects
      • SYSTEM Memory
      • Disk Boot Sectors.
      • My Computer.
      • Also any other drives (Removable that you may have)[/color]
      Leave the rest of the settings as they appear as default.
      • Then click on Scan at the to right hand Corner.
      • It will automatically Neutralize any objects found.
      • If some objects are left un-neutralized then click the button that says Neutralize all
      • If it says it cannot be neutralized then choose the delete option when prompted.
      • After that is done click on the reports button at the bottom and save it to file name it Kas.
      • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

        Note: This tool will self uninstall when you close it so please save the log before closing it.
      322.

      Solve : Infected wuauclt.exe - please help?

      Answer»

      Sorry put this in the main forum so repeating it here in the hope that I might get some HELP.

      This is our family laptop and the virus has completely stopped IE opening, can open firefox, and won't let me open any of my anti-virus stuff.

      If I click yes on one of the notices I either get directed to site to BUY anti-virus software or I get a *censored* site front PAGE. As my children use this computer I really need to get this off asap. Please help me.

      RebekahI responded to the thread in the main forum. I will LOCK this one.

      323.

      Solve : Another "cannot be executed. **** is infected" problem?

      Answer»

      I FOLLOWED a similar thread and ran RKILL, OTL and ComboFix (downloaded from another computer.) RKILL log provided below. I'll save the others until told to include them.
      Please help...

      (Machine not rebooted yet)

      *****
      RKILL
      *****
      This log file is located at C:\rkill.log.
      Please POST this only if requested to by the person helping you.
      Otherwise you can close this log when you WISH.
      Ran as Judy on 07/31/2010 at 11:01:48.


      Processes terminated by Rkill or while it was running:


      C:\Users\Judy\AppData\Local\yjhwvghwy\fdnlxcftssd.exe
      C:\Windows\system32\SearchProtocolHost.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Windows\system32\DllHost.exe
      C:\Windows\system32\DllHost.exe


      Rkill completed on 07/31/2010 at 11:01:56.
      Sorry -- did not yet RUN ComboFix. Only downloaded to thumb drive.
      FIXED -- Thank you

      324.

      Solve : Pretty sure I got hold of some malware?

      Answer»

      I keep getting error messages that say that Windows Explorer is shutting down. This happens when I am moving or opening FILES and programs. Sometimes it seems to be random; other times a specific file or program will cause the error repeatedly. When I am on the internet, Internet Explorer will randomly shut down. Sometimes it restarts itself, other times it gives me a message telling me that it shut down to protect my computer. I can download, but am completely unable to install new programs--I get an error message telling me to clear my internet cache and download again (which I have already done--twice). I have Avira antivirus, and have run several scans, which came back clean. It hasn't been updated in about three weeks because the updates won't work. I have tried everything I can think of. System restore fails, even in safe mode. I could not find anything suspicious in add/remove programs and I have cleaned my hard drive using CCleaner. I am unable to follow the steps that are suggested because I can't install new programs. Just for information's sake, I am running Windows Vista, and this has been happening for about a day or two now. Any help you can provide would be greatly appreciated, as I really do not want to have to wipe my hard drive! Hi,

      Please download OTL to your Desktop. (If you already have it downloaded, then just follow the instructions below).

      • Double click on the icon to run it. Make sure all other windows are closed and to LET it run uninterrupted.
      • Under the Custom Scan box paste this in
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\System32\config\*.sav
      %systemroot%\system32\*.sys
      %systemroot%\system32\drivers\*.dll
      %systemroot%\system32\drivers\*.ini
      %systemroot%\system32\drivers\*.exe
      %SYSTEMDRIVE%\*.*
      %PROGRAMFILES%\*.
      %appdata%\*.*
      netsvcs
      msconfig
      safebootminimal
      safebootnetwork
      activex
      drivers32
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      ahcix86.sys
      KR10N.sys
      disk.sys
      nvstor32.sys
      ahcix86s.sys
      nvrd32.sys
      symmpi.sys
      adp3132.sys
      mv61xx.sys
      usbstor.sys
      /md5stop
      CREATERESTOREPOINT
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


      • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
        • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
        • Please copy (Edit->Select All, Edit->Copy) and paste (Edit->Paste) the contents of these files, one at a time
      Note: in the event that OTL fails to run, please use alternate download links to try again:

      http://oldtimer.geekstogo.com/OTL.com
      http://oldtimer.geekstogo.com/OTL.scrok, here are the logs

      OTL logfile created on: 7/20/2010 6:00:10 PM - Run 1
      OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\owner\Desktop
      64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
      Internet Explorer (Version = 8.0.6001.18928)
      Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

      4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
      8.00 Gb Paging File | 6.00 Gb Available in Paging File | 77.00% Paging File free
      Paging file location(s): ?:\pagefile.sys [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
      Drive C: | 286.54 Gb Total Space | 79.67 Gb Free Space | 27.80% Space Free | Partition Type: NTFS
      Drive D: | 289.63 Gb Total Space | 278.85 Gb Free Space | 96.28% Space Free | Partition Type: NTFS
      Drive E: | 612.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
      Drive F: | 139.82 Gb Total Space | 19.48 Gb Free Space | 13.93% Space Free | Partition Type: NTFS
      G: Drive not present or media not loaded
      H: Drive not present or media not loaded
      Drive I: | 139.77 Gb Total Space | 16.41 Gb Free Space | 11.74% Space Free | Partition Type: NTFS

      Computer Name: POOKLET
      Current User Name: owner
      Logged in as Administrator.

      Current Boot Mode: Normal
      Scan Mode: Current user
      Include 64bit Scans
      Company Name Whitelist: Off
      Skip Microsoft Files: Off
      File Age = 30 Days
      Output = Standard

      ========== Processes (SafeList) ==========

      PRC - [2010/07/20 17:58:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe
      PRC - [2010/07/07 15:50:42 | 000,176,408 | ---- | M] (iWin Inc.) -- C:\Program Files (x86)\iWin Games\iWinTrusted.exe
      PRC - [2010/04/19 09:21:37 | 000,267,432 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
      PRC - [2010/03/02 09:28:31 | 000,282,792 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
      PRC - [2010/02/24 08:28:09 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
      PRC - [2009/11/13 16:37:30 | 002,022,072 | ---- | M] (NesterSoft Inc.) -- C:\Program Files (x86)\TimeLeft3\TimeLeft.exe
      PRC - [2009/04/10 11:58:53 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      PRC - [2008/12/09 06:08:38 | 000,495,616 | ---- | M] (Gadwin Systems, Inc) -- C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe
      PRC - [2008/07/29 19:53:00 | 000,500,784 | ---- | M] (Egis Incorporated) -- C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
      PRC - [2008/05/20 19:50:50 | 000,269,448 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
      PRC - [2008/04/25 23:36:20 | 000,045,056 | ---- | M] (NewTech InfoSystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
      PRC - [2008/04/25 23:36:02 | 000,131,072 | ---- | M] () -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
      PRC - [2008/03/03 15:11:14 | 000,016,384 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe


      ========== Modules (SafeList) ==========

      MOD - [2010/07/20 17:58:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe
      MOD - [2008/01/20 21:50:01 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx


      ========== Win32 Services (SafeList) ==========

      SRV:64bit: - [2008/08/19 16:27:22 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe -- (ETService)
      SRV:64bit: - [2008/01/20 21:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
      SRV:64bit: - [2007/12/10 22:11:30 | 000,015,872 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\SysNative\agr64svc.exe -- (AgereModemAudio)
      SRV - [2010/07/07 15:50:42 | 000,176,408 | ---- | M] (iWin Inc.) [Auto | Running] -- C:\Program Files (x86)\iWin Games\iWinTrusted.exe -- (iWinTrusted)
      SRV - [2010/04/19 09:21:37 | 000,267,432 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
      SRV - [2010/03/18 14:27:14 | 001,020,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
      SRV - [2010/03/18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
      SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
      SRV - [2010/02/24 08:28:09 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
      SRV - [2008/07/29 19:53:00 | 000,500,784 | ---- | M] (Egis Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -- (eDataSecurity Service)
      SRV - [2008/05/20 19:50:50 | 000,269,448 | ---- | M] (CyberLink) [Auto | Running] -- C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe -- (Acer HomeMedia Connect Service)
      SRV - [2008/04/25 23:36:20 | 000,045,056 | ---- | M] (NewTech InfoSystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe -- (NTIBackupSvc)
      SRV - [2008/04/25 23:36:02 | 000,131,072 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe -- (NTISchedulerSvc)
      SRV - [2008/03/03 15:11:14 | 000,016,384 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe -- (BUNAgentSvc)


      ========== Driver Services (SafeList) ==========

      DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
      DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
      DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\ipinip.sys -- (IpInIp)
      DRV:64bit: - [2010/03/30 20:58:04 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\PxHlpa64.sys -- (PxHlpa64)
      DRV:64bit: - [2010/03/02 11:35:01 | 000,116,568 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\avipbb.sys -- (avipbb)
      DRV:64bit: - [2010/02/16 12:24:00 | 000,081,072 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\DRIVERS\avgntflt.sys -- (avgntflt)
      DRV:64bit: - [2009/09/30 19:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
      DRV:64bit: - [2009/07/25 11:38:29 | 000,311,968 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\atksgt.sys -- (atksgt)
      DRV:64bit: - [2009/07/25 11:38:29 | 000,043,168 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\lirsgt.sys -- (lirsgt)
      DRV:64bit: - [2008/08/04 23:29:26 | 000,056,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
      DRV:64bit: - [2008/07/29 19:53:50 | 000,060,976 | ---- | M] (Egis Incorporated) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\PSDVdisk.sys -- (psdvdisk)
      DRV:64bit: - [2008/07/29 19:53:50 | 000,021,040 | ---- | M] (Egis Incorporated) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\PSDNServ.sys -- (PSDNServ)
      DRV:64bit: - [2008/07/29 19:53:48 | 000,022,064 | ---- | M] (Egis Incorporated) [File_System | Boot | Running] -- C:\Windows\SysNative\DRIVERS\psdfilter.sys -- (PSDFilter)
      DRV:64bit: - [2008/07/29 06:47:00 | 001,075,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\athrxusb.sys -- (athrusb)
      DRV:64bit: - [2008/03/05 01:22:34 | 001,253,376 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\agrsm64.sys -- (AgereSoftModem)
      DRV:64bit: - [2008/01/30 19:48:32 | 000,016,384 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\NTIDrvr.sys -- (NTIDrvr)
      DRV:64bit: - [2008/01/20 21:49:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\RootMdm.sys -- (ROOTMODEM)
      DRV:64bit: - [2007/05/31 11:39:32 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RimUsb_AMD64.sys -- (RimUsb)
      DRV:64bit: - [2007/01/18 14:10:22 | 000,030,336 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\RimSerial_AMD64.sys -- (RimVSerPort)
      DRV:64bit: - [2006/09/18 16:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\Wbem\ntfs.mof -- (Ntfs)
      DRV - [2008/08/19 16:23:00 | 000,017,952 | ---- | M] (Acer, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\drivers\int15_64.sys -- (int15)


      ========== Standard Registry (SafeList) ==========


      ========== Internet Explorer ==========

      IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0409&m=aspire_x1700
      IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0409&m=aspire_x1700
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0409&m=aspire_x1700
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0409&m=aspire_x1700

      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=1&o=vp64&d=0409&m=aspire_x1700
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

      FF - HKLM\software\mozilla\Firefox\Extensions\\{98e34367-8df7-42b4-837b-20b892ff0849}: C:\ProgramData\iWin Games\firefox [2010/06/15 09:24:58 | 000,000,000 | ---D | M]
      FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/01/21 15:20:50 | 000,000,000 | ---D | M]
      FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/01/22 22:10:14 | 000,000,000 | ---D | M]

      [2010/06/07 04:27:44 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\mozilla\Extensions
      [2010/07/19 23:20:28 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\0dy5c5j8.default\extensions
      [2010/06/07 06:16:32 | 000,000,000 | ---D | M] -- C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\cm83o6ap.default\extensions
      [2010/06/07 06:16:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\owner\AppData\Roaming\mozilla\Firefox\Profiles\cm83o6ap.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
      [2010/01/21 15:20:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions

      O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
      O1 - Hosts: 127.0.0.1 localhost
      O1 - Hosts: ::1 localhost
      O2:64bit: - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll (Egis)
      O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
      O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg64.dll (Google Inc.)
      O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
      O2 - BHO: (ShoppingReport) - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files (x86)\ShoppingReport\Bin\2.6.71\ShoppingReport.dll File not found
      O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files (x86)\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
      O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
      O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
      O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files (x86)\PicLensIE\cooliris.dll File not found
      O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
      O3:64bit: - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
      O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
      O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
      O3:64bit: - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
      O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
      O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
      O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
      O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
      O4 - HKLM..\Run: [] File not found
      O4 - HKLM..\Run: [1157840481] C:\Program Files (x86)\eGames\Twistingo\Register\eGamesRegistration.exe (DataLode, Inc.)
      O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
      O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
      O4 - HKCU..\Run: [AdobeUpdater] C:\Program Files (x86)\Common Files\Adobe\Updater5\AdobeUpdater.exe (Adobe Systems Incorporated)
      O4 - HKCU..\Run: [Gadwin PrintScreen] C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)
      O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
      O4 - Startup: C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TimeLeft.lnk = C:\Program Files (x86)\TimeLeft3\TimeLeft.exe (NesterSoft Inc.)
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
      O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
      O8:64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
      O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
      O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
      O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
      O9 - Extra Button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files (x86)\PicLensIE\cooliris.dll File not found
      O9 - Extra Button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files (x86)\ShoppingReport\Bin\2.6.71\ShoppingReport.dll File not found
      O9 - Extra Button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files (x86)\ShoppingReport\Bin\2.6.71\ShoppingReport.dll File not found
      O13 - gopher Prefix: missing
      O13 - gopher Prefix: missing
      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
      O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll (Installation Support)
      O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos1.walmart.com/WalmartActivia.cab (Snapfish Activia)
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab (BDSCANONLINE Control)
      O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
      O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
      O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      O16 - DPF: ActiveGS.cab http://activegs.freetoolsassociation.com/ActiveGS.cab (Reg Error: Key error.)
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
      O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
      O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
      O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
      O24 - Desktop WallPaper: C:\Users\owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
      O24 - Desktop BackupWallPaper: C:\Users\owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
      O32 - HKLM CDRom: AutoRun - 1
      O32 - AutoRun File - [2008/10/11 18:47:17 | 000,662,592 | R--- | M] (Electronic Arts Inc.) - E:\AutoRunGUI.dll -- [ UDF ]
      O32 - AutoRun File - [2008/10/22 09:19:21 | 000,000,000 | R--D | M] - E:\AutoRun -- [ UDF ]
      O32 - AutoRun File - [2008/10/11 18:47:17 | 000,703,552 | R--- | M] (Electronic Arts Inc.) - E:\AutoRun.exe -- [ UDF ]
      O32 - AutoRun File - [2008/10/11 18:47:12 | 000,000,166 | R--- | M] () - E:\autorun.inf -- [ UDF ]
      O33 - MountPoints2\{7b189048-25f5-11de-9b10-806e6f6e6963}\Shell - "" = AutoRun
      O33 - MountPoints2\{7b189048-25f5-11de-9b10-806e6f6e6963}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- [2008/10/11 18:47:17 | 000,703,552 | R--- | M] (Electronic Arts Inc.)
      O34 - HKLM BootExecute: (autocheck autochk *) - File not found
      O35:64bit: - HKLM\..comfile [open] -- "%1" %*
      O35:64bit: - HKLM\..exefile [open] -- "%1" %*
      O35 - HKLM\..comfile [open] -- "%1" %*
      O35 - HKLM\..exefile [open] -- "%1" %*
      O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
      O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
      O37 - HKLM\...com [@ = comfile] -- "%1" %*
      O37 - HKLM\...exe [@ = exefile] -- "%1" %*


      MsConfig:64bit - StartUpReg: Acer Empowering Technology Monitor - hkey= - key= - C:\Program Files\Acer\Empowering Technology\SysMonitor.exe ()
      MsConfig:64bit - StartUpReg: eDataSecurity Loader - hkey= - key= - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe (Egis Incorporated)
      MsConfig:64bit - StartUpReg: EmpoweringTechnology - hkey= - key= - C:\Program Files\Acer\Empowering Technology\Framework.Lau File not found
      MsConfig:64bit - StartUpReg: NvCplDaemon - hkey= - key= - C:\Windows\SysNative\NvCpl.DLL (NVIDIA Corporation)
      MsConfig:64bit - StartUpReg: RtHDVCpl - hkey= - key= - C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
      MsConfig:64bit - StartUpReg: Skytel - hkey= - key= - C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)

      SafeBootMin:64bit: AppMgmt - Service
      SafeBootMin:64bit: Base - Driver Group
      SafeBootMin:64bit: Boot Bus Extender - Driver Group
      SafeBootMin:64bit: Boot file system - Driver Group
      SafeBootMin:64bit: File system - Driver Group
      SafeBootMin:64bit: Filter - Driver Group
      SafeBootMin:64bit: HelpSvc - Service
      SafeBootMin:64bit: PCI Configuration - Driver Group
      SafeBootMin:64bit: PNP Filter - Driver Group
      SafeBootMin:64bit: Primary disk - Driver Group
      SafeBootMin:64bit: sacsvr - Service
      SafeBootMin:64bit: SCSI Class - Driver Group
      SafeBootMin:64bit: System Bus Extender - Driver Group
      SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
      SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
      SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
      SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
      SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
      SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
      SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
      SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
      SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
      SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
      SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
      SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
      SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
      SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
      SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
      SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
      SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
      SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
      SafeBootMin: AppMgmt - Service
      SafeBootMin: Base - Driver Group
      SafeBootMin: Boot Bus Extender - Driver Group
      SafeBootMin: Boot file system - Driver Group
      SafeBootMin: File system - Driver Group
      SafeBootMin: Filter - Driver Group
      SafeBootMin: HelpSvc - Service
      SafeBootMin: PCI Configuration - Driver Group
      SafeBootMin: PNP Filter - Driver Group
      SafeBootMin: Primary disk - Driver Group
      SafeBootMin: sacsvr - Service
      SafeBootMin: SCSI Class - Driver Group
      SafeBootMin: System Bus Extender - Driver Group
      SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
      SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
      SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
      SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
      SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
      SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
      SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
      SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
      SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
      SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
      SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
      SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
      SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
      SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
      SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
      SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
      SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

      SafeBootNet:64bit: AppMgmt - Service
      SafeBootNet:64bit: Base - Driver Group
      SafeBootNet:64bit: Boot Bus Extender - Driver Group
      SafeBootNet:64bit: Boot file system - Driver Group
      SafeBootNet:64bit: File system - Driver Group
      SafeBootNet:64bit: Filter - Driver Group
      SafeBootNet:64bit: HelpSvc - Service
      SafeBootNet:64bit: Messenger - Service
      SafeBootNet:64bit: NDIS Wrapper - Driver Group
      SafeBootNet:64bit: NetBIOSGroup - Driver Group
      SafeBootNet:64bit: NetDDEGroup - Driver Group
      SafeBootNet:64bit: Network - Driver Group
      SafeBootNet:64bit: NetworkProvider - Driver Group
      SafeBootNet:64bit: PCI Configuration - Driver Group
      SafeBootNet:64bit: PNP Filter - Driver Group
      SafeBootNet:64bit: PNP_TDI - Driver Group
      SafeBootNet:64bit: Primary disk - Driver Group
      SafeBootNet:64bit: rdsessmgr - Service
      SafeBootNet:64bit: sacsvr - Service
      SafeBootNet:64bit: SCSI Class - Driver Group
      SafeBootNet:64bit: Streams Drivers - Driver Group
      SafeBootNet:64bit: System Bus Extender - Driver Group
      SafeBootNet:64bit: TDI - Driver Group
      SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
      SafeBootNet:64bit: WudfPf - Driver
      SafeBootNet:64bit: WudfUsbccidDriver - Driver
      SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
      SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
      SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
      SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
      SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
      SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
      SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
      SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
      SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
      SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
      SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
      SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
      SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
      SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
      SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
      SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
      SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
      SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
      SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
      SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
      SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
      SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
      SafeBootNet: AppMgmt - Service
      SafeBootNet: Base - Driver Group
      SafeBootNet: Boot Bus Extender - Driver Group
      SafeBootNet: Boot file system - Driver Group
      SafeBootNet: File system - Driver Group
      SafeBootNet: Filter - Driver Group
      SafeBootNet: HelpSvc - Service
      SafeBootNet: Messenger - Service
      SafeBootNet: NDIS Wrapper - Driver Group
      SafeBootNet: NetBIOSGroup - Driver Group
      SafeBootNet: NetDDEGroup - Driver Group
      SafeBootNet: Network - Driver Group
      SafeBootNet: NetworkProvider - Driver Group
      SafeBootNet: PCI Configuration - Driver Group
      SafeBootNet: PNP Filter - Driver Group
      SafeBootNet: PNP_TDI - Driver Group
      SafeBootNet: Primary disk - Driver Group
      SafeBootNet: rdsessmgr - Service
      SafeBootNet: sacsvr - Service
      SafeBootNet: SCSI Class - Driver Group
      SafeBootNet: Streams Drivers - Driver Group
      SafeBootNet: System Bus Extender - Driver Group
      SafeBootNet: TDI - Driver Group
      SafeBootNet: WudfPf - Driver
      SafeBootNet: WudfUsbccidDriver - Driver
      SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
      SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
      SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
      SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
      SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
      SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
      SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
      SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
      SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
      SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
      SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
      SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
      SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
      SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
      SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
      SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
      SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
      SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
      SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
      SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
      SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
      SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

      ActiveX:64bit: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
      ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
      ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
      ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
      ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
      ActiveX:64bit: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
      ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
      ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
      ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
      ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
      ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
      ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
      ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
      ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
      ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
      ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
      ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
      ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
      ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
      ActiveX:64bit: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
      ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
      ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
      ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
      ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
      ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
      ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
      ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
      ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error.
      ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
      ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player
      ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
      ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error.
      ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error.
      ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
      ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
      ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
      ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
      ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
      ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
      ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
      ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
      ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
      ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
      ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
      ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
      ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
      ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
      ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
      ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
      ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
      ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
      ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
      ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
      ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
      ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
      ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP

      Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
      Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
      Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
      Drivers32: msacm.mkdmp3enc - C:\PROGRA~2\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM File not found
      Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
      Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
      Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
      Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)

      CREATERESTOREPOINT
      Restore point Set: OTL Restore Point

      ========== Files/Folders - Created Within 30 Days ==========

      [2010/07/20 17:58:23 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe
      [2010/07/19 23:08:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner
      [2010/07/19 22:28:52 | 000,043,520 | ---- | C] (NirSoft) -- C:\Users\owner\Desktop\shexview.exe
      [2010/07/19 18:32:47 | 000,000,000 | ---D | C] -- C:\Users\owner\Desktop\Sims 3
      [2010/07/19 16:44:36 | 000,000,000 | ---D | C] -- C:\Users\owner\Desktop\Simmy
      [2010/07/15 04:26:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
      [2010/07/15 04:26:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
      [2010/07/15 04:26:46 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Local\Cooliris
      [2010/07/10 02:57:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iWin Games
      [2010/07/09 02:03:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Astar Games
      [2010/07/08 20:55:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Gogii
      [2010/07/08 20:50:56 | 000,000,000 | ---D | C] -- C:\Users\owner\Documents\Floodgate
      [2010/07/04 04:19:22 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\KitchenBrigade
      [2010/07/03 23:06:23 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\com.picaboo.Picaboo.A382D4714709B456C4E0088DFC1F7243AF9EBF75.1
      [2010/07/03 23:06:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Picaboo X
      [2010/07/03 23:06:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
      [2010/06/29 14:33:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared(158)
      [2010/06/29 14:33:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Roxio(356)
      [2010/06/25 04:01:35 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\cerasus.media
      [2010/06/24 23:00:18 | 000,000,000 | ---D | C] -- C:\Users\owner\Documents\Pet Vet 3D Down Under
      [2010/06/24 22:28:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Islands
      [2010/06/24 22:28:55 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Islands
      [2010/06/24 09:00:52 | 001,942,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll
      [2010/06/24 09:00:52 | 001,130,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll
      [2010/06/24 09:00:52 | 000,320,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHost.exe
      [2010/06/24 09:00:52 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHost.exe
      [2010/06/24 09:00:52 | 000,109,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationHostProxy.dll
      [2010/06/24 09:00:52 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHostProxy.dll
      [2010/06/24 09:00:52 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netfxperf.dll
      [2010/06/24 09:00:52 | 000,048,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netfxperf.dll
      [2010/06/24 03:39:12 | 000,000,000 | ---D | C] -- C:\ProgramData\GameHouse
      [2010/06/23 20:54:22 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\GameUXLegacyGDFs.dll
      [2010/06/23 20:54:22 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\SysNative\GameUXLegacyGDFs.dll
      [2010/06/23 20:54:22 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Apphlpdm.dll
      [2010/06/23 20:54:22 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Apphlpdm.dll
      [2010/06/23 05:55:06 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\Go-Go Gourmet Chef of the Year
      [2010/06/23 05:41:42 | 000,000,000 | ---D | C] -- C:\Users\owner\AppData\Roaming\YoudaGames
      [2010/06/22 23:07:59 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\iwin
      [2009/03/13 20:28:09 | 000,049,152 | ---- | C] ( ) -- C:\Windows\Interop.IWshRuntimeLibrary.dll

      ========== Files - Modified Within 30 Days ==========

      [2010/07/20 18:00:12 | 003,407,872 | -HS- | M] () -- C:\Users\owner\ntuser.dat
      [2010/07/20 17:59:04 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
      [2010/07/20 17:58:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\owner\Desktop\OTL.exe
      [2010/07/20 17:15:10 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
      [2010/07/20 17:15:10 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
      [2010/07/20 12:59:01 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
      [2010/07/20 12:29:10 | 003,645,694 | -H-- | M] () -- C:\Users\owner\AppData\Local\IconCache.db
      [2010/07/19 23:22:01 | 000,703,388 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
      [2010/07/19 23:22:01 | 000,604,264 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
      [2010/07/19 23:22:01 | 000,103,964 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
      [2010/07/19 23:15:19 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\LogConfigTemp.xml
      [2010/07/19 23:15:08 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
      [2010/07/19 23:15:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
      [2010/07/19 23:15:02 | 4294,172,672 | -HS- | M] () -- C:\hiberfil.sys
      [2010/07/19 23:08:38 | 000,000,865 | ---- | M] () -- C:\Users\owner\Desktop\CCleaner.lnk
      [2010/07/19 22:34:11 | 000,000,667 | ---- | M] () -- C:\Users\owner\Desktop\shexview.cfg
      [2010/07/19 22:28:39 | 000,055,898 | ---- | M] () -- C:\Users\owner\Desktop\shexview.zip
      [2010/07/19 21:03:03 | 000,524,288 | -HS- | M] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TMContainer00000000000000000001.regtrans-ms
      [2010/07/19 21:03:03 | 000,065,536 | -HS- | M] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TM.blf
      [2010/07/19 20:26:00 | 054,835,272 | ---- | M] () -- C:\Users\owner\Desktop\setup_av_free.exe
      [2010/07/19 17:55:27 | 000,003,108 | ---- | M] () -- C:\Users\owner\AppData\Roaming\wklnhst.dat
      [2010/07/19 17:52:22 | 000,017,408 | ---- | M] () -- C:\Users\owner\Documents\scrapstuff.wps
      [2010/07/19 17:51:35 | 000,018,432 | ---- | M] () -- C:\Users\owner\Documents\scrap master.wps
      [2010/07/19 17:50:27 | 000,017,920 | ---- | M] () -- C:\Users\owner\Documents\Scrap List.wps
      [2010/07/19 02:49:53 | 000,041,472 | ---- | M] () -- C:\Users\owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
      [2010/07/18 05:29:06 | 000,001,910 | ---- | M] () -- C:\Users\Public\Desktop\Coconut Queen.lnk
      [2010/07/15 04:26:47 | 000,000,868 | ---- | M] () -- C:\Users\owner\Desktop\Launch Cooliris.lnk
      [2010/07/05 00:21:43 | 000,018,432 | ---- | M] () -- C:\Users\owner\Documents\home decor stuff.wps
      [2010/06/30 15:38:06 | 000,119,768 | ---- | M] () -- C:\Users\owner\AppData\Local\GDIPFONTCACHEV1.DAT
      [2010/06/30 15:35:08 | 000,524,288 | -HS- | M] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TMContainer00000000000000000002.regtrans-ms
      [2010/06/30 15:33:51 | 003,407,872 | -HS- | M] () -- C:\Users\owner\ntuser.dat_previous
      [2010/06/30 15:33:50 | 000,524,288 | -HS- | M] () -- C:\Users\owner\ntuser.dat{a1e78f04-72da-11df-8bf6-9fce7987da27}.TMContainer00000000000000000001.regtrans-ms
      [2010/06/30 15:33:50 | 000,065,536 | -HS- | M] () -- C:\Users\owner\ntuser.dat{a1e78f04-72da-11df-8bf6-9fce7987da27}.TM.blf
      [2010/06/28 14:31:56 | 000,017,408 | ---- | M] () -- C:\Users\owner\Documents\calendar stuff.wps
      [2010/06/22 19:39:53 | 000,017,408 | ---- | M] () -- C:\Users\owner\Documents\stuff.wps

      ========== Files Created - No Company Name ==========

      [2010/07/19 23:08:38 | 000,000,865 | ---- | C] () -- C:\Users\owner\Desktop\CCleaner.lnk
      [2010/07/19 22:34:11 | 000,000,667 | ---- | C] () -- C:\Users\owner\Desktop\shexview.cfg
      [2010/07/19 22:28:52 | 000,018,238 | ---- | C] () -- C:\Users\owner\Desktop\shexview.chm
      [2010/07/19 22:28:38 | 000,055,898 | ---- | C] () -- C:\Users\owner\Desktop\shexview.zip
      [2010/07/19 16:47:19 | 054,835,272 | ---- | C] () -- C:\Users\owner\Desktop\setup_av_free.exe
      [2010/07/18 05:29:06 | 000,001,910 | ---- | C] () -- C:\Users\Public\Desktop\Coconut Queen.lnk
      [2010/07/15 04:26:47 | 000,000,868 | ---- | C] () -- C:\Users\owner\Desktop\Launch Cooliris.lnk
      [2010/07/05 00:21:43 | 000,018,432 | ---- | C] () -- C:\Users\owner\Documents\home decor stuff.wps
      [2010/07/04 03:10:04 | 000,018,432 | ---- | C] () -- C:\Users\owner\Documents\scrap master.wps
      [2010/07/04 03:05:12 | 000,017,920 | ---- | C] () -- C:\Users\owner\Documents\Scrap List.wps
      [2010/07/03 06:05:30 | 000,017,408 | ---- | C] () -- C:\Users\owner\Documents\scrapstuff.wps
      [2010/06/30 15:35:08 | 000,524,288 | -HS- | C] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TMContainer00000000000000000002.regtrans-ms
      [2010/06/30 15:35:08 | 000,524,288 | -HS- | C] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TMContainer00000000000000000001.regtrans-ms
      [2010/06/30 15:35:08 | 000,065,536 | -HS- | C] () -- C:\Users\owner\ntuser.dat{28829569-7f9b-11df-8418-002197af7ab1}.TM.blf
      [2010/06/22 19:39:53 | 000,017,408 | ---- | C] () -- C:\Users\owner\Documents\stuff.wps
      [2010/01/05 23:33:17 | 000,151,552 | ---- | C] () -- C:\Windows\SysWow64\nvRegDev.dll
      [2009/07/15 21:23:50 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
      [2009/07/15 21:23:34 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
      [2009/04/10 12:08:23 | 000,000,042 | ---- | C] () -- C:\Windows\Acer(Wide).ini
      [2009/04/10 12:08:22 | 000,000,044 | ---- | C] () -- C:\Windows\Acer(Normal).ini
      [2009/03/13 21:05:40 | 000,001,024 | RH-- | C] () -- C:\Windows\SysWow64\NTIOFM4.dll
      [2009/03/13 21:05:40 | 000,001,024 | RH-- | C] () -- C:\Windows\SysWow64\NTIBUN5.dll
      [2009/01/05 15:44:10 | 000,000,453 | ---- | C] () -- C:\Windows\bdoscandellang.ini
      [2008/01/20 21:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
      [2008/01/15 05:31:00 | 000,000,530 | ---- | C] () -- C:\Windows\SysWow64\tx14_ic.ini
      [2001/12/26 18:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\multiplex_vcd.dll
      [2001/09/04 01:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\SysWow64\Hmpg12.dll
      [2001/07/30 18:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\SysWow64\HMPV2_ENC.dll
      [2001/07/24 00:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\SysWow64\HMPV2_ENC_MMX.dll

      ========== Custom Scans ==========


      < %systemroot%\*. /mp /s >

      < %systemroot%\system32\*.dll /lockedfiles >

      < %systemroot%\system32\*.exe /lockedfiles >

      < %systemroot%\Tasks\*.job /lockedfiles >

      < %systemroot%\system32\drivers\*.sys /lockedfiles >

      < %systemroot%\System32\config\*.sav >

      < %systemroot%\system32\*.sys >

      < %systemroot%\system32\drivers\*.dll >

      < %systemroot%\system32\drivers\*.ini >

      < %systemroot%\system32\drivers\*.exe >

      < %SYSTEMDRIVE%\*.* >
      [2009/04/11 01:36:38 | 000,333,257 | RHS- | M] () -- C:\bootmgr
      [2009/03/13 20:28:46 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
      [2010/03/03 15:41:02 | 000,096,264 | ---- | M] (Microsoft Corporation) -- C:\GameuxInstallHelper.dll
      [2010/07/19 23:15:02 | 4294,172,672 | -HS- | M] () -- C:\hiberfil.sys
      [2010/07/19 23:13:45 | 000,000,090 | ---- | M] () -- C:\MDisc.log
      [2010/07/19 23:13:47 | 000,000,090 | ---- | M] () -- C:\MDR.log
      [2010/07/19 23:15:01 | 312,811,519 | -HS- | M] () -- C:\pagefile.sys
      [2009/03/13 20:33:11 | 000,000,787 | ---- | M] () -- C:\RHDSetup.log
      [2010/04/25 23:53:49 | 000,005,729 | ---- | M] () -- C:\scramble.log

      < %PROGRAMFILES%\*. >
      [2009/04/10 11:59:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Acer
      [2010/07/19 23:13:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Acer Arcade Live
      [2010/07/19 23:17:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Acer GameZone
      [2009/04/10 12:08:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Acer Incorporated
      [2010/07/03 23:06:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
      [2010/01/30 19:36:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Amazon
      [2009/12/05 03:30:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
      [2009/08/28 12:18:57 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Atari
      [2010/04/25 23:54:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Atrinsic
      [2010/01/20 01:26:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Avira
      [2009/07/25 22:09:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\BFG
      [2009/07/25 22:38:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Brainiversity
      [2010/07/19 23:08:38 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CCleaner
      [2010/01/26 04:11:49 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Chocolatier Decadence by Design
      [2010/07/19 23:23:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
      [2009/03/13 20:58:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\CyberLink
      [2010/07/19 23:23:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\DivX
      [2010/04/26 15:09:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\e-Sword
      [2010/05/19 00:32:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\EA GAMES
      [2010/01/29 01:54:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\eGames
      [2010/01/06 17:33:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Electronic Arts
      [2009/03/13 21:22:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\eSobi
      [2010/05/29 22:51:36 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Free Ride Games
      [2009/11/23 02:23:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Gadwin Systems
      [2010/01/26 03:29:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\GameHouse
      [2010/03/06 22:02:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Games
      [2009/07/25 22:46:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Games A Go-Go
      [2010/02/03 15:39:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Google
      [2009/07/25 22:24:28 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hidden Expedition - Amazon
      [2009/07/25 22:28:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hidden Expedition - Everest
      [2009/07/25 22:21:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Hidden Expedition Titanic
      [2009/11/28 11:17:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\HP
      [2010/07/19 23:13:38 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
      [2010/06/12 09:17:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
      [2010/07/10 02:57:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iWin Games
      [2010/07/18 05:29:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\iWin.com
      [2010/07/15 04:26:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Java
      [2009/12/30 02:56:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\LDA Games
      [2010/01/29 18:32:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\LimeWire
      [2009/07/25 22:26:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Lost Treasures of Alexandria
      [2009/08/06 21:53:10 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mad Scientist PRODUCTIONS
      [2010/01/03 03:05:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Maxis
      [2009/09/05 21:28:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Games
      [2009/03/13 20:47:14 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
      [2009/03/13 20:47:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office Suite Activation Assistant
      [2010/02/17 17:10:39 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
      [2009/03/13 20:47:15 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Works
      [2009/08/06 21:52:31 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft WSE
      [2010/06/26 09:01:09 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
      [2010/06/15 13:29:59 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MostFun
      [2010/01/21 15:20:50 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
      [2006/11/02 10:07:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
      [2009/12/18 20:07:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSECache
      [2009/07/15 20:49:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MSXML 4.0
      [2009/07/25 22:45:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\MumboJumbo
      [2009/07/25 22:09:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mystery in London
      [2009/03/13 21:05:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NewTech Infosystems
      [2010/01/05 23:38:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\NVIDIA Corporation
      [2009/10/13 19:03:30 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\OverDrive Media Console
      [2010/07/03 23:06:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Picaboo X
      [2009/07/25 22:34:33 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PlayFirst
      [2009/07/25 22:40:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\PopCap Games
      [2009/10/28 14:06:22 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\ProPoster
      [2009/12/05 03:31:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime
      [2009/12/30 02:59:13 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\RealArcade
      [2009/03/13 20:32:21 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
      [2006/11/02 10:07:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
      [2009/10/30 14:40:17 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Research In Motion
      [2010/06/30 15:33:24 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Roxio
      [2010/06/29 14:34:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Roxio(356)
      [2009/07/25 22:19:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Scholastic
      [2010/06/08 03:55:16 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Shockwave.com
      [2009/07/26 01:52:19 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Sims2Pack Clean Installer
      [2009/12/27 04:10:52 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\TimeLeft3
      [2009/12/25 15:56:26 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Ubisoft
      [2006/11/02 10:36:07 | 000,000,000 | -H-D | M] -- C:\Program Files (x86)\Uninstall Information
      [2009/09/02 16:28:18 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\VideoLAN
      [2010/03/12 17:12:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Wardrobe Wrangler
      [2009/07/25 22:39:29 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WildTangent
      [2009/07/15 21:56:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Calendar
      [2008/01/20 22:09:47 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Collaboration
      [2008/01/20 22:09:41 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
      [2010/07/14 09:00:32 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
      [2009/10/28 08:06:07 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
      [2006/11/02 10:07:27 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
      [2009/07/15 21:56:04 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Gallery
      [2009/11/17 09:17:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Portable Devices
      [2009/07/15 21:56:05 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar
      [2009/07/26 01:14:11 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\WinRAR
      [2010/04/15 18:18:46 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Yahoo!

      < %appdata%\*.* >
      [2009/10/30 14:46:42 | 000,000,006 | -HS- | M] () -- C:\Users\owner\AppData\Roaming\desktop.ini
      [2010/07/19 17:55:27 | 000,003,108 | ---- | M] () -- C:\Users\owner\AppData\Roaming\wklnhst.dat


      < MD5 for: AGP440.SYS >
      [2008/01/20 21:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
      [2008/01/20 21:46:51 | 000,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys

      < MD5 for: AHCIX86S.SYS >
      [2007/08/07 23:55:08 | 000,122,880 | ---- | M] (Promise Technology, Inc.) MD5=4283A0F3A9557EB133D2BA8979747A77 -- C:\ACER\Preload\Autorun\DRV\ATI VGA PCI-E\Packages\Drivers\SBDrv\SB6xx\RAID\LH\ahcix86s.sys

      < MD5 for: ATAPI.SYS >
      [2008/01/20 21:46:50 | 000,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
      [2009/04/11 02:15:02 | 000,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys

      < MD5 for: CNGAUDIT.DLL >
      [2006/11/02 06:16:48 | 000,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
      [2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
      [2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
      [2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll


      OTL Extras logfile created on: 7/20/2010 6:00:10 PM - Run 1
      OTL by OldTimer - Version 3.2.9.1 Folder = C:\Users\owner\Desktop
      64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
      Internet Explorer (Version = 8.0.6001.18928)
      Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

      4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
      8.00 Gb Paging File | 6.00 Gb Available in Paging File | 77.00% Paging File free
      Paging file location(s): ?:\pagefile.sys [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
      Drive C: | 286.54 Gb Total Space | 79.67 Gb Free Space | 27.80% Space Free | Partition Type: NTFS
      Drive D: | 289.63 Gb Total Space | 278.85 Gb Free Space | 96.28% Space Free | Partition Type: NTFS
      Drive E: | 612.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
      Drive F: | 139.82 Gb Total Space | 19.48 Gb Free Space | 13.93% Space Free | Partition Type: NTFS
      G: Drive not present or media not loaded
      H: Drive not present or media not loaded
      Drive I: | 139.77 Gb Total Space | 16.41 Gb Free Space | 11.74% Space Free | Partition Type: NTFS

      Computer Name: POOKLET
      Current User Name: owner
      Logged in as Administrator.

      Current Boot Mode: Normal
      Scan Mode: Current user
      Include 64bit Scans
      Company Name Whitelist: Off
      Skip Microsoft Files: Off
      File Age = 30 Days
      Output = Standard

      ========== Extra Registry (SafeList) ==========


      ========== File Associations ==========
      Hi,

      Please download Malwarebytes Anti-Malware from Here.


      Double Click mbam-setup.exe to install the application.
      • Make sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
      • If an update is found, it will download and install the latest version.
      • Once the program has loaded, select "Perform Quick Scan", then click Scan.
      • The scan may take some time to finish,so please be patient.
      • When the scan is complete, click OK, then Show Results to view the results.
      • Make sure that everything is checked, and click Remove Selected.
      • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
      • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
      • Copy&Paste the entire report in your next reply.
      Extra Note:
      If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.When I tried to install, it said "The setup files are corrupted. Please obtain a new copy of the program." Some version of this appears whenever I try to install anything.Hi,

      Download Dr.Web CureIt to the desktop:
      ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe
      • Double-click the launch.exe or cureit.exe file and Allow to run the express scan
      • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
      • Once the short scan has finished, just let it cure whatever it finds...

      o Now, go to Settings >> Change Settings
      o Go to Actions tab >> under Objects section, change the settings to below
      Infected objects - Cure
      Incurable objects - Report
      Suspicious objects - Report
      o Don't change any other settings
      • Start the scan again. This time, choose Complete Scan
      • Click the green arrow button at the right, and the scan will start.
      • After the scan finished, click Select all
      • Click on Cure and choose Report incurable (means take no actions.. Don't "move", or "rename" or "delete")
      • When the scan has finished, in the menu, click File and choose Save report list
      • Save the report to your Desktop. The report will be called DrWeb.csv
      • Post DrWeb.csv in your next reply (Open it as Notepad).. Do NOT reboot the computer yet..
      Okay, it took me FOREVER to get this to work, but it finally finished a scan. It still refuses to make the report, but it says I have problems in 22 files.

      In the launch files of everything in the Acer Games folder: Trojan.Downloader 1.5449
      Plus, three files listed as probably DLOADER.TROJAN

      These are all in my F drive. In order to get it to finish a scan, I had to delte thr files it found on my C drive, which were all of the same Acer Game files and a couple of Java ones. I didn't need the programs, so I just deleted the whole folders, and tried the scan again. Also, before deleting those files I suddenly couldn't access the internet, but now it's allowing me back on again.Hi,

      Please run a free online scan with the ESET Online Scanner
      Note: You will need to use Internet Explorer for this scan[/i]
      • Tick the box next to YES, I accept the Terms of Use
      • Click Start
      • When asked, allow the ActiveX control to install
      • Click Start
      • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
      • Click Scan (This scan can take several hours, so please be patient)
      • Once the scan is completed, you may close the window
      • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
      • Copy and paste that log as a reply to this topic
      While "Downloading Virus Signature Database", the program gives this message:
      "Can not get update. Is proxy configured?"Hi.

      Remove the Proxy setting in Internet explorer and/or in FireFox.

      In IE: Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

      In Firefox in Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection > Choose "No Proxy"

      Click the apply button and restart that computer in normal mode.The box you indicated was already not checked.Hi.

      Could you please re-run ComboFix?Comment removed. Do not post in the malware forum unless you need help. ~Sneakyone
      I am unable to download ComboFix. It says connection with the server was reset.
      325.

      Solve : need some help thanks?

      Answer»

      about the same i think but i'm thinking it might be the internet connectionAll looks GOOD on my end.

      To remove all of the tools we used and the files and folders they CREATED do the following:
      Double CLICK OTL.exe.

      • Click the CleanUp button.
      • Select Yes when the "Begin cleanup Process?" prompt appears.
      • If you are PROMPTED to Reboot during the cleanup, select Yes.
      • The tool will delete itself once it finishes.
      Note: If any tool, file or FOLDER (belonging to the program we have used) hasn't been deleted, please delete it manually.
      ok thanks for your help!
      326.

      Solve : Nasty trojan(s) redirecting, came from facebook, followed evilfantasy's steps?

      Answer»

      You're WELCOME.

      327.

      Solve : malware/virus help?

      Answer»

      How are things running now? So far, so good Ok. Let's do one more scan

      Please run a FREE online scan with the ESET Online Scanner
      Note: You will need to use INTERNET Explorer for this scan[/i]

      • Tick the box next to YES, I accept the Terms of Use
      • Click Start
      • When asked, allow the ACTIVEX control to install
      • Click Start
      • Make sure that the options Remove found threats and the option Scan UNWANTED applications is checked
      • Click Scan (This scan can take several hours, so please be patient)
      • Once the scan is completed, you may CLOSE the window
      • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
      • Copy and paste that log as a reply to this topic
      328.

      Solve : Malware infection?

      Answer»

      Hi,

      Download MBRCheck to your desktop.

      • Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
      • It will show a black screen with some data on it.
      • A report called MBRcheckxxxx.txt will be on your desktop
      • Open this report and post its content in your next reply.
      MBRCheck, version 1.1.1
      2010, AD

      \\.\C: --> \\.\PhysicalDrive0
      \\.\D: --> \\.\PhysicalDrive1
      \\.\E: --> \\.\PhysicalDrive1

      Size Device Name MBR Status
      ----------------------------------------------------------------------
      232 GB \\.\PhysicalDrive0 MBR Code Faked!
      232 GB \\.\PhysicalDrive1 Windows XP MBR code detected

      Found non-standard for infected MBR
      Enter 'Y' and hit entere for more options, or 'N' to exit: y

      Options:
      [1] Dump the MBR of a physical disk to file.
      [2] Restore the MBR of a phyical disk with a standard boot code
      [3] Exit

      Enter your choice:

      Hi,

      Run MBRCheck.exe
      • Run MBRCheck.exe
      • Wait until you see the following line: Enter 'Y' and hit ENTER for more options, or 'N' to exit:
      • Please push the 'Y' key and then press Enter
      • When program ask you Enter your choice: enter 2 and press the Enter key
      • Now the program will ask you "Enter the physical disk number to fix (0-99, -1 to cancel):"
      • Enter 0 and press the Enter key.
      • The program will show Available MBR codes:, followed by a list of operating systems. Please enter 1 for Windows XP, and then press Enter.
      • When asked Do you want to fix the MBR code? type in YES and press enter
      • Restart your PC.
      ok, restarted


      Hi,

      Could you please run MBRCheck again and post the log here, to be sure it is gone. MBRCheck, version 1.1.1
      2010, AD

      \\.\C: --> \\.\PhysicalDrive0
      \\.\D: --> \\.\PhysicalDrive1
      \\.\E: --> \\.\PhysicalDrive1

      Size Device Name MBR Status
      ----------------------------------------------------------------------
      232 GB \\.\PhysicalDrive0 Windows XP MBR code detected
      232 GB \\.\PhysicalDrive1 Windows XP MBR code detected

      Done! Press ENTER to exit....Hi,

      Please download ComboFix from BleepingComputer.com

      Alternate link: GeeksToGo.com

      Alternate link: Forospyware.com

      Rename ComboFix.exe to commy.exe before you save it to your Desktop
      • Disable your AntiVirus and AntiSpyware applications, usually VIA a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
      • Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
      • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
      • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console

      Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

      Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


      • Click on Yes, to continue scanning for malware.
      • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.
      Yay! It ran!

      Then automatically rebooted.

      Combofix log:

      ComboFix 10-07-21.02 - Toni 07/22/2010 2:11.4.2 - x86
      Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1181 [GMT -4:00]
      Running from: c:\documents and settings\Toni\desktop\commy.exe
      Command switches used :: /stepdel
      AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
      FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\Toni\Application Data\Sky-Banners
      c:\documents and settings\Toni\Application Data\Street-Ads
      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}
      c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor
      c:\windows\$NtUninstallMTF1011$
      c:\windows\TEMP\logishrd\LVPrcInj01.dll
      c:\documents and settings\Toni\Application Data\09f7619a.exe
      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome.manifest
      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\_cfg.js
      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\overlay.xul
      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\install.rdf
      c:\documents and settings\Toni\Start Menu\Antimalware Doctor.lnk
      c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk
      c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk
      c:\windows\$NtUninstallMTF1011$\apUninstall.exe
      c:\windows\$NtUninstallMTF1011$\zrpt.xml
      c:\windows\system32\ernel32.dll

      .
      ((((((((((((((((((((((((( Files Created from 2010-06-22 to 2010-07-22 )))))))))))))))))))))))))))))))
      .

      2010-07-21 13:54 . 2010-07-21 14:49--------d-----w-C:\commy21098c
      2010-07-21 11:25 . 2010-07-21 12:14--------d-----w-C:\commy
      2010-07-21 11:18 . 2010-07-21 11:18--------d-----w-C:\_OTL
      2010-07-20 10:57 . 2010-07-20 10:57--------d-----w-c:\program files\CCleaner
      2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\program files\Uniblue
      2010-07-18 16:03 . 2010-07-18 16:034057620----a-w-c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\registrybooster1-Wrapped.exe
      2010-07-18 16:03 . 2010-07-18 16:06--------d-----w-c:\documents and settings\Toni\Local Settings\Application Data\OpenCandy
      2010-07-18 16:03 . 2010-07-18 16:03331304----a-w-c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\DLMgr_3_1.6.44.exe
      2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\documents and settings\Toni\Application Data\OpenCandy
      2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\program files\Winamp Detect
      2010-07-18 16:01 . 2010-07-18 16:51--------d-----w-c:\documents and settings\Toni\Application Data\Winamp
      2010-07-18 16:01 . 2010-07-18 16:03--------d-----w-c:\program files\Winamp
      2010-07-17 15:37 . 2010-07-21 16:00--------d-----w-c:\documents and settings\Toni\Local Settings\Application Data\AskToolbar
      2010-07-15 16:36 . 2010-07-15 16:362944904----a-w-c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\r8se12d9.default\extensions\[emailprotected]\chrome\temp\askToolbar.exe
      2010-07-14 13:39 . 2010-07-14 13:39--------d-----w-c:\documents and settings\Toni\Application Data\Avery
      2010-07-14 13:24 . 2010-07-14 13:24--------d-----w-c:\program files\Avery Dennison
      2010-07-14 13:24 . 2010-07-14 13:24--------d-----w-c:\documents and settings\All Users\Application Data\Avery
      2010-07-14 13:10 . 2010-07-17 14:02--------d-----w-c:\program files\Ask.com
      2010-07-14 13:05 . 2010-07-14 13:0789582136----a-w-c:\program files\DesignPro5_5_Limited.exe
      2010-07-14 09:10 . 2010-06-14 14:31744448-c----w-c:\windows\system32\dllcache\helpsvc.exe
      2010-07-12 15:35 . 2010-07-12 15:352272----a-w-c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
      2010-07-10 14:39 . 2010-07-10 14:39--------d-----w-c:\documents and settings\Administrator\Application Data\Malwarebytes

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-07-22 06:17 . 2009-02-17 19:400----a-w-c:\windows\system32\drivers\lvuvc.hs
      2010-07-22 06:17 . 2009-02-17 19:380----a-w-c:\windows\system32\drivers\logiflt.iad
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k7
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k6
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k5
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k4
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k3
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k2
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k1
      2010-07-22 06:16 . 2009-01-28 19:20227220----a-w-c:\windows\system32\drivers\kmxcfg.u2k0
      2010-07-22 05:55 . 2010-04-09 13:471324----a-w-c:\windows\system32\d3d9caps.dat
      2010-07-20 19:53 . 2010-03-10 14:04--------d-----w-c:\program files\Malwarebytes' Anti-Malware
      2010-07-18 00:58 . 2009-08-13 23:13--------d-----w-c:\documents and settings\Toni\Application Data\Vso
      2010-07-16 20:20 . 2010-03-22 17:58--------d-----w-c:\program files\uTorrent
      2010-07-15 15:39 . 2009-01-30 16:19395984----a-w-c:\documents and settings\Toni\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2010-07-14 13:33 . 2009-01-28 14:38--------d--h--w-c:\program files\InstallShield Installation Information
      2010-07-10 23:55 . 2010-02-11 12:30--------d-----w-c:\documents and settings\All Users\Application Data\Roxio
      2010-06-25 18:51 . 2009-02-04 05:06--------d-----w-c:\documents and settings\Toni\Application Data\ZoomBrowser EX
      2010-06-25 18:50 . 2009-01-31 18:06--------d-----w-c:\documents and settings\All Users\Application Data\ZoomBrowser
      2010-06-19 16:23 . 2009-02-03 02:26--------d-----w-c:\documents and settings\Toni\Application Data\AdobeUM
      2010-06-17 15:46 . 2010-06-16 20:29--------d-----w-c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe
      2010-06-16 20:25 . 2009-01-30 07:02--------d-----w-c:\program files\Common Files\Adobe
      2010-06-16 19:40 . 2010-06-16 19:40--------d-----w-c:\program files\Adobe Media Player
      2010-06-16 19:39 . 2010-06-16 19:3910134----a-r-c:\documents and settings\Toni\Application Data\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
      2010-06-16 19:39 . 2010-06-16 19:39--------d-----w-c:\program files\My Company Name
      2010-06-16 19:34 . 2010-06-16 19:34--------d-----w-c:\program files\Common Files\Adobe AIR
      2010-06-16 16:18 . 2009-02-26 02:14--------d-----w-c:\documents and settings\Toni\Application Data\Move Networks
      2010-06-14 19:58 . 2010-06-14 19:58--------d-----w-c:\documents and settings\All Users\Application Data\vsosdk
      2010-06-14 14:31 . 2009-01-28 13:06744448----a-w-c:\windows\pchealth\helpctr\binaries\helpsvc.exe
      2010-06-13 18:14 . 2010-06-13 18:06--------d-----w-c:\program files\PeerGuardian2
      2010-06-07 00:19 . 2010-05-04 17:20--------d-----w-c:\program files\Microsoft Silverlight
      2010-06-03 16:35 . 2009-07-09 01:421561896----a-w-c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll
      2010-06-03 16:35 . 2009-01-28 18:24746216----a-w-c:\windows\system32\drivers\vetefile.sys
      2010-06-03 16:35 . 2009-01-28 18:24130280----a-w-c:\windows\system32\drivers\veteboot.sys
      2010-05-28 18:57 . 2009-01-28 18:2491472----a-w-c:\windows\system32\isafprod.dll
      2010-05-04 17:20 . 2004-08-04 12:00832512----a-w-c:\windows\system32\wininet.dll
      2010-05-04 17:20 . 2004-08-04 12:0078336----a-w-c:\windows\system32\ieencode.dll
      2010-05-04 17:20 . 2004-08-04 12:0017408----a-w-c:\windows\system32\corpol.dll
      2010-05-02 05:22 . 2004-08-04 12:001851264----a-w-c:\windows\system32\win32k.sys
      2010-04-29 19:39 . 2010-03-10 14:0438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
      2010-04-29 19:39 . 2010-03-10 14:0420952----a-w-c:\windows\system32\drivers\mbam.sys
      2010-02-02 17:02 . 2010-02-02 17:021438976----a-w-c:\program files\MoveMediaPlayerWin_071505000011.exe
      2010-02-01 01:43 . 2010-02-01 01:432107456----a-w-c:\program files\Install_Facebook_Plug-In_1.0.1.exe
      2010-01-31 12:26 . 2010-01-31 12:261533702----a-w-c:\program files\gburner27.exe
      2009-08-13 23:06 . 2009-08-13 23:057741336----a-w-c:\program files\DivX521XP2K_1.exe
      2009-08-13 22:54 . 2009-08-13 22:534526458----a-w-c:\program files\WinAVI_Video_Converter.exe
      2009-06-16 21:38 . 2009-06-16 21:382144584----a-w-c:\program files\InstallFirefoxPluginV3.exe
      2009-06-12 22:34 . 2009-06-12 22:3024527365----a-w-c:\program files\FreeVideoConverter.exe
      2009-03-05 21:24 . 2009-03-05 21:244909440----a-w-c:\program files\Silverlight.2.0.exe
      .

      ((((((((((((((((((((((((((((( [emailprotected]_11.57.58 )))))))))))))))))))))))))))))))))))))))))
      .
      + 2009-06-26 23:10 . 2009-06-26 23:1059904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90u.dll
      + 2009-06-26 23:10 . 2009-06-26 23:1059904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3249152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3249152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3257344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3265536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3245056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3240960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
      + 2009-07-12 05:07 . 2009-07-12 05:0757856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
      + 2009-07-12 05:19 . 2009-07-12 05:1969632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
      + 2009-07-11 23:41 . 2009-07-11 23:4197280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
      + 2010-07-22 06:17 . 2010-07-22 06:1716384 c:\windows\temp\Perflib_Perfdata_4e8.dat
      - 2008-04-14 00:12 . 2010-01-23 08:1146080 c:\windows\system32\tzchange.exe
      + 2008-04-14 00:12 . 2010-04-21 13:2846080 c:\windows\system32\tzchange.exe
      + 2006-03-25 00:00 . 2006-03-25 00:0045056 c:\windows\system32\spool\prtprocs\w32x86\iQ17cEI7q.dll
      + 2005-05-24 00:00 . 2005-05-24 00:0045056 c:\windows\system32\spool\prtprocs\w32x86\aAA17eI.dll
      + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\pxinsa64.exe
      - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\pxinsa64.exe
      + 2010-07-18 16:02 . 2009-04-28 20:2072176 c:\windows\system32\pxhpinst.exe
      + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\pxcpya64.exe
      - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\pxcpya64.exe
      + 2010-03-31 04:16 . 2010-03-31 04:1699176 c:\windows\system32\PresentationHostProxy.dll
      + 2004-08-04 12:00 . 2010-05-04 17:2044544 c:\windows\system32\pngfilt.dll
      - 2004-08-04 12:00 . 2010-03-11 12:3844544 c:\windows\system32\pngfilt.dll
      - 2004-08-04 12:00 . 2010-03-14 12:5378958 c:\windows\system32\perfc009.dat
      + 2004-08-04 12:00 . 2010-07-08 14:5278958 c:\windows\system32\perfc009.dat
      + 2009-11-07 05:07 . 2009-11-07 05:0749488 c:\windows\system32\netfxperf.dll
      + 2009-11-06 02:17 . 2009-11-06 02:1711600 c:\windows\system32\mui\0409\mscorees.dll
      - 2007-08-14 02:54 . 2010-03-11 12:3852224 c:\windows\system32\msfeedsbs.dll
      + 2007-08-14 02:54 . 2010-05-04 17:2052224 c:\windows\system32\msfeedsbs.dll
      + 2004-08-04 12:00 . 2010-05-04 17:2027648 c:\windows\system32\jsproxy.dll
      - 2004-08-04 12:00 . 2010-03-11 12:3827648 c:\windows\system32\jsproxy.dll
      + 2007-08-14 02:39 . 2010-05-04 12:3913824 c:\windows\system32\ieudinit.exe
      - 2007-08-14 02:39 . 2010-03-10 13:1813824 c:\windows\system32\ieudinit.exe
      - 2004-08-04 12:00 . 2010-03-11 12:3844544 c:\windows\system32\iernonce.dll
      + 2004-08-04 12:00 . 2010-05-04 17:2044544 c:\windows\system32\iernonce.dll
      - 2004-08-04 12:00 . 2010-03-10 13:1870656 c:\windows\system32\ie4uinit.exe
      + 2004-08-04 12:00 . 2010-05-04 12:3970656 c:\windows\system32\ie4uinit.exe
      - 2007-08-14 02:36 . 2010-03-11 12:3863488 c:\windows\system32\icardie.dll
      + 2007-08-14 02:36 . 2010-05-04 17:2063488 c:\windows\system32\icardie.dll
      - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\drvins64.exe
      + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\drvins64.exe
      + 2009-07-09 07:00 . 2009-07-09 07:0045200 c:\windows\system32\drivers\pxhelp20.sys
      - 2009-07-09 08:00 . 2009-07-09 08:0045200 c:\windows\system32\drivers\pxhelp20.sys
      + 2007-08-14 02:36 . 2010-05-04 17:2044544 c:\windows\system32\dllcache\pngfilt.dll
      - 2007-08-14 02:36 . 2010-03-11 12:3844544 c:\windows\system32\dllcache\pngfilt.dll
      + 2009-01-28 15:29 . 2010-05-04 17:2052224 c:\windows\system32\dllcache\msfeedsbs.dll
      - 2009-01-28 15:29 . 2010-03-11 12:3852224 c:\windows\system32\dllcache\msfeedsbs.dll
      + 2007-08-14 02:54 . 2010-05-04 17:2027648 c:\windows\system32\dllcache\jsproxy.dll
      - 2007-08-14 02:54 . 2010-03-11 12:3827648 c:\windows\system32\dllcache\jsproxy.dll
      - 2009-01-28 15:29 . 2010-03-10 13:1813824 c:\windows\system32\dllcache\ieudinit.exe
      + 2009-01-28 15:29 . 2010-05-04 12:3913824 c:\windows\system32\dllcache\ieudinit.exe
      - 2007-08-14 02:39 . 2010-03-11 12:3844544 c:\windows\system32\dllcache\iernonce.dll
      + 2007-08-14 02:39 . 2010-05-04 17:2044544 c:\windows\system32\dllcache\iernonce.dll
      + 2007-08-14 02:45 . 2010-05-04 17:2078336 c:\windows\system32\dllcache\ieencode.dll
      - 2007-08-14 02:45 . 2010-03-11 12:3878336 c:\windows\system32\dllcache\ieencode.dll
      + 2007-08-14 02:39 . 2010-05-04 12:3970656 c:\windows\system32\dllcache\ie4uinit.exe
      - 2007-08-14 02:39 . 2010-03-10 13:1870656 c:\windows\system32\dllcache\ie4uinit.exe
      + 2009-01-28 15:29 . 2010-05-04 17:2063488 c:\windows\system32\dllcache\icardie.dll
      - 2009-01-28 15:29 . 2010-03-11 12:3863488 c:\windows\system32\dllcache\icardie.dll
      + 2007-08-14 02:42 . 2010-05-04 17:2017408 c:\windows\system32\dllcache\corpol.dll
      - 2007-08-14 02:42 . 2010-03-11 12:3817408 c:\windows\system32\dllcache\corpol.dll
      + 2010-03-05 14:37 . 2010-03-05 14:3765536 c:\windows\system32\dllcache\asycfilt.dll
      - 2009-01-28 13:12 . 2009-03-24 23:1632768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
      + 2009-01-28 13:12 . 2010-07-10 19:4832768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
      - 2009-01-28 13:12 . 2009-03-24 23:1616384 c:\windows\system32\config\systemprofile\Cookies\index.dat
      + 2010-05-07 15:17 . 2010-07-10 19:4816384 c:\windows\system32\config\systemprofile\Cookies\index.dat
      + 2004-08-04 12:00 . 2010-03-05 14:3765536 c:\windows\system32\asycfilt.dll
      - 2008-07-30 03:16 . 2008-07-30 03:1632768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
      + 2010-04-08 03:48 . 2010-04-08 03:4832768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
      + 2010-03-23 09:31 . 2010-03-23 09:3130544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
      + 2010-04-01 15:42 . 2010-04-01 15:4281920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
      - 2008-05-28 04:49 . 2008-05-28 04:4977824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
      + 2010-03-31 18:51 . 2010-03-31 18:5177824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
      - 2008-05-28 04:49 . 2008-05-28 04:4986016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
      + 2010-03-31 18:51 . 2010-03-31 18:5186016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
      + 2010-03-31 18:51 . 2010-03-31 18:5181920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
      - 2008-05-28 04:49 . 2008-05-28 04:4981920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
      + 2010-03-31 19:32 . 2010-03-31 19:3232768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
      - 2008-05-28 05:30 . 2008-05-28 05:3032768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
      - 2003-02-21 03:19 . 2003-02-21 03:1924576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
      + 2010-03-31 19:32 . 2010-03-31 19:3224576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713688 c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_system.data.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713696 c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713672 c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0786864 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
      + 2010-06-16 19:40 . 2010-06-16 19:4022016 c:\windows\Installer\a68879.msi
      + 2010-06-16 19:34 . 2010-06-16 19:3422528 c:\windows\Installer\a6885b.msi
      + 2010-06-16 19:34 . 2010-06-16 19:3427648 c:\windows\Installer\a68853.msi
      + 2010-05-04 17:20 . 2010-05-04 17:2049664 c:\windows\Installer\35251f9.msi
      + 2010-06-15 00:32 . 2010-06-15 00:3221504 c:\windows\Installer\1712a6bf.msi
      + 2010-07-14 13:26 . 2010-07-14 13:2640960 c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\ARPPRODUCTICON.exe
      + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}\ARPPRODUCTICON.exe
      + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{D1A19B02-817E-4296-A45B-07853FD74D57}\ARPPRODUCTICON.exe
      + 2010-06-16 20:25 . 2010-06-16 20:2581920 c:\windows\Installer\{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}\ARPPRODUCTICON.exe
      + 2010-05-08 16:34 . 2010-05-08 16:3425214 c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
      + 2010-05-08 16:34 . 2010-05-08 16:3425214 c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\ARPPRODUCTICON.exe
      + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}\ARPPRODUCTICON.exe
      - 2009-01-28 18:22 . 2010-04-14 03:4723040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
      + 2009-01-28 18:22 . 2010-07-15 11:0423040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
      - 2009-01-28 18:22 . 2010-04-14 03:4761440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
      + 2009-01-28 18:22 . 2010-07-15 11:0461440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
      - 2009-01-28 18:22 . 2010-04-14 03:4727136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
      + 2009-01-28 18:22 . 2010-07-15 11:0427136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
      - 2009-01-28 18:22 . 2010-04-14 03:4711264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
      + 2009-01-28 18:22 . 2010-07-15 11:0411264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
      - 2009-01-28 18:22 . 2010-04-14 03:4712288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
      + 2009-01-28 18:22 . 2010-07-15 11:0412288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
      + 2010-06-10 12:21 . 2010-06-10 12:2138240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
      - 2010-04-14 03:51 . 2010-04-14 03:5138240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
      + 2010-05-04 17:26 . 2010-06-04 07:0149152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
      + 2010-06-16 19:43 . 2010-06-16 19:4381920 c:\windows\Installer\{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}\ARPPRODUCTICON.exe
      + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}\ARPPRODUCTICON.exe
      + 2010-06-16 19:33 . 2010-06-16 19:3310134 c:\windows\Installer\{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}\ARPPRODUCTICON.exe
      + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{08D2E121-7F6A-43EB-97FD-629B44903403}\ARPPRODUCTICON.exe
      + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}\ARPPRODUCTICON.exe
      + 2010-06-10 11:51 . 2010-03-11 12:3844544 c:\windows\ie7updates\KB982381-IE7\pngfilt.dll
      + 2010-06-10 11:51 . 2010-03-11 12:3852224 c:\windows\ie7updates\KB982381-IE7\msfeedsbs.dll
      + 2010-06-10 11:52 . 2010-03-11 12:3827648 c:\windows\ie7updates\KB982381-IE7\jsproxy.dll
      + 2010-06-10 11:52 . 2010-03-10 13:1813824 c:\windows\ie7updates\KB982381-IE7\ieudinit.exe
      + 2010-06-10 11:52 . 2010-03-11 12:3844544 c:\windows\ie7updates\KB982381-IE7\iernonce.dll
      + 2010-06-10 11:52 . 2010-03-11 12:3878336 c:\windows\ie7updates\KB982381-IE7\ieencode.dll
      + 2010-06-10 11:52 . 2010-03-10 13:1870656 c:\windows\ie7updates\KB982381-IE7\ie4uinit.exe
      + 2010-06-10 11:52 . 2010-03-11 12:3863488 c:\windows\ie7updates\KB982381-IE7\icardie.dll
      + 2010-06-10 11:52 . 2010-03-11 12:3817408 c:\windows\ie7updates\KB982381-IE7\corpol.dll
      + 2010-06-10 12:23 . 2010-06-10 12:2390112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_ee3c85bd\System.Drawing.Design.dll
      + 2010-06-10 12:23 . 2010-06-10 12:2361440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b31c6c1f\CustomMarshalers.dll
      + 2010-06-10 12:27 . 2010-06-10 12:2747616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\11b5c5344eb40eeb36a818d2824fe3a1\WindowsLiveWriter.ni.exe
      + 2010-06-10 12:29 . 2010-06-10 12:2999840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c69cc7d4e4fca9aa892ddfacc64cddb2\WindowsLive.Writer.Api.ni.dll
      + 2010-06-24 07:11 . 2010-06-24 07:1160928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ea1b4fbde0e772748c6ac42d627cf684\UIAutomationProvider.ni.dll
      + 2010-06-24 07:13 . 2010-06-24 07:1337888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\f46915dfc57bc7e49c5402e9b8f7ec18\System.Windows.Presentation.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:3137888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\1c1629f536fa9874ef08d09fb19ab0f0\System.Windows.Presentation.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:3136864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\1464c662c302ea6372a885161b983732\System.Web.DynamicData.Design.ni.dll
      + 2010-06-10 12:30 . 2010-06-10 12:3094208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\5d535ecadf77ac2d9278a1661beb2855\System.ComponentModel.DataAnnotations.ni.dll
      + 2010-06-10 12:12 . 2010-06-10 12:1247104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\e67992626a30603458b0df22841c2423\PresentationFontCache.ni.exe
      + 2010-06-24 07:09 . 2010-06-24 07:0947104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\18729514178d458aa1225dd068718d4e\PresentationFontCache.ni.exe
      + 2010-06-10 12:10 . 2010-06-10 12:1039424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\6be27d744e6e2bfc4b0e25bd2998ef7c\PresentationCFFRasterizer.ni.dll
      + 2010-06-24 07:08 . 2010-06-24 07:0839424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\0375dfa28e2f6ef7e89df9edede4b83d\PresentationCFFRasterizer.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:3155296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\4a52287444c36c89310856b38ff52fe0\Microsoft.Vsa.ni.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1377824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
      + 2010-06-10 12:10 . 2010-06-10 12:1032768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
      - 2009-01-28 15:35 . 2009-01-28 15:3532768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1381920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0481920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0481920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
      - 2009-10-17 07:14 . 2009-10-17 07:1481920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1332768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0432768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1312800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0412800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0428672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1328672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
      - 2009-10-17 07:14 . 2009-10-17 07:1477824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0436864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1336864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1377824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1313312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0413312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1310752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0410752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0472192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1372192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1369120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0469120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
      + 2010-06-10 12:23 . 2010-06-10 12:2381920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
      + 2010-05-26 07:00 . 2010-01-23 08:1146080 c:\windows\$NtUninstallKB981793$\tzchange.exe
      + 2010-05-26 07:00 . 2010-04-22 22:2116896 c:\windows\$NtUninstallKB981793$\spuninst\tzchange.dll
      + 2010-06-10 12:12 . 2008-04-14 00:1165024 c:\windows\$NtUninstallKB979482$\asycfilt.dll
      + 2010-06-10 11:52 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB982381-IE7\update\spcustom.dll
      + 2010-06-10 11:52 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB982381-IE7\spmsg.dll
      + 2010-05-04 17:20 . 2010-05-04 17:2044544 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\pngfilt.dll
      + 2010-05-04 17:20 . 2010-05-04 17:2052224 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msfeedsbs.dll
      + 2010-05-04 17:20 . 2010-05-04 17:2027648 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\jsproxy.dll
      + 2010-05-04 13:19 . 2010-05-04 13:1913824 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieudinit.exe
      + 2010-05-04 17:20 . 2010-05-04 17:2044544 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iernonce.dll
      + 2010-05-04 17:20 . 2010-05-04 17:2078336 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieencode.dll
      + 2010-05-04 13:19 . 2010-05-04 13:1970656 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ie4uinit.exe
      + 2010-05-04 17:20 . 2010-05-04 17:2063488 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\icardie.dll
      + 2010-05-04 17:19 . 2010-05-04 17:1917408 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\corpol.dll
      + 2010-06-10 12:28 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB980218\update\spcustom.dll
      + 2010-06-10 12:28 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB980218\spmsg.dll
      + 2010-06-10 12:23 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB980195\update\spcustom.dll
      + 2010-06-10 12:23 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB980195\spmsg.dll
      + 2010-06-10 12:19 . 2009-05-26 09:0126488 c:\windows\$hf_mig$\KB979559\update\spcustom.dll
      + 2010-06-10 12:19 . 2009-05-26 09:0117272 c:\windows\$hf_mig$\KB979559\spmsg.dll
      + 2010-06-10 12:12 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB979482\update\spcustom.dll
      + 2010-06-10 12:12 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB979482\spmsg.dll
      + 2010-03-05 14:52 . 2010-03-05 14:5265536 c:\windows\$hf_mig$\KB979482\SP3QFE\asycfilt.dll
      + 2010-05-13 07:01 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB978542\update\spcustom.dll
      + 2010-05-13 07:01 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB978542\spmsg.dll
      + 2010-06-10 12:12 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB975562\update\spcustom.dll
      + 2010-06-10 12:12 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB975562\spmsg.dll
      - 2009-10-17 07:13 . 2009-10-17 07:138192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
      + 2010-06-24 07:04 . 2010-06-24 07:048192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
      - 2009-06-23 08:00 . 2009-06-23 08:009200 c:\windows\system32\drivers\cdralw2k.sys
      + 2009-06-23 07:00 . 2009-06-23 07:009200 c:\windows\system32\drivers\cdralw2k.sys
      - 2009-06-23 08:00 . 2009-06-23 08:009072 c:\windows\system32\drivers\cdr4_xp.sys
      + 2009-06-23 07:00 . 2009-06-23 07:009072 c:\windows\system32\drivers\cdr4_xp.sys
      + 2010-07-14 13:26 . 2010-07-14 13:262238 c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\Shortcut1_71F6DF7DB6394FADBA93E6DF267AA44D.exe
      + 2009-01-28 18:22 . 2010-07-15 11:044096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
      - 2009-01-28 18:22 . 2010-04-14 03:474096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
      + 2010-06-24 07:04 . 2010-06-24 07:047168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
      - 2009-10-17 07:13 . 2009-10-17 07:137168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
      + 2010-06-24 07:04 . 2010-06-24 07:045632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
      - 2009-10-17 07:14 . 2009-10-17 07:145632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
      + 2010-06-24 07:04 . 2010-06-24 07:046656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
      - 2009-10-17 07:13 . 2009-10-17 07:136656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
      + 2010-06-24 07:04 . 2010-06-24 07:048192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
      - 2009-10-17 07:13 . 2009-10-17 07:138192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
      + 2009-06-26 23:07 . 2009-06-26 23:07653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcr90.dll
      + 2009-06-26 23:07 . 2009-06-26 23:07569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcp90.dll
      + 2009-06-26 23:10 . 2009-06-26 23:10225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcm90.dll
      + 2009-06-26 23:07 . 2009-06-26 23:07159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_35349982\atl90.dll
      + 2009-07-12 05:12 . 2009-07-12 05:12632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
      + 2009-07-12 05:09 . 2009-07-12 05:09554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
      + 2009-07-12 05:08 . 2009-07-12 05:08479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20233472 c:\windows\system32\webcheck.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38233472 c:\windows\system32\webcheck.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20105984 c:\windows\system32\url.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38105984 c:\windows\system32\url.dll
      + 2009-07-10 02:03 . 2009-07-10 02:03125424 c:\windows\system32\pxinsi64.exe
      - 2009-07-10 03:03 . 2009-07-10 03:03125424 c:\windows\system32\pxinsi64.exe
      - 2009-07-10 03:03 . 2009-07-10 03:03123888 c:\windows\system32\pxcpyi64.exe
      + 2009-07-10 02:03 . 2009-07-10 02:03123888 c:\windows\system32\pxcpyi64.exe
      + 2010-03-31 04:10 . 2010-03-31 04:10295264 c:\windows\system32\PresentationHost.exe
      - 2004-08-04 12:00 . 2010-03-14 12:53465072 c:\windows\system32\perfh009.dat
      + 2004-08-04 12:00 . 2010-07-08 14:52465072 c:\windows\system32\perfh009.dat
      + 2004-08-04 12:00 . 2010-05-04 17:20102912 c:\windows\system32\occache.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38102912 c:\windows\system32\occache.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20671232 c:\windows\system32\mstime.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38671232 c:\windows\system32\mstime.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38193024 c:\windows\system32\msrating.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20193024 c:\windows\system32\msrating.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38477696 c:\windows\system32\mshtmled.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20477696 c:\windows\system32\mshtmled.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38459264 c:\windows\system32\msfeeds.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20459264 c:\windows\system32\msfeeds.dll
      + 2009-11-07 05:07 . 2009-11-07 05:07297808 c:\windows\system32\mscoree.dll
      + 2010-06-16 20:25 . 2010-06-16 20:25223184 c:\windows\system32\Macromed\Flash\FlashUtil10g_Plugin.exe
      + 2010-06-16 19:43 . 2010-06-16 19:43223184 c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.exe
      + 2010-06-16 19:43 . 2010-06-16 19:43268240 c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.dll
      + 2009-01-28 13:06 . 2010-01-29 15:01691712 c:\windows\system32\inetcomm.dll
      - 2009-01-28 13:06 . 2008-04-11 19:04691712 c:\windows\system32\inetcomm.dll
      - 2007-08-14 02:34 . 2010-03-11 12:38268288 c:\windows\system32\iertutil.dll
      + 2007-08-14 02:34 . 2010-05-04 17:20268288 c:\windows\system32\iertutil.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20192512 c:\windows\system32\iepeers.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38192512 c:\windows\system32\iepeers.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38385024 c:\windows\system32\iedkcs32.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20385024 c:\windows\system32\iedkcs32.dll
      - 2007-07-11 20:27 . 2010-03-11 12:38380928 c:\windows\system32\ieapfltr.dll
      + 2007-07-11 20:27 . 2010-05-04 17:20380928 c:\windows\system32\ieapfltr.dll
      + 2004-08-04 12:00 . 2010-04-16 11:43161792 c:\windows\system32\ieakui.dll
      - 2004-08-04 12:00 . 2010-02-23 05:18161792 c:\windows\system32\ieakui.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20230400 c:\windows\system32\ieaksie.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38230400 c:\windows\system32\ieaksie.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20153088 c:\windows\system32\ieakeng.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38153088 c:\windows\system32\ieakeng.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38133120 c:\windows\system32\extmgr.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20133120 c:\windows\system32\extmgr.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38214528 c:\windows\system32\dxtrans.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20214528 c:\windows\system32\dxtrans.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38347136 c:\windows\system32\dxtmsft.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20347136 c:\windows\system32\dxtmsft.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20832512 c:\windows\system32\dllcache\wininet.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38832512 c:\windows\system32\dllcache\wininet.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20233472 c:\windows\system32\dllcache\webcheck.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38233472 c:\windows\system32\dllcache\webcheck.dll
      - 2007-08-14 02:44 . 2010-03-11 12:38105984 c:\windows\system32\dllcache\url.dll
      + 2007-08-14 02:44 . 2010-05-04 17:20105984 c:\windows\system32\dllcache\url.dll
      + 2007-08-14 02:44 . 2010-05-04 17:20102912 c:\windows\system32\dllcache\occache.dll
      - 2007-08-14 02:44 . 2010-03-11 12:38102912 c:\windows\system32\dllcache\occache.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38671232 c:\windows\system32\dllcache\mstime.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20671232 c:\windows\system32\dllcache\mstime.dll
      - 2007-08-14 02:44 . 2010-03-11 12:38193024 c:\windows\system32\dllcache\msrating.dll
      + 2007-08-14 02:44 . 2010-05-04 17:20193024 c:\windows\system32\dllcache\msrating.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20477696 c:\windows\system32\dllcache\mshtmled.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38477696 c:\windows\system32\dllcache\mshtmled.dll
      + 2009-01-28 15:29 . 2010-05-04 17:20459264 c:\windows\system32\dllcache\msfeeds.dll
      - 2009-01-28 15:29 . 2010-03-11 12:38459264 c:\windows\system32\dllcache\msfeeds.dll
      + 2009-01-28 14:49 . 2010-01-29 15:01691712 c:\windows\system32\dllcache\inetcomm.dll
      - 2009-01-28 14:49 . 2008-04-11 19:04691712 c:\windows\system32\dllcache\inetcomm.dll
      + 2007-08-14 02:43 . 2010-04-16 11:43634656 c:\windows\system32\dllcache\iexplore.exe
      + 2009-01-28 15:29 . 2010-05-04 17:20268288 c:\windows\system32\dllcache\iertutil.dll
      - 2009-01-28 15:29 . 2010-03-11 12:38268288 c:\windows\system32\dllcache\iertutil.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38192512 c:\windows\system32\dllcache\iepeers.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20192512 c:\windows\system32\dllcache\iepeers.dll
      - 2007-08-14 02:39 . 2010-03-11 12:38385024 c:\windows\system32\dllcache\iedkcs32.dll
      + 2007-08-14 02:39 . 2010-05-04 17:20385024 c:\windows\system32\dllcache\iedkcs32.dll
      - 2009-01-28 15:29 . 2010-03-11 12:38380928 c:\windows\system32\dllcache\ieapfltr.dll
      + 2009-01-28 15:29 . 2010-05-04 17:20380928 c:\windows\system32\dllcache\ieapfltr.dll
      + 2004-08-04 12:00 . 2010-04-16 11:43161792 c:\windows\system32\dllcache\ieakui.dll
      - 2004-08-04 12:00 . 2010-02-23 05:18161792 c:\windows\system32\dllcache\ieakui.dll
      + 2007-08-14 02:39 . 2010-05-04 17:20230400 c:\windows\system32\dllcache\ieaksie.dll
      - 2007-08-14 02:39 . 2010-03-11 12:38230400 c:\windows\system32\dllcache\ieaksie.dll
      - 2007-08-14 02:39 . 2010-03-11 12:38153088 c:\windows\system32\dllcache\ieakeng.dll
      + 2007-08-14 02:39 . 2010-05-04 17:20153088 c:\windows\system32\dllcache\ieakeng.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20133120 c:\windows\system32\dllcache\extmgr.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38133120 c:\windows\system32\dllcache\extmgr.dll
      + 2007-08-14 02:35 . 2010-05-04 17:20214528 c:\windows\system32\dllcache\dxtrans.dll
      - 2007-08-14 02:35 . 2010-03-11 12:38214528 c:\windows\system32\dllcache\dxtrans.dll
      + 2007-08-14 02:35 . 2010-05-04 17:20347136 c:\windows\system32\dllcache\dxtmsft.dll
      - 2007-08-14 02:35 . 2010-03-11 12:38347136 c:\windows\system32\dllcache\dxtmsft.dll
      + 2010-04-20 05:30 . 2010-04-20 05:30285696 c:\windows\system32\dllcache\atmfd.dll
      + 2009-01-28 14:40 . 2008-04-13 16:39142592 c:\windows\system32\dllcache\aec.sys
      - 2007-08-14 02:39 . 2010-03-11 12:38124928 c:\windows\system32\dllcache\advpack.dll
      + 2007-08-14 02:39 . 2010-05-04 17:20124928 c:\windows\system32\dllcache\advpack.dll
      - 2004-08-04 12:00 . 2008-04-14 00:09285696 c:\windows\system32\atmfd.dll
      + 2004-08-04 12:00 . 2010-04-20 05:30285696 c:\windows\system32\atmfd.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20124928 c:\windows\system32\advpack.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38124928 c:\windows\system32\advpack.dll
      + 2010-03-31 04:16 . 2010-03-31 04:16130408 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
      + 2010-04-08 03:48 . 2010-04-08 03:48970752 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
      - 2008-07-30 03:16 . 2008-07-30 03:16110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
      + 2010-04-08 03:48 . 2010-04-08 03:48110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
      + 2010-03-23 09:31 . 2010-03-23 09:31435024 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
      + 2010-02-09 16:22 . 2010-02-09 16:22258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
      - 2008-07-25 19:17 . 2008-07-25 19:17258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
      - 2008-05-28 04:49 . 2008-05-28 04:49102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
      + 2010-03-31 18:51 . 2010-03-31 18:51102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
      - 2008-05-28 04:48 . 2008-05-28 04:48315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
      + 2010-03-31 18:49 . 2010-03-31 18:49315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
      + 2010-03-31 19:32 . 2010-03-31 19:32258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
      - 2008-05-28 05:30 . 2008-05-28 05:30258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
      + 2010-06-10 12:22 . 2010-06-10 12:22200192 c:\windows\Installer\be07f0b.msi
      + 2010-02-25 04:14 . 2010-02-25 04:14543232 c:\windows\Installer\be07e85.msp
      + 2010-06-16 19:39 . 2010-06-16 19:39454144 c:\windows\Installer\a68871.msi
      + 2010-06-16 19:33 . 2010-06-16 19:33356352 c:\windows\Installer\a6884b.msi
      + 2010-06-16 19:32 . 2010-06-16 19:32315392 c:\windows\Installer\a68843.msi
      + 2010-06-16 19:32 . 2010-06-16 19:32316928 c:\windows\Installer\a6883b.msi
      + 2010-06-16 19:32 . 2010-06-16 19:32356864 c:\windows\Installer\a68833.msi
      + 2010-06-16 19:31 . 2010-06-16 19:31359424 c:\windows\Installer\a6882b.msi
      + 2010-06-16 19:31 . 2010-06-16 19:31356352Hi,

      Your log is cut off, could you please post the full log. Oh goodness...sorry!

      Here you go.

      ComboFix 10-07-21.02 - Toni 07/22/2010 2:11.4.2 - x86
      Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1181 [GMT -4:00]
      Running from: c:\documents and settings\Toni\desktop\commy.exe
      Command switches used :: /stepdel
      AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
      FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\Toni\Application Data\Sky-Banners
      c:\documents and settings\Toni\Application Data\Street-Ads
      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}
      c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor
      c:\windows\$NtUninstallMTF1011$
      c:\windows\TEMP\logishrd\LVPrcInj01.dll
      c:\documents and settings\Toni\Application Data\09f7619a.exe
      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome.manifest
      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\_cfg.js
      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\chrome\content\overlay.xul
      c:\documents and settings\Toni\Local Settings\Application Data\{5A4D470B-C9C5-4452-AC72-95292AA9588B}\install.rdf
      c:\documents and settings\Toni\Start Menu\Antimalware Doctor.lnk
      c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk
      c:\documents and settings\Toni\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk
      c:\windows\$NtUninstallMTF1011$\apUninstall.exe
      c:\windows\$NtUninstallMTF1011$\zrpt.xml
      c:\windows\system32\ernel32.dll

      .
      ((((((((((((((((((((((((( Files Created from 2010-06-22 to 2010-07-22 )))))))))))))))))))))))))))))))
      .

      2010-07-21 13:54 . 2010-07-21 14:49--------d-----w-C:\commy21098c
      2010-07-21 11:25 . 2010-07-21 12:14--------d-----w-C:\commy
      2010-07-21 11:18 . 2010-07-21 11:18--------d-----w-C:\_OTL
      2010-07-20 10:57 . 2010-07-20 10:57--------d-----w-c:\program files\CCleaner
      2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\program files\Uniblue
      2010-07-18 16:03 . 2010-07-18 16:034057620----a-w-c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\registrybooster1-Wrapped.exe
      2010-07-18 16:03 . 2010-07-18 16:06--------d-----w-c:\documents and settings\Toni\Local Settings\Application Data\OpenCandy
      2010-07-18 16:03 . 2010-07-18 16:03331304----a-w-c:\documents and settings\Toni\Application Data\OpenCandy\OpenCandy_DC2CFC93B76549EA900F7868E1DEF338\DLMgr_3_1.6.44.exe
      2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\documents and settings\Toni\Application Data\OpenCandy
      2010-07-18 16:03 . 2010-07-18 16:03--------d-----w-c:\program files\Winamp Detect
      2010-07-18 16:01 . 2010-07-18 16:51--------d-----w-c:\documents and settings\Toni\Application Data\Winamp
      2010-07-18 16:01 . 2010-07-18 16:03--------d-----w-c:\program files\Winamp
      2010-07-17 15:37 . 2010-07-21 16:00--------d-----w-c:\documents and settings\Toni\Local Settings\Application Data\AskToolbar
      2010-07-15 16:36 . 2010-07-15 16:362944904----a-w-c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\r8se12d9.default\extensions\[emailprotected]\chrome\temp\askToolbar.exe
      2010-07-14 13:39 . 2010-07-14 13:39--------d-----w-c:\documents and settings\Toni\Application Data\Avery
      2010-07-14 13:24 . 2010-07-14 13:24--------d-----w-c:\program files\Avery Dennison
      2010-07-14 13:24 . 2010-07-14 13:24--------d-----w-c:\documents and settings\All Users\Application Data\Avery
      2010-07-14 13:10 . 2010-07-17 14:02--------d-----w-c:\program files\Ask.com
      2010-07-14 13:05 . 2010-07-14 13:0789582136----a-w-c:\program files\DesignPro5_5_Limited.exe
      2010-07-14 09:10 . 2010-06-14 14:31744448-c----w-c:\windows\system32\dllcache\helpsvc.exe
      2010-07-12 15:35 . 2010-07-12 15:352272----a-w-c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
      2010-07-10 14:39 . 2010-07-10 14:39--------d-----w-c:\documents and settings\Administrator\Application Data\Malwarebytes

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-07-22 06:17 . 2009-02-17 19:400----a-w-c:\windows\system32\drivers\lvuvc.hs
      2010-07-22 06:17 . 2009-02-17 19:380----a-w-c:\windows\system32\drivers\logiflt.iad
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k7
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k6
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k5
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k4
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k3
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k2
      2010-07-22 06:16 . 2009-01-28 19:2064----a-w-c:\windows\system32\drivers\kmxcfg.u2k1
      2010-07-22 06:16 . 2009-01-28 19:20227220----a-w-c:\windows\system32\drivers\kmxcfg.u2k0
      2010-07-22 05:55 . 2010-04-09 13:471324----a-w-c:\windows\system32\d3d9caps.dat
      2010-07-20 19:53 . 2010-03-10 14:04--------d-----w-c:\program files\Malwarebytes' Anti-Malware
      2010-07-18 00:58 . 2009-08-13 23:13--------d-----w-c:\documents and settings\Toni\Application Data\Vso
      2010-07-16 20:20 . 2010-03-22 17:58--------d-----w-c:\program files\uTorrent
      2010-07-15 15:39 . 2009-01-30 16:19395984----a-w-c:\documents and settings\Toni\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2010-07-14 13:33 . 2009-01-28 14:38--------d--h--w-c:\program files\InstallShield Installation Information
      2010-07-10 23:55 . 2010-02-11 12:30--------d-----w-c:\documents and settings\All Users\Application Data\Roxio
      2010-06-25 18:51 . 2009-02-04 05:06--------d-----w-c:\documents and settings\Toni\Application Data\ZoomBrowser EX
      2010-06-25 18:50 . 2009-01-31 18:06--------d-----w-c:\documents and settings\All Users\Application Data\ZoomBrowser
      2010-06-19 16:23 . 2009-02-03 02:26--------d-----w-c:\documents and settings\Toni\Application Data\AdobeUM
      2010-06-17 15:46 . 2010-06-16 20:29--------d-----w-c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe
      2010-06-16 20:25 . 2009-01-30 07:02--------d-----w-c:\program files\Common Files\Adobe
      2010-06-16 19:40 . 2010-06-16 19:40--------d-----w-c:\program files\Adobe Media Player
      2010-06-16 19:39 . 2010-06-16 19:3910134----a-r-c:\documents and settings\Toni\Application Data\Microsoft\Installer\{024521CF-C07E-4F8E-8481-0D75695E03AF}\ARPPRODUCTICON.exe
      2010-06-16 19:39 . 2010-06-16 19:39--------d-----w-c:\program files\My Company Name
      2010-06-16 19:34 . 2010-06-16 19:34--------d-----w-c:\program files\Common Files\Adobe AIR
      2010-06-16 16:18 . 2009-02-26 02:14--------d-----w-c:\documents and settings\Toni\Application Data\Move Networks
      2010-06-14 19:58 . 2010-06-14 19:58--------d-----w-c:\documents and settings\All Users\Application Data\vsosdk
      2010-06-14 14:31 . 2009-01-28 13:06744448----a-w-c:\windows\pchealth\helpctr\binaries\helpsvc.exe
      2010-06-13 18:14 . 2010-06-13 18:06--------d-----w-c:\program files\PeerGuardian2
      2010-06-07 00:19 . 2010-05-04 17:20--------d-----w-c:\program files\Microsoft Silverlight
      2010-06-03 16:35 . 2009-07-09 01:421561896----a-w-c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll
      2010-06-03 16:35 . 2009-01-28 18:24746216----a-w-c:\windows\system32\drivers\vetefile.sys
      2010-06-03 16:35 . 2009-01-28 18:24130280----a-w-c:\windows\system32\drivers\veteboot.sys
      2010-05-28 18:57 . 2009-01-28 18:2491472----a-w-c:\windows\system32\isafprod.dll
      2010-05-04 17:20 . 2004-08-04 12:00832512----a-w-c:\windows\system32\wininet.dll
      2010-05-04 17:20 . 2004-08-04 12:0078336----a-w-c:\windows\system32\ieencode.dll
      2010-05-04 17:20 . 2004-08-04 12:0017408----a-w-c:\windows\system32\corpol.dll
      2010-05-02 05:22 . 2004-08-04 12:001851264----a-w-c:\windows\system32\win32k.sys
      2010-04-29 19:39 . 2010-03-10 14:0438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
      2010-04-29 19:39 . 2010-03-10 14:0420952----a-w-c:\windows\system32\drivers\mbam.sys
      2010-02-02 17:02 . 2010-02-02 17:021438976----a-w-c:\program files\MoveMediaPlayerWin_071505000011.exe
      2010-02-01 01:43 . 2010-02-01 01:432107456----a-w-c:\program files\Install_Facebook_Plug-In_1.0.1.exe
      2010-01-31 12:26 . 2010-01-31 12:261533702----a-w-c:\program files\gburner27.exe
      2009-08-13 23:06 . 2009-08-13 23:057741336----a-w-c:\program files\DivX521XP2K_1.exe
      2009-08-13 22:54 . 2009-08-13 22:534526458----a-w-c:\program files\WinAVI_Video_Converter.exe
      2009-06-16 21:38 . 2009-06-16 21:382144584----a-w-c:\program files\InstallFirefoxPluginV3.exe
      2009-06-12 22:34 . 2009-06-12 22:3024527365----a-w-c:\program files\FreeVideoConverter.exe
      2009-03-05 21:24 . 2009-03-05 21:244909440----a-w-c:\program files\Silverlight.2.0.exe
      .

      ((((((((((((((((((((((((((((( [emailprotected]_11.57.58 )))))))))))))))))))))))))))))))))))))))))
      .
      + 2009-06-26 23:10 . 2009-06-26 23:1059904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90u.dll
      + 2009-06-26 23:10 . 2009-06-26 23:1059904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3249152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3249152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3261440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3257344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3265536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3245056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
      + 2009-07-12 00:32 . 2009-07-12 00:3240960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
      + 2009-07-12 05:07 . 2009-07-12 05:0757856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
      + 2009-07-12 05:19 . 2009-07-12 05:1969632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
      + 2009-07-11 23:41 . 2009-07-11 23:4197280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
      + 2010-07-22 06:17 . 2010-07-22 06:1716384 c:\windows\temp\Perflib_Perfdata_4e8.dat
      - 2008-04-14 00:12 . 2010-01-23 08:1146080 c:\windows\system32\tzchange.exe
      + 2008-04-14 00:12 . 2010-04-21 13:2846080 c:\windows\system32\tzchange.exe
      + 2006-03-25 00:00 . 2006-03-25 00:0045056 c:\windows\system32\spool\prtprocs\w32x86\iQ17cEI7q.dll
      + 2005-05-24 00:00 . 2005-05-24 00:0045056 c:\windows\system32\spool\prtprocs\w32x86\aAA17eI.dll
      + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\pxinsa64.exe
      - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\pxinsa64.exe
      + 2010-07-18 16:02 . 2009-04-28 20:2072176 c:\windows\system32\pxhpinst.exe
      + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\pxcpya64.exe
      - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\pxcpya64.exe
      + 2010-03-31 04:16 . 2010-03-31 04:1699176 c:\windows\system32\PresentationHostProxy.dll
      + 2004-08-04 12:00 . 2010-05-04 17:2044544 c:\windows\system32\pngfilt.dll
      - 2004-08-04 12:00 . 2010-03-11 12:3844544 c:\windows\system32\pngfilt.dll
      - 2004-08-04 12:00 . 2010-03-14 12:5378958 c:\windows\system32\perfc009.dat
      + 2004-08-04 12:00 . 2010-07-08 14:5278958 c:\windows\system32\perfc009.dat
      + 2009-11-07 05:07 . 2009-11-07 05:0749488 c:\windows\system32\netfxperf.dll
      + 2009-11-06 02:17 . 2009-11-06 02:1711600 c:\windows\system32\mui\0409\mscorees.dll
      - 2007-08-14 02:54 . 2010-03-11 12:3852224 c:\windows\system32\msfeedsbs.dll
      + 2007-08-14 02:54 . 2010-05-04 17:2052224 c:\windows\system32\msfeedsbs.dll
      + 2004-08-04 12:00 . 2010-05-04 17:2027648 c:\windows\system32\jsproxy.dll
      - 2004-08-04 12:00 . 2010-03-11 12:3827648 c:\windows\system32\jsproxy.dll
      + 2007-08-14 02:39 . 2010-05-04 12:3913824 c:\windows\system32\ieudinit.exe
      - 2007-08-14 02:39 . 2010-03-10 13:1813824 c:\windows\system32\ieudinit.exe
      - 2004-08-04 12:00 . 2010-03-11 12:3844544 c:\windows\system32\iernonce.dll
      + 2004-08-04 12:00 . 2010-05-04 17:2044544 c:\windows\system32\iernonce.dll
      - 2004-08-04 12:00 . 2010-03-10 13:1870656 c:\windows\system32\ie4uinit.exe
      + 2004-08-04 12:00 . 2010-05-04 12:3970656 c:\windows\system32\ie4uinit.exe
      - 2007-08-14 02:36 . 2010-03-11 12:3863488 c:\windows\system32\icardie.dll
      + 2007-08-14 02:36 . 2010-05-04 17:2063488 c:\windows\system32\icardie.dll
      - 2009-07-10 03:03 . 2009-07-10 03:0368080 c:\windows\system32\drvins64.exe
      + 2009-07-10 02:03 . 2009-07-10 02:0368080 c:\windows\system32\drvins64.exe
      + 2009-07-09 07:00 . 2009-07-09 07:0045200 c:\windows\system32\drivers\pxhelp20.sys
      - 2009-07-09 08:00 . 2009-07-09 08:0045200 c:\windows\system32\drivers\pxhelp20.sys
      + 2007-08-14 02:36 . 2010-05-04 17:2044544 c:\windows\system32\dllcache\pngfilt.dll
      - 2007-08-14 02:36 . 2010-03-11 12:3844544 c:\windows\system32\dllcache\pngfilt.dll
      + 2009-01-28 15:29 . 2010-05-04 17:2052224 c:\windows\system32\dllcache\msfeedsbs.dll
      - 2009-01-28 15:29 . 2010-03-11 12:3852224 c:\windows\system32\dllcache\msfeedsbs.dll
      + 2007-08-14 02:54 . 2010-05-04 17:2027648 c:\windows\system32\dllcache\jsproxy.dll
      - 2007-08-14 02:54 . 2010-03-11 12:3827648 c:\windows\system32\dllcache\jsproxy.dll
      - 2009-01-28 15:29 . 2010-03-10 13:1813824 c:\windows\system32\dllcache\ieudinit.exe
      + 2009-01-28 15:29 . 2010-05-04 12:3913824 c:\windows\system32\dllcache\ieudinit.exe
      - 2007-08-14 02:39 . 2010-03-11 12:3844544 c:\windows\system32\dllcache\iernonce.dll
      + 2007-08-14 02:39 . 2010-05-04 17:2044544 c:\windows\system32\dllcache\iernonce.dll
      + 2007-08-14 02:45 . 2010-05-04 17:2078336 c:\windows\system32\dllcache\ieencode.dll
      - 2007-08-14 02:45 . 2010-03-11 12:3878336 c:\windows\system32\dllcache\ieencode.dll
      + 2007-08-14 02:39 . 2010-05-04 12:3970656 c:\windows\system32\dllcache\ie4uinit.exe
      - 2007-08-14 02:39 . 2010-03-10 13:1870656 c:\windows\system32\dllcache\ie4uinit.exe
      + 2009-01-28 15:29 . 2010-05-04 17:2063488 c:\windows\system32\dllcache\icardie.dll
      - 2009-01-28 15:29 . 2010-03-11 12:3863488 c:\windows\system32\dllcache\icardie.dll
      + 2007-08-14 02:42 . 2010-05-04 17:2017408 c:\windows\system32\dllcache\corpol.dll
      - 2007-08-14 02:42 . 2010-03-11 12:3817408 c:\windows\system32\dllcache\corpol.dll
      + 2010-03-05 14:37 . 2010-03-05 14:3765536 c:\windows\system32\dllcache\asycfilt.dll
      - 2009-01-28 13:12 . 2009-03-24 23:1632768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
      + 2009-01-28 13:12 . 2010-07-10 19:4832768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
      - 2009-01-28 13:12 . 2009-03-24 23:1616384 c:\windows\system32\config\systemprofile\Cookies\index.dat
      + 2010-05-07 15:17 . 2010-07-10 19:4816384 c:\windows\system32\config\systemprofile\Cookies\index.dat
      + 2004-08-04 12:00 . 2010-03-05 14:3765536 c:\windows\system32\asycfilt.dll
      - 2008-07-30 03:16 . 2008-07-30 03:1632768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
      + 2010-04-08 03:48 . 2010-04-08 03:4832768 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll
      + 2010-03-23 09:31 . 2010-03-23 09:3130544 c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
      + 2010-04-01 15:42 . 2010-04-01 15:4281920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
      - 2008-05-28 04:49 . 2008-05-28 04:4977824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
      + 2010-03-31 18:51 . 2010-03-31 18:5177824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
      - 2008-05-28 04:49 . 2008-05-28 04:4986016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
      + 2010-03-31 18:51 . 2010-03-31 18:5186016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
      + 2010-03-31 18:51 . 2010-03-31 18:5181920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
      - 2008-05-28 04:49 . 2008-05-28 04:4981920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
      + 2010-03-31 19:32 . 2010-03-31 19:3232768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
      - 2008-05-28 05:30 . 2008-05-28 05:3032768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
      - 2003-02-21 03:19 . 2003-02-21 03:1924576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
      + 2010-03-31 19:32 . 2010-03-31 19:3224576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\SharedReg12.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713648 c:\windows\Microsoft.NET\Framework\sbscmp10.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713688 c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_system.data.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713696 c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713656 c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713672 c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0713664 c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll
      + 2009-11-07 05:07 . 2009-11-07 05:0786864 c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe
      + 2010-06-16 19:40 . 2010-06-16 19:4022016 c:\windows\Installer\a68879.msi
      + 2010-06-16 19:34 . 2010-06-16 19:3422528 c:\windows\Installer\a6885b.msi
      + 2010-06-16 19:34 . 2010-06-16 19:3427648 c:\windows\Installer\a68853.msi
      + 2010-05-04 17:20 . 2010-05-04 17:2049664 c:\windows\Installer\35251f9.msi
      + 2010-06-15 00:32 . 2010-06-15 00:3221504 c:\windows\Installer\1712a6bf.msi
      + 2010-07-14 13:26 . 2010-07-14 13:2640960 c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\ARPPRODUCTICON.exe
      + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}\ARPPRODUCTICON.exe
      + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{D1A19B02-817E-4296-A45B-07853FD74D57}\ARPPRODUCTICON.exe
      + 2010-06-16 20:25 . 2010-06-16 20:2581920 c:\windows\Installer\{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}\ARPPRODUCTICON.exe
      + 2010-05-08 16:34 . 2010-05-08 16:3425214 c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
      + 2010-05-08 16:34 . 2010-05-08 16:3425214 c:\windows\Installer\{961034C0-58DF-11DF-97FD-005056806466}\ARPPRODUCTICON.exe
      + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}\ARPPRODUCTICON.exe
      - 2009-01-28 18:22 . 2010-04-14 03:4723040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
      + 2009-01-28 18:22 . 2010-07-15 11:0423040 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
      - 2009-01-28 18:22 . 2010-04-14 03:4761440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
      + 2009-01-28 18:22 . 2010-07-15 11:0461440 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
      - 2009-01-28 18:22 . 2010-04-14 03:4727136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
      + 2009-01-28 18:22 . 2010-07-15 11:0427136 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
      - 2009-01-28 18:22 . 2010-04-14 03:4711264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
      + 2009-01-28 18:22 . 2010-07-15 11:0411264 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
      - 2009-01-28 18:22 . 2010-04-14 03:4712288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
      + 2009-01-28 18:22 . 2010-07-15 11:0412288 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
      + 2010-06-10 12:21 . 2010-06-10 12:2138240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
      - 2010-04-14 03:51 . 2010-04-14 03:5138240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
      + 2010-05-04 17:26 . 2010-06-04 07:0149152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
      + 2010-06-16 19:43 . 2010-06-16 19:4381920 c:\windows\Installer\{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}\ARPPRODUCTICON.exe
      + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}\ARPPRODUCTICON.exe
      + 2010-06-16 19:33 . 2010-06-16 19:3310134 c:\windows\Installer\{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}\ARPPRODUCTICON.exe
      + 2010-06-16 19:31 . 2010-06-16 19:3110134 c:\windows\Installer\{08D2E121-7F6A-43EB-97FD-629B44903403}\ARPPRODUCTICON.exe
      + 2010-06-16 19:32 . 2010-06-16 19:3210134 c:\windows\Installer\{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}\ARPPRODUCTICON.exe
      + 2010-06-10 11:51 . 2010-03-11 12:3844544 c:\windows\ie7updates\KB982381-IE7\pngfilt.dll
      + 2010-06-10 11:51 . 2010-03-11 12:3852224 c:\windows\ie7updates\KB982381-IE7\msfeedsbs.dll
      + 2010-06-10 11:52 . 2010-03-11 12:3827648 c:\windows\ie7updates\KB982381-IE7\jsproxy.dll
      + 2010-06-10 11:52 . 2010-03-10 13:1813824 c:\windows\ie7updates\KB982381-IE7\ieudinit.exe
      + 2010-06-10 11:52 . 2010-03-11 12:3844544 c:\windows\ie7updates\KB982381-IE7\iernonce.dll
      + 2010-06-10 11:52 . 2010-03-11 12:3878336 c:\windows\ie7updates\KB982381-IE7\ieencode.dll
      + 2010-06-10 11:52 . 2010-03-10 13:1870656 c:\windows\ie7updates\KB982381-IE7\ie4uinit.exe
      + 2010-06-10 11:52 . 2010-03-11 12:3863488 c:\windows\ie7updates\KB982381-IE7\icardie.dll
      + 2010-06-10 11:52 . 2010-03-11 12:3817408 c:\windows\ie7updates\KB982381-IE7\corpol.dll
      + 2010-06-10 12:23 . 2010-06-10 12:2390112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_ee3c85bd\System.Drawing.Design.dll
      + 2010-06-10 12:23 . 2010-06-10 12:2361440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_b31c6c1f\CustomMarshalers.dll
      + 2010-06-10 12:27 . 2010-06-10 12:2747616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\11b5c5344eb40eeb36a818d2824fe3a1\WindowsLiveWriter.ni.exe
      + 2010-06-10 12:29 . 2010-06-10 12:2999840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c69cc7d4e4fca9aa892ddfacc64cddb2\WindowsLive.Writer.Api.ni.dll
      + 2010-06-24 07:11 . 2010-06-24 07:1160928 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\ea1b4fbde0e772748c6ac42d627cf684\UIAutomationProvider.ni.dll
      + 2010-06-24 07:13 . 2010-06-24 07:1337888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\f46915dfc57bc7e49c5402e9b8f7ec18\System.Windows.Presentation.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:3137888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\1c1629f536fa9874ef08d09fb19ab0f0\System.Windows.Presentation.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:3136864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\1464c662c302ea6372a885161b983732\System.Web.DynamicData.Design.ni.dll
      + 2010-06-10 12:30 . 2010-06-10 12:3094208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\5d535ecadf77ac2d9278a1661beb2855\System.ComponentModel.DataAnnotations.ni.dll
      + 2010-06-10 12:12 . 2010-06-10 12:1247104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\e67992626a30603458b0df22841c2423\PresentationFontCache.ni.exe
      + 2010-06-24 07:09 . 2010-06-24 07:0947104 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\18729514178d458aa1225dd068718d4e\PresentationFontCache.ni.exe
      + 2010-06-10 12:10 . 2010-06-10 12:1039424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\6be27d744e6e2bfc4b0e25bd2998ef7c\PresentationCFFRasterizer.ni.dll
      + 2010-06-24 07:08 . 2010-06-24 07:0839424 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\0375dfa28e2f6ef7e89df9edede4b83d\PresentationCFFRasterizer.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:3155296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\4a52287444c36c89310856b38ff52fe0\Microsoft.Vsa.ni.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1377824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
      + 2010-06-10 12:10 . 2010-06-10 12:1032768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
      - 2009-01-28 15:35 . 2009-01-28 15:3532768 c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1381920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0481920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0481920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
      - 2009-10-17 07:14 . 2009-10-17 07:1481920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1332768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0432768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1312800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0412800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0428672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1328672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
      - 2009-10-17 07:14 . 2009-10-17 07:1477824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0436864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1336864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1377824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0477824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1313312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0413312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1310752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0410752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0472192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1372192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
      - 2009-10-17 07:13 . 2009-10-17 07:1369120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
      + 2010-06-24 07:04 . 2010-06-24 07:0469120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
      + 2010-06-10 12:23 . 2010-06-10 12:2381920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
      + 2010-05-26 07:00 . 2010-01-23 08:1146080 c:\windows\$NtUninstallKB981793$\tzchange.exe
      + 2010-05-26 07:00 . 2010-04-22 22:2116896 c:\windows\$NtUninstallKB981793$\spuninst\tzchange.dll
      + 2010-06-10 12:12 . 2008-04-14 00:1165024 c:\windows\$NtUninstallKB979482$\asycfilt.dll
      + 2010-06-10 11:52 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB982381-IE7\update\spcustom.dll
      + 2010-06-10 11:52 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB982381-IE7\spmsg.dll
      + 2010-05-04 17:20 . 2010-05-04 17:2044544 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\pngfilt.dll
      + 2010-05-04 17:20 . 2010-05-04 17:2052224 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msfeedsbs.dll
      + 2010-05-04 17:20 . 2010-05-04 17:2027648 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\jsproxy.dll
      + 2010-05-04 13:19 . 2010-05-04 13:1913824 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieudinit.exe
      + 2010-05-04 17:20 . 2010-05-04 17:2044544 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iernonce.dll
      + 2010-05-04 17:20 . 2010-05-04 17:2078336 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieencode.dll
      + 2010-05-04 13:19 . 2010-05-04 13:1970656 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ie4uinit.exe
      + 2010-05-04 17:20 . 2010-05-04 17:2063488 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\icardie.dll
      + 2010-05-04 17:19 . 2010-05-04 17:1917408 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\corpol.dll
      + 2010-06-10 12:28 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB980218\update\spcustom.dll
      + 2010-06-10 12:28 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB980218\spmsg.dll
      + 2010-06-10 12:23 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB980195\update\spcustom.dll
      + 2010-06-10 12:23 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB980195\spmsg.dll
      + 2010-06-10 12:19 . 2009-05-26 09:0126488 c:\windows\$hf_mig$\KB979559\update\spcustom.dll
      + 2010-06-10 12:19 . 2009-05-26 09:0117272 c:\windows\$hf_mig$\KB979559\spmsg.dll
      + 2010-06-10 12:12 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB979482\update\spcustom.dll
      + 2010-06-10 12:12 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB979482\spmsg.dll
      + 2010-03-05 14:52 . 2010-03-05 14:5265536 c:\windows\$hf_mig$\KB979482\SP3QFE\asycfilt.dll
      + 2010-05-13 07:01 . 2009-05-26 11:4026488 c:\windows\$hf_mig$\KB978542\update\spcustom.dll
      + 2010-05-13 07:01 . 2009-05-26 11:4017272 c:\windows\$hf_mig$\KB978542\spmsg.dll
      + 2010-06-10 12:12 . 2008-07-08 13:0226488 c:\windows\$hf_mig$\KB975562\update\spcustom.dll
      + 2010-06-10 12:12 . 2008-07-08 13:0217272 c:\windows\$hf_mig$\KB975562\spmsg.dll
      - 2009-10-17 07:13 . 2009-10-17 07:138192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
      + 2010-06-24 07:04 . 2010-06-24 07:048192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
      - 2009-06-23 08:00 . 2009-06-23 08:009200 c:\windows\system32\drivers\cdralw2k.sys
      + 2009-06-23 07:00 . 2009-06-23 07:009200 c:\windows\system32\drivers\cdralw2k.sys
      - 2009-06-23 08:00 . 2009-06-23 08:009072 c:\windows\system32\drivers\cdr4_xp.sys
      + 2009-06-23 07:00 . 2009-06-23 07:009072 c:\windows\system32\drivers\cdr4_xp.sys
      + 2010-07-14 13:26 . 2010-07-14 13:262238 c:\windows\Installer\{FB98D390-54A4-4CD1-93D3-FBC96A6F07A3}\Shortcut1_71F6DF7DB6394FADBA93E6DF267AA44D.exe
      + 2009-01-28 18:22 . 2010-07-15 11:044096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
      - 2009-01-28 18:22 . 2010-04-14 03:474096 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
      + 2010-06-24 07:04 . 2010-06-24 07:047168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
      - 2009-10-17 07:13 . 2009-10-17 07:137168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
      + 2010-06-24 07:04 . 2010-06-24 07:045632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
      - 2009-10-17 07:14 . 2009-10-17 07:145632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
      + 2010-06-24 07:04 . 2010-06-24 07:046656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
      - 2009-10-17 07:13 . 2009-10-17 07:136656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
      + 2010-06-24 07:04 . 2010-06-24 07:048192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
      - 2009-10-17 07:13 . 2009-10-17 07:138192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
      + 2009-06-26 23:07 . 2009-06-26 23:07653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcr90.dll
      + 2009-06-26 23:07 . 2009-06-26 23:07569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcp90.dll
      + 2009-06-26 23:10 . 2009-06-26 23:10225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcm90.dll
      + 2009-06-26 23:07 . 2009-06-26 23:07159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_35349982\atl90.dll
      + 2009-07-12 05:12 . 2009-07-12 05:12632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
      + 2009-07-12 05:09 . 2009-07-12 05:09554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
      + 2009-07-12 05:08 . 2009-07-12 05:08479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20233472 c:\windows\system32\webcheck.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38233472 c:\windows\system32\webcheck.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20105984 c:\windows\system32\url.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38105984 c:\windows\system32\url.dll
      + 2009-07-10 02:03 . 2009-07-10 02:03125424 c:\windows\system32\pxinsi64.exe
      - 2009-07-10 03:03 . 2009-07-10 03:03125424 c:\windows\system32\pxinsi64.exe
      - 2009-07-10 03:03 . 2009-07-10 03:03123888 c:\windows\system32\pxcpyi64.exe
      + 2009-07-10 02:03 . 2009-07-10 02:03123888 c:\windows\system32\pxcpyi64.exe
      + 2010-03-31 04:10 . 2010-03-31 04:10295264 c:\windows\system32\PresentationHost.exe
      - 2004-08-04 12:00 . 2010-03-14 12:53465072 c:\windows\system32\perfh009.dat
      + 2004-08-04 12:00 . 2010-07-08 14:52465072 c:\windows\system32\perfh009.dat
      + 2004-08-04 12:00 . 2010-05-04 17:20102912 c:\windows\system32\occache.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38102912 c:\windows\system32\occache.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20671232 c:\windows\system32\mstime.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38671232 c:\windows\system32\mstime.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38193024 c:\windows\system32\msrating.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20193024 c:\windows\system32\msrating.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38477696 c:\windows\system32\mshtmled.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20477696 c:\windows\system32\mshtmled.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38459264 c:\windows\system32\msfeeds.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20459264 c:\windows\system32\msfeeds.dll
      + 2009-11-07 05:07 . 2009-11-07 05:07297808 c:\windows\system32\mscoree.dll
      + 2010-06-16 20:25 . 2010-06-16 20:25223184 c:\windows\system32\Macromed\Flash\FlashUtil10g_Plugin.exe
      + 2010-06-16 19:43 . 2010-06-16 19:43223184 c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.exe
      + 2010-06-16 19:43 . 2010-06-16 19:43268240 c:\windows\system32\Macromed\Flash\FlashUtil10g_ActiveX.dll
      + 2009-01-28 13:06 . 2010-01-29 15:01691712 c:\windows\system32\inetcomm.dll
      - 2009-01-28 13:06 . 2008-04-11 19:04691712 c:\windows\system32\inetcomm.dll
      - 2007-08-14 02:34 . 2010-03-11 12:38268288 c:\windows\system32\iertutil.dll
      + 2007-08-14 02:34 . 2010-05-04 17:20268288 c:\windows\system32\iertutil.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20192512 c:\windows\system32\iepeers.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38192512 c:\windows\system32\iepeers.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38385024 c:\windows\system32\iedkcs32.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20385024 c:\windows\system32\iedkcs32.dll
      - 2007-07-11 20:27 . 2010-03-11 12:38380928 c:\windows\system32\ieapfltr.dll
      + 2007-07-11 20:27 . 2010-05-04 17:20380928 c:\windows\system32\ieapfltr.dll
      + 2004-08-04 12:00 . 2010-04-16 11:43161792 c:\windows\system32\ieakui.dll
      - 2004-08-04 12:00 . 2010-02-23 05:18161792 c:\windows\system32\ieakui.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20230400 c:\windows\system32\ieaksie.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38230400 c:\windows\system32\ieaksie.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20153088 c:\windows\system32\ieakeng.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38153088 c:\windows\system32\ieakeng.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38133120 c:\windows\system32\extmgr.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20133120 c:\windows\system32\extmgr.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38214528 c:\windows\system32\dxtrans.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20214528 c:\windows\system32\dxtrans.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38347136 c:\windows\system32\dxtmsft.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20347136 c:\windows\system32\dxtmsft.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20832512 c:\windows\system32\dllcache\wininet.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38832512 c:\windows\system32\dllcache\wininet.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20233472 c:\windows\system32\dllcache\webcheck.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38233472 c:\windows\system32\dllcache\webcheck.dll
      - 2007-08-14 02:44 . 2010-03-11 12:38105984 c:\windows\system32\dllcache\url.dll
      + 2007-08-14 02:44 . 2010-05-04 17:20105984 c:\windows\system32\dllcache\url.dll
      + 2007-08-14 02:44 . 2010-05-04 17:20102912 c:\windows\system32\dllcache\occache.dll
      - 2007-08-14 02:44 . 2010-03-11 12:38102912 c:\windows\system32\dllcache\occache.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38671232 c:\windows\system32\dllcache\mstime.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20671232 c:\windows\system32\dllcache\mstime.dll
      - 2007-08-14 02:44 . 2010-03-11 12:38193024 c:\windows\system32\dllcache\msrating.dll
      + 2007-08-14 02:44 . 2010-05-04 17:20193024 c:\windows\system32\dllcache\msrating.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20477696 c:\windows\system32\dllcache\mshtmled.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38477696 c:\windows\system32\dllcache\mshtmled.dll
      + 2009-01-28 15:29 . 2010-05-04 17:20459264 c:\windows\system32\dllcache\msfeeds.dll
      - 2009-01-28 15:29 . 2010-03-11 12:38459264 c:\windows\system32\dllcache\msfeeds.dll
      + 2009-01-28 14:49 . 2010-01-29 15:01691712 c:\windows\system32\dllcache\inetcomm.dll
      - 2009-01-28 14:49 . 2008-04-11 19:04691712 c:\windows\system32\dllcache\inetcomm.dll
      + 2007-08-14 02:43 . 2010-04-16 11:43634656 c:\windows\system32\dllcache\iexplore.exe
      + 2009-01-28 15:29 . 2010-05-04 17:20268288 c:\windows\system32\dllcache\iertutil.dll
      - 2009-01-28 15:29 . 2010-03-11 12:38268288 c:\windows\system32\dllcache\iertutil.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38192512 c:\windows\system32\dllcache\iepeers.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20192512 c:\windows\system32\dllcache\iepeers.dll
      - 2007-08-14 02:39 . 2010-03-11 12:38385024 c:\windows\system32\dllcache\iedkcs32.dll
      + 2007-08-14 02:39 . 2010-05-04 17:20385024 c:\windows\system32\dllcache\iedkcs32.dll
      - 2009-01-28 15:29 . 2010-03-11 12:38380928 c:\windows\system32\dllcache\ieapfltr.dll
      + 2009-01-28 15:29 . 2010-05-04 17:20380928 c:\windows\system32\dllcache\ieapfltr.dll
      + 2004-08-04 12:00 . 2010-04-16 11:43161792 c:\windows\system32\dllcache\ieakui.dll
      - 2004-08-04 12:00 . 2010-02-23 05:18161792 c:\windows\system32\dllcache\ieakui.dll
      + 2007-08-14 02:39 . 2010-05-04 17:20230400 c:\windows\system32\dllcache\ieaksie.dll
      - 2007-08-14 02:39 . 2010-03-11 12:38230400 c:\windows\system32\dllcache\ieaksie.dll
      - 2007-08-14 02:39 . 2010-03-11 12:38153088 c:\windows\system32\dllcache\ieakeng.dll
      + 2007-08-14 02:39 . 2010-05-04 17:20153088 c:\windows\system32\dllcache\ieakeng.dll
      + 2007-08-14 02:54 . 2010-05-04 17:20133120 c:\windows\system32\dllcache\extmgr.dll
      - 2007-08-14 02:54 . 2010-03-11 12:38133120 c:\windows\system32\dllcache\extmgr.dll
      + 2007-08-14 02:35 . 2010-05-04 17:20214528 c:\windows\system32\dllcache\dxtrans.dll
      - 2007-08-14 02:35 . 2010-03-11 12:38214528 c:\windows\system32\dllcache\dxtrans.dll
      + 2007-08-14 02:35 . 2010-05-04 17:20347136 c:\windows\system32\dllcache\dxtmsft.dll
      - 2007-08-14 02:35 . 2010-03-11 12:38347136 c:\windows\system32\dllcache\dxtmsft.dll
      + 2010-04-20 05:30 . 2010-04-20 05:30285696 c:\windows\system32\dllcache\atmfd.dll
      + 2009-01-28 14:40 . 2008-04-13 16:39142592 c:\windows\system32\dllcache\aec.sys
      - 2007-08-14 02:39 . 2010-03-11 12:38124928 c:\windows\system32\dllcache\advpack.dll
      + 2007-08-14 02:39 . 2010-05-04 17:20124928 c:\windows\system32\dllcache\advpack.dll
      - 2004-08-04 12:00 . 2008-04-14 00:09285696 c:\windows\system32\atmfd.dll
      + 2004-08-04 12:00 . 2010-04-20 05:30285696 c:\windows\system32\atmfd.dll
      + 2004-08-04 12:00 . 2010-05-04 17:20124928 c:\windows\system32\advpack.dll
      - 2004-08-04 12:00 . 2010-03-11 12:38124928 c:\windows\system32\advpack.dll
      + 2010-03-31 04:16 . 2010-03-31 04:16130408 c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
      + 2010-04-08 03:48 . 2010-04-08 03:48970752 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
      - 2008-07-30 03:16 . 2008-07-30 03:16110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
      + 2010-04-08 03:48 . 2010-04-08 03:48110592 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMdiagnostics.dll
      + 2010-03-23 09:31 . 2010-03-23 09:31435024 c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll
      + 2010-02-09 16:22 . 2010-02-09 16:22258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
      - 2008-07-25 19:17 . 2008-07-25 19:17258048 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll
      - 2008-05-28 04:49 . 2008-05-28 04:49102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
      + 2010-03-31 18:51 . 2010-03-31 18:51102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
      - 2008-05-28 04:48 . 2008-05-28 04:48315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
      + 2010-03-31 18:49 . 2010-03-31 18:49315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
      + 2010-03-31 19:32 . 2010-03-31 19:32258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
      - 2008-05-28 05:30 . 2008-05-28 05:30258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
      + 2010-06-10 12:22 . 2010-06-10 12:22200192 c:\windows\Installer\be07f0b.msi
      + 2010-02-25 04:14 . 2010-02-25 04:14543232 c:\windows\Installer\be07e85.msp
      + 2010-06-16 19:39 . 2010-06-16 19:39454144 c:\windows\Installer\a68871.msi
      + 2010-06-16 19:33 . 2010-06-16 19:33356352 c:\windows\Installer\a6884b.msi
      + 2010-06-16 19:32 . 2010-06-16 19:32315392 c:\windows\Installer\a68843.msi
      + 2010-06-16 19:32 . 2010-06-16 19:32316928 c:\windows\Installer\a6883b.msi
      + 2010-06-16 19:32 . 2010-06-16 19:32356864 c:\windows\Installer\a68833.msi
      + 2010-06-16 19:31 . 2010-06-16 19:31359424 c:\windows\Installer\a6882b.msi
      + 2010-06-16 19:31 . 2010-06-16 19:31356352 &nbsI guess it is too long. I will copy in multiple posts.

      + 2010-06-16 19:31 . 2010-06-16 19:31356352 c:\windows\Installer\a68823.msi
      + 2010-06-16 19:31 . 2010-06-16 19:31316416 c:\windows\Installer\a6881b.msi
      + 2010-06-11 23:07 . 2010-06-11 23:07168960 c:\windows\Installer\843fc78.msp
      + 2010-05-08 16:34 . 2010-05-08 16:34881664 c:\windows\Installer\28fe89.msi
      + 2009-01-28 18:22 . 2010-07-15 11:04409600 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
      - 2009-01-28 18:22 . 2010-04-14 03:47409600 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
      - 2009-01-28 18:22 . 2010-04-14 03:47286720 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
      + 2009-01-28 18:22 . 2010-07-15 11:04286720 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
      + 2009-01-28 18:22 . 2010-07-15 11:04249856 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe
      - 2009-01-28 18:22 . 2010-04-14 03:47249856 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe
      - 2009-01-28 18:22 . 2010-04-14 03:47794624 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe
      + 2009-01-28 18:22 . 2010-07-15 11:04794624 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe
      + 2009-01-28 18:22 . 2010-07-15 11:04135168 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe
      - 2009-01-28 18:22 . 2010-04-14 03:47135168 c:\windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe
      + 2010-07-14 13:10 . 2010-07-17 14:01102400 c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe
      + 2010-06-10 11:51 . 2010-03-11 12:38832512 c:\windows\ie7updates\KB982381-IE7\wininet.dll
      + 2010-06-10 11:51 . 2010-03-11 12:38233472 c:\windows\ie7updates\KB982381-IE7\webcheck.dll
      + 2010-06-10 11:51 . 2010-03-11 12:38105984 c:\windows\ie7updates\KB982381-IE7\url.dll
      + 2010-06-10 11:52 . 2009-05-26 11:40382840 c:\windows\ie7updates\KB982381-IE7\spuninst\updspapi.dll
      + 2010-06-10 11:52 . 2008-07-08 13:02231288 c:\windows\ie7updates\KB982381-IE7\spuninst\spuninst.exe
      + 2010-06-10 11:51 . 2010-03-11 12:38102912 c:\windows\ie7updates\KB982381-IE7\occache.dll
      + 2010-06-10 11:51 . 2010-03-11 12:38671232 c:\windows\ie7updates\KB982381-IE7\mstime.dll
      + 2010-06-10 11:51 . 2010-03-11 12:38193024 c:\windows\ie7updates\KB982381-IE7\msrating.dll
      + 2010-06-10 11:51 . 2010-03-11 12:38477696 c:\windows\ie7updates\KB982381-IE7\mshtmled.dll
      + 2010-06-10 11:51 . 2010-03-11 12:38459264 c:\windows\ie7updates\KB982381-IE7\msfeeds.dll
      + 2010-06-10 11:52 . 2010-02-23 05:20634648 c:\windows\ie7updates\KB982381-IE7\iexplore.exe
      + 2010-06-10 11:52 . 2010-03-11 12:38268288 c:\windows\ie7updates\KB982381-IE7\iertutil.dll
      + 2010-06-10 11:52 . 2010-03-11 12:38192512 c:\windows\ie7updates\KB982381-IE7\iepeers.dll
      + 2010-06-10 11:52 . 2010-03-11 12:38385024 c:\windows\ie7updates\KB982381-IE7\iedkcs32.dll
      + 2010-06-10 11:52 . 2010-03-11 12:38380928 c:\windows\ie7updates\KB982381-IE7\ieapfltr.dll
      + 2010-06-10 11:52 . 2010-02-23 05:18161792 c:\windows\ie7updates\KB982381-IE7\ieakui.dll
      + 2010-06-10 11:52 . 2010-03-11 12:38230400 c:\windows\ie7updates\KB982381-IE7\ieaksie.dll
      + 2010-06-10 11:52 . 2010-03-11 12:38153088 c:\windows\ie7updates\KB982381-IE7\ieakeng.dll
      + 2010-06-10 11:52 . 2010-03-11 12:38133120 c:\windows\ie7updates\KB982381-IE7\extmgr.dll
      + 2010-06-10 11:52 . 2010-03-11 12:38214528 c:\windows\ie7updates\KB982381-IE7\dxtrans.dll
      + 2010-06-10 11:52 . 2010-03-11 12:38347136 c:\windows\ie7updates\KB982381-IE7\dxtmsft.dll
      + 2010-06-10 11:52 . 2010-03-11 12:38124928 c:\windows\ie7updates\KB982381-IE7\advpack.dll
      + 2010-06-10 12:24 . 2010-06-10 12:24835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_00504892\System.Drawing.dll
      + 2010-06-10 12:24 . 2010-06-10 12:24192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_01398cc1\System.Drawing.Design.dll
      + 2010-06-10 12:24 . 2010-06-10 12:24118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_7930f4fc\CustomMarshalers.dll
      + 2010-06-10 12:26 . 2010-06-10 12:26321536 c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\4d07b1ccecca66f320c1a0971dd614d1\WsatConfig.ni.exe
      + 2010-06-10 12:29 . 2010-06-10 12:29633856 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\31a06c9eb6c083d9b8710ac6ce1be937\WindowsLiveLocal.WriterPlugin.ni.dll
      + 2010-06-10 12:28 . 2010-06-10 12:28319488 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f0530ae077336e0eca143d4b32e8d34e\WindowsLive.Writer.Interop.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29258048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e50904b2c1e6e1ac5a4c7df032c2123c\WindowsLive.Writer.Mshtml.ni.dll
      + 2010-06-10 12:27 . 2010-06-10 12:27843776 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c6f20d937db1a69d005f791db60ee326\WindowsLive.Writer.Controls.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29118784 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c35124ff18874635fa84856596f154cc\WindowsLive.Writer.Extensibility.ni.dll
      + 2010-06-10 12:28 . 2010-06-10 12:28152064 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c1992981a0cafba5e0d3753b8ec39b21\WindowsLive.Writer.HtmlParser.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29594944 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bea5a870bbb250130356c5dd8c2f3ca9\WindowsLive.Writer.HtmlEditor.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29428032 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b07e085adf681435595a729c5f8ca528\WindowsLive.Writer.Localization.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a148f5e5315f10bd4dfb626fdcf001c2\WindowsLive.Writer.FileDestinations.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29851968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\53a0614cafe16513d774a5d7b0473a73\WindowsLive.Writer.BlogClient.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29117760 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4190016a1225c8f33b8ebd96addb2a8e\WindowsLive.Writer.Instrumentation.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29322048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\27e34aec3681f62ec3791cdfe9ac0230\WindowsLive.Writer.SpellChecker.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29108544 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\18dce358e91aedbd9656a6a0d0da582a\WindowsLive.Writer.Passport.ni.dll
      + 2010-06-10 12:28 . 2010-06-10 12:28174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\06657a351a8cafd8101bbd06c31c6194\WindowsLive.Writer.BrowserControl.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29145920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\3aca1d7df14c17850246ef5ebca827c5\WindowsLive.Client.ni.dll
      + 2010-06-24 07:11 . 2010-06-24 07:11240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\b3a9fac9aea3ad913781fafbdcbb0cae\WindowsFormsIntegration.ni.dll
      + 2010-06-10 12:20 . 2010-06-10 12:20240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\a7c702f75d47bf841b9587e582c2d0b2\WindowsFormsIntegration.ni.dll
      + 2010-06-24 07:11 . 2010-06-24 07:11447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\4131a3627fec69291dbaed236f30dc65\UIAutomationClient.ni.dll
      + 2010-06-10 12:20 . 2010-06-10 12:20447488 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\3a78043c85333d5af49a0d958912ae4a\UIAutomationClient.ni.dll
      + 2010-06-10 12:32 . 2010-06-10 12:32400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\747e84d81d1de2041661f0f71b04734a\System.Xml.Linq.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\d51dfbd8d5431eb89181baaa24863e15\System.Web.Routing.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\436dde9611932489da3dc8a1be170843\System.Web.RegularExpressions.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\e8ef769b3e899e62b26daadee50b97ed\System.Web.Extensions.Design.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\ce3b446b7bee5c47949c994ec89b1649\System.Web.Entity.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\ad04fe1182e55e7c01066b62a4bee6b5\System.Web.Entity.Design.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\20ba0d4d182a1a9c1f54c00d3bc29a68\System.Web.DynamicData.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\c97ecf9250c2f0794262534f27f98b72\System.Web.Abstractions.ni.dll
      + 2010-06-10 12:28 . 2010-06-10 12:28627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9c56656c88979cf18de6cbcb6587ba8f\System.Transactions.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5adb0f89d469632511aed9d88cfe05c4\System.ServiceProcess.ni.dll
      + 2010-06-10 12:28 . 2010-06-10 12:28679936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\42b2ffb594dbd5652a576a0dce28722c\System.Security.ni.dll
      + 2010-06-10 12:28 . 2010-06-10 12:28311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\3231473e2ec4451c8f218930fda80d19\System.Runtime.Serialization.Formatters.Soap.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\2077ce69bd24a095dd54683ae26454d4\System.Runtime.Remoting.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\f90965b9d9a6a6604c9a66f57c37c026\System.Net.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\16670b6870746e5a8dc4a73a76a90bed\System.Management.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\e6bd59fec415e273c173170c6508180a\System.Management.Instrumentation.ni.dll
      + 2010-06-10 12:25 . 2010-06-10 12:25381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\e3eb86170cba4c80e6e22ca33c63c218\System.IO.Log.ni.dll
      + 2010-06-10 12:27 . 2010-06-10 12:27212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\cfa48936affc9a5fb89f0bf66cc52a47\System.IdentityModel.Selectors.ni.dll
      + 2010-06-10 12:28 . 2010-06-10 12:28280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\e9edc5cd12ebb513b4a3c53cb4640771\System.EnterpriseServices.Wrapper.dll
      + 2010-06-10 12:28 . 2010-06-10 12:28627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\e9edc5cd12ebb513b4a3c53cb4640771\System.EnterpriseServices.ni.dll
      + 2010-06-10 12:19 . 2010-06-10 12:19208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\aeba6820f20655dec7fe0fe05aaeb818\System.Drawing.Design.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\9ef70079beca3a9982a3aa76ebc0ddd8\System.DirectoryServices.Protocols.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\277619716d9136216065bea970365c65\System.DirectoryServices.AccountManagement.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\90b67e13866b176ae6cbdb23144f724d\System.Data.Services.Client.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\131a477d41a8669b15696128b94c2636\System.Data.Services.Design.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:31756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\d4990681ce373d81a52b231ee4c4afea\System.Data.Entity.Design.ni.dll
      + 2010-06-10 12:30 . 2010-06-10 12:30135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\9e9d66a3a0e16fceead505c25af569eb\System.Data.DataSetExtensions.ni.dll
      + 2010-06-10 12:27 . 2010-06-10 12:27971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\39e4f9a276fb12125d8a1444d8b65a84\System.Configuration.Install.ni.dll
      + 2010-06-10 12:30 . 2010-06-10 12:30633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\849916c5cb3ff7763d15a3976766c2f6\System.AddIn.ni.dll
      + 2010-06-10 12:26 . 2010-06-10 12:26366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\f38a426b90e6c526dcb2c435c7380450\SMSvcHost.ni.exe
      + 2010-06-10 12:26 . 2010-06-10 12:26256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\6cabc7d1700c224e8b41ff2f96a3087c\SMDiagnostics.ni.dll
      + 2010-06-10 12:26 . 2010-06-10 12:26320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\5c8f5ca36498f43980d64820d8186c8a\ServiceModelReg.ni.exe
      + 2010-06-10 12:15 . 2010-06-10 12:15258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ae733e4062edba3a33bb0a632bef66bf\PresentationFramework.Royale.ni.dll
      + 2010-06-24 07:10 . 2010-06-24 07:10368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a10c2c7e38291c3ada631ad13e762818\PresentationFramework.Aero.ni.dll
      + 2010-06-24 07:10 . 2010-06-24 07:10539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7579c76fa81eb309d3170b62467be58d\PresentationFramework.Luna.ni.dll
      + 2010-06-10 12:14 . 2010-06-10 12:14368128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3ffad524016f0aba7b11a8aa33301a65\PresentationFramework.Aero.ni.dll
      + 2010-06-24 07:10 . 2010-06-24 07:10224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3bef0992fb684e71dbfab5c0a99316af\PresentationFramework.Classic.ni.dll
      + 2010-06-24 07:10 . 2010-06-24 07:10258048 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2f6687d394813d760496f60acf046384\PresentationFramework.Royale.ni.dll
      + 2010-06-10 12:14 . 2010-06-10 12:14224768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\201968d038a23a4688310fed1eeaddaa\PresentationFramework.Classic.ni.dll
      + 2010-06-10 12:14 . 2010-06-10 12:14539648 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1ead87ca8eb84c595c77c70e3b2df88d\PresentationFramework.Luna.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\7700963610c1af364aa934c3c824b7b4\MSBuild.ni.exe
      + 2010-06-10 12:26 . 2010-06-10 12:26386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\c74d4c69c49992dfb23ba512081dc3de\Microsoft.Transactions.Bridge.Dtc.ni.dll
      + 2010-06-10 12:30 . 2010-06-10 12:30144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\a6a9f24b1a8984eaafbabb1ee968e359\Microsoft.Build.Utilities.ni.dll
      + 2010-06-10 12:30 . 2010-06-10 12:30175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\2fa81d363cb1496be2427d848a867409\Microsoft.Build.Utilities.v3.5.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\c4c360df9c1024ebc3f0de77f5cf8b1c\Microsoft.Build.Engine.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:29222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\c9386dcd89c2518a74115f3bfd861830\Microsoft.Build.Conversion.v3.5.ni.dll
      + 2010-06-10 12:26 . 2010-06-10 12:26410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\abb62e3ed74c974f0282bc7ea5d3f1c1\ComSvcConfig.ni.exe
      + 2010-06-10 12:27 . 2010-06-10 12:27842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\6d34f00b6a782d15bec70d6cdb00b5e8\AspNetMMCExt.ni.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
      + 2010-06-10 12:10 . 2010-06-10 12:10970752 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
      - 2009-10-17 07:14 . 2009-10-17 07:14372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
      + 2010-06-10 12:10 . 2010-06-10 12:10438272 c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13626688 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
      - 2009-10-17 07:14 . 2009-10-17 07:14970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
      - 2009-10-17 07:14 . 2009-10-17 07:14745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
      - 2009-10-17 07:14 . 2009-10-17 07:14425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
      - 2009-10-17 07:14 . 2009-10-17 07:14110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
      - 2009-01-28 15:35 . 2009-01-28 15:35110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
      + 2010-06-10 12:10 . 2010-06-10 12:10110592 c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
      - 2009-10-17 07:14 . 2009-10-17 07:14655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
      - 2009-10-17 07:13 . 2009-10-17 07:13258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
      - 2009-10-17 07:14 . 2009-10-17 07:14486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
      + 2010-06-24 07:04 . 2010-06-24 07:04486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
      + 2010-05-26 07:00 . 2009-05-26 09:01382840 c:\windows\$NtUninstallKB981793$\spuninst\updspapi.dll
      + 2010-05-26 07:00 . 2009-05-26 09:01231288 c:\windows\$NtUninstallKB981793$\spuninst\spuninst.exe
      + 2010-06-10 12:28 . 2009-05-26 11:40382840 c:\windows\$NtUninstallKB980218$\spuninst\updspapi.dll
      + 2010-06-10 12:28 . 2009-05-26 11:40231288 c:\windows\$NtUninstallKB980218$\spuninst\spuninst.exe
      + 2010-06-10 12:28 . 2008-04-14 00:09285696 c:\windows\$NtUninstallKB980218$\atmfd.dll
      + 2010-06-10 12:23 . 2008-07-08 13:02382840 c:\windows\$NtUninstallKB980195$\spuninst\updspapi.dll
      + 2010-06-10 12:23 . 2008-07-08 13:02231288 c:\windows\$NtUninstallKB980195$\spuninst\spuninst.exe
      + 2010-06-10 12:19 . 2009-05-26 11:40382840 c:\windows\$NtUninstallKB979559$\spuninst\updspapi.dll
      + 2010-06-10 12:19 . 2009-05-26 09:01231288 c:\windows\$NtUninstallKB979559$\spuninst\spuninst.exe
      + 2010-06-10 12:12 . 2009-05-26 11:40382840 c:\windows\$NtUninstallKB979482$\spuninst\updspapi.dll
      + 2010-06-10 12:12 . 2009-05-26 11:40231288 c:\windows\$NtUninstallKB979482$\spuninst\spuninst.exe
      + 2010-06-10 12:13 . 2007-07-28 03:11382840 c:\windows\$NtUninstallKB978695_WM9$\spuninst\updspapi.dll
      + 2010-06-10 12:13 . 2007-07-28 03:11231288 c:\windows\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe
      + 2010-05-13 07:01 . 2009-05-26 11:40382840 c:\windows\$NtUninstallKB978542$\spuninst\updspapi.dll
      + 2010-05-13 07:01 . 2009-05-26 11:40231288 c:\windows\$NtUninstallKB978542$\spuninst\spuninst.exe
      + 2010-05-13 07:00 . 2008-04-11 19:04691712 c:\windows\$NtUninstallKB978542$\inetcomm.dll
      + 2010-06-10 12:12 . 2009-05-26 11:40382840 c:\windows\$NtUninstallKB975562$\spuninst\updspapi.dll
      + 2010-06-10 12:12 . 2008-07-08 13:02231288 c:\windows\$NtUninstallKB975562$\spuninst\spuninst.exe
      + 2010-06-10 11:52 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB982381-IE7\update\updspapi.dll
      + 2010-06-10 11:52 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB982381-IE7\update\update.exe
      + 2010-06-10 11:52 . 2008-07-08 13:02231288 c:\windows\$hf_mig$\KB982381-IE7\spuninst.exe
      + 2010-05-04 17:20 . 2010-05-04 17:20841216 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\wininet.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20233472 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\webcheck.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20105984 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\url.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20102912 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\occache.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20671232 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\mstime.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20193024 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msrating.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20477696 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\mshtmled.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20459264 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\msfeeds.dll
      + 2010-04-16 11:08 . 2010-04-16 11:08634648 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
      + 2010-05-04 17:20 . 2010-05-04 17:20268288 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iertutil.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20193024 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iepeers.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20388608 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iedkcs32.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20380928 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieapfltr.dll
      + 2010-04-16 11:06 . 2010-04-16 11:06161792 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieakui.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20230400 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieaksie.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20153088 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieakeng.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20132608 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\extmgr.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20214528 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\dxtrans.dll
      + 2010-05-04 17:20 . 2010-05-04 17:20347136 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\dxtmsft.dll
      + 2010-05-04 17:19 . 2010-05-04 17:19124928 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\advpack.dll
      + 2010-06-10 12:28 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB980218\update\updspapi.dll
      + 2010-06-10 12:28 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB980218\update\update.exe
      + 2010-06-10 12:28 . 2009-05-26 11:40231288 c:\windows\$hf_mig$\KB980218\spuninst.exe
      + 2010-04-20 05:37 . 2010-04-20 05:37285824 c:\windows\$hf_mig$\KB980218\SP3QFE\atmfd.dll
      + 2010-06-10 12:23 . 2008-07-08 13:02382840 c:\windows\$hf_mig$\KB980195\update\updspapi.dll
      + 2010-06-10 12:23 . 2008-07-08 13:02755576 c:\windows\$hf_mig$\KB980195\update\update.exe
      + 2010-06-10 12:23 . 2008-07-08 13:02231288 c:\windows\$hf_mig$\KB980195\spuninst.exe
      + 2010-06-10 12:19 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB979559\update\updspapi.dll
      + 2010-06-10 12:19 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB979559\update\update.exe
      + 2010-06-10 12:19 . 2009-05-26 09:01231288 c:\windows\$hf_mig$\KB979559\spuninst.exe
      + 2010-06-10 12:12 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB979482\update\updspapi.dll
      + 2010-06-10 12:12 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB979482\update\update.exe
      + 2010-06-10 12:12 . 2009-05-26 11:40231288 c:\windows\$hf_mig$\KB979482\spuninst.exe
      + 2010-05-13 07:01 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB978542\update\updspapi.dll
      + 2010-05-13 07:01 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB978542\update\update.exe
      + 2010-05-13 07:01 . 2009-05-26 11:40231288 c:\windows\$hf_mig$\KB978542\spuninst.exe
      + 2010-01-29 14:53 . 2010-01-29 14:53691712 c:\windows\$hf_mig$\KB978542\SP3QFE\inetcomm.dll
      + 2010-06-10 12:12 . 2009-05-26 11:40382840 c:\windows\$hf_mig$\KB975562\update\updspapi.dll
      + 2010-06-10 12:12 . 2009-05-26 11:40755576 c:\windows\$hf_mig$\KB975562\update\update.exe
      + 2010-06-10 12:12 . 2008-07-08 13:02231288 c:\windows\$hf_mig$\KB975562\spuninst.exe
      + 2009-06-26 23:07 . 2009-06-26 23:073780416 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfc90u.dll
      + 2009-06-26 23:07 . 2009-06-26 23:073765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfc90.dll
      + 2009-07-12 00:46 . 2009-07-12 00:461093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
      + 2009-07-12 00:46 . 2009-07-12 00:461105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
      + 2004-08-04 12:00 . 2010-04-06 08:522462720 c:\windows\system32\WMVCore.dll
      - 2004-08-04 12:00 . 2010-03-11 12:381168384 c:\windows\system32\urlmon.dll
      + 2004-08-04 12:00 . 2010-05-04 17:201168384 c:\windows\system32\urlmon.dll
      + 2004-08-04 12:00 . 2010-02-05 18:271291776 c:\windows\system32\quartz.dll
      - 2004-08-04 12:00 . 2009-11-27 17:111291776 c:\windows\system32\quartz.dll
      + 2004-08-04 12:00 . 2010-05-04 17:203600384 c:\windows\system32\mshtml.dll
      + 2009-07-18 03:21 . 2010-06-16 20:255537232 c:\windows\system32\Macromed\Flash\NPSWF32.dll
      - 2007-08-14 02:54 . 2010-03-11 12:386067200 c:\windows\system32\ieframe.dll
      + 2007-08-14 02:54 . 2010-05-04 17:206067200 c:\windows\system32\ieframe.dll
      + 2009-01-28 04:53 . 2010-07-14 16:274429288 c:\windows\system32\FNTCACHE.DAT
      + 2004-08-04 12:00 . 2010-04-06 08:522462720 c:\windows\system32\dllcache\WMVCore.dll
      + 2009-01-28 14:48 . 2010-05-02 05:221851264 c:\windows\system32\dllcache\win32k.sys
      - 2007-08-14 02:54 . 2010-03-11 12:381168384 c:\windows\system32\dllcache\urlmon.dll
      + 2007-08-14 02:54 . 2010-05-04 17:201168384 c:\windows\system32\dllcache\urlmon.dll
      + 2008-05-07 05:12 . 2010-02-05 18:271291776 c:\windows\system32\dllcache\quartz.dll
      - 2008-05-07 05:12 . 2009-11-27 17:111291776 c:\windows\system32\dllcache\quartz.dll
      - 2009-08-12 21:03 . 2009-07-10 13:271315328 c:\windows\system32\dllcache\msoe.dll
      + 2009-08-12 21:03 . 2010-01-29 15:011315328 c:\windows\system32\dllcache\msoe.dll
      + 2007-08-14 02:54 . 2010-05-04 17:203600384 c:\windows\system32\dllcache\mshtml.dll
      - 2009-01-28 15:29 . 2010-03-11 12:386067200 c:\windows\system32\dllcache\ieframe.dll
      + 2009-01-28 15:29 . 2010-05-04 17:206067200 c:\windows\system32\dllcache\ieframe.dll
      + 2009-11-07 05:06 . 2009-11-07 05:061130824 c:\windows\system32\dfshim.dll
      + 2010-04-08 03:48 . 2010-04-08 03:485967872 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
      - 2008-11-25 12:59 . 2008-11-25 12:595242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
      + 2010-03-23 09:32 . 2010-03-23 09:325242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
      + 2010-03-23 09:32 . 2010-03-23 09:323182592 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
      - 2008-05-28 05:35 . 2008-05-28 05:351265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
      + 2010-04-01 15:42 . 2010-04-01 15:421265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
      - 2008-05-28 05:35 . 2008-05-28 05:351232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
      + 2010-04-01 15:42 . 2010-04-01 15:421232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
      - 2008-05-28 04:48 . 2008-05-28 04:482514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
      + 2010-03-31 18:50 . 2010-03-31 18:502514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
      + 2010-03-31 18:50 . 2010-03-31 18:502527232 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
      - 2008-05-28 04:43 . 2008-05-28 04:432142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
      + 2010-04-01 15:42 . 2010-04-01 15:422142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
      + 2010-06-16 20:25 . 2010-06-16 20:251093120 c:\windows\Installer\d825a5.msi
      + 2010-05-03 20:27 . 2010-05-03 20:276825472 c:\windows\Installer\be07f42.msp
      + 2010-05-03 20:11 . 2010-05-03 20:114149760 c:\windows\Installer\be07ee7.msp
      + 2010-05-05 02:25 . 2010-05-05 02:257681024 c:\windows\Installer\be07ed1.msp
      + 2010-05-10 21:17 . 2010-05-10 21:175520896 c:\windows\Installer\be07ebb.msp
      + 2010-04-12 02:17 . 2010-04-12 02:172607104 c:\windows\Installer\be07e94.msp
      + 2010-04-12 02:17 . 2010-04-12 02:174210688 c:\windows\Installer\be07e93.msp
      + 2010-04-24 21:10 . 2010-04-24 21:108486400 c:\windows\Installer\be07e74.msp
      + 2010-05-03 20:06 . 2010-05-03 20:065053952 c:\windows\Installer\be07e69.msp
      + 2010-06-16 19:43 . 2010-06-16 19:431093120 c:\windows\Installer\a68889.msi
      + 2009-10-16 22:07 . 2009-10-16 22:076115328 c:\windows\Installer\4b9138a.msp
      + 2010-04-21 21:46 . 2010-04-21 21:465522432 c:\windows\Installer\4b91374.msp
      + 2010-07-14 13:26 . 2010-07-14 13:266483968 c:\windows\Installer\47ec359.msi
      + 2009-11-09 04:25 . 2009-11-09 04:251935360 c:\windows\Installer\43767ad.msp
      + 2010-05-25 15:45 . 2010-05-25 15:458445440 c:\windows\Installer\3fb686e.msp
      + 2010-07-01 02:52 . 2010-07-01 02:525522944 c:\windows\Installer\3fb6857.msp
      + 2010-07-17 14:01 . 2010-07-17 14:011904640 c:\windows\Installer\24ef50.msi
      + 2009-01-30 07:03 . 2010-07-13 16:533777536 c:\windows\Installer\12178a.msi
      - 2009-01-30 07:03 . 2010-04-14 23:133777536 c:\windows\Installer\12178a.msi
      + 2010-06-10 11:51 . 2010-03-11 12:381168384 c:\windows\ie7updates\KB982381-IE7\urlmon.dll
      + 2010-06-10 11:51 . 2010-03-11 12:383599872 c:\windows\ie7updates\KB982381-IE7\mshtml.dll
      + 2010-06-10 11:52 . 2010-03-11 12:386067200 c:\windows\ie7updates\KB982381-IE7\ieframe.dll
      + 2009-01-28 15:38 . 2009-01-28 15:385283840 c:\windows\assembly\temp\PCP2T7DR5Y\PresentationFramework.dll
      + 2009-01-28 15:35 . 2009-01-28 15:354210688 c:\windows\assembly\temp\4CMKJJJJJJ\PresentationCore.dll
      + 2009-01-28 15:35 . 2009-01-28 15:351245184 c:\windows\assembly\temp\0ILZDDDDDD\WindowsBase.dll
      + 2010-06-10 12:23 . 2010-06-10 12:231966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_f636947c\System.dll
      + 2010-06-10 12:24 . 2010-06-10 12:244792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_79ae7e92\System.dll
      + 2010-06-10 12:24 . 2010-06-10 12:245513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_c444e089\System.Xml.dll
      + 2010-06-10 12:23 . 2010-06-10 12:232088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_66bef7e9\System.Xml.dll
      + 2010-06-10 12:23 . 2010-06-10 12:233018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_b54f8c9d\System.Windows.Forms.dll
      + 2010-06-10 12:24 . 2010-06-10 12:247884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_6b5a1c44\System.Windows.Forms.dll
      + 2010-06-10 12:24 . 2010-06-10 12:242244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_09d267e4\System.Drawing.dll
      + 2010-06-10 12:24 . 2010-06-10 12:243395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_b8fadec9\System.Design.dll
      + 2010-06-10 12:24 . 2010-06-10 12:241470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_297bc57f\System.Design.dll
      + 2010-06-10 12:24 . 2010-06-10 12:248908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_d460f315\mscorlib.dll
      + 2010-06-10 12:24 . 2010-06-10 12:243391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_7590502d\mscorlib.dll
      + 2010-06-10 12:27 . 2010-06-10 12:276392832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\af8ff11dbab485d5d13323bbf6a5be79\WindowsLive.Writer.PostEditor.ni.dll
      + 2010-06-10 12:28 . 2010-06-10 12:282002432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\590ced109c1eb276203e1561a695ab99\WindowsLive.Writer.CoreServices.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:291105920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0654d7056eddd323f13f38ff67325ca7\WindowsLive.Writer.ApplicationFramework.ni.dll
      + 2010-06-10 12:10 . 2010-06-10 12:103313664 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\f231461883859922a040002dddfb7b12\WindowsBase.ni.dll
      + 2010-06-24 07:08 . 2010-06-24 07:083325440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d63164ac4ed5adabc6a1b0fdf07eee05\WindowsBase.ni.dll
      + 2010-06-24 07:11 . 2010-06-24 07:111049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\d8549ce90b26cdc3071224ab6f020189\UIAutomationClientsideProviders.ni.dll
      + 2010-06-10 12:20 . 2010-06-10 12:201049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\48b66876f72f472db62de48ae4369406\UIAutomationClientsideProviders.ni.dll
      + 2010-06-10 12:09 . 2010-06-10 12:097949824 c:\windows\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll
      + 2010-06-10 12:20 . 2010-06-10 12:205450752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll
      + 2010-06-10 12:32 . 2010-06-10 12:321356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\016b75f60a18535c8d6b3e5d861ab559\System.WorkflowServices.ni.dll
      + 2010-06-10 12:32 . 2010-06-10 12:321908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\6dacae37d337004345518976fb57099e\System.Workflow.Runtime.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:314514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\c7b832bbc5bb11c6c7f128c801ce90d7\System.Workflow.ComponentModel.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:312992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\b9ea6ea910293cd6f13f765775867ebd\System.Workflow.Activities.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:291840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\8ef8d556899a4a10b7f288a80925489f\System.Web.Services.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:312209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\5dfda43f1991ee6ba345d62b2be4801c\System.Web.Mobile.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:312403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\f08b3b8cdf548e3dfe61f342536175eb\System.Web.Extensions.ni.dll
      + 2010-06-10 12:19 . 2010-06-10 12:191917952 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\2d6a5dbee4506bf643b853e41668afa3\System.Speech.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:311706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\169fe0ad9d59982a2a6b89779c09885b\System.ServiceModel.Web.ni.dll
      + 2010-06-10 12:25 . 2010-06-10 12:252345472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8b2710a63ecd363315ef16b257588b95\System.Runtime.Serialization.ni.dll
      + 2010-06-24 07:11 . 2010-06-24 07:111035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\af217ef58e5558991f331d482c2bdba6\System.Printing.ni.dll
      + 2010-06-10 12:19 . 2010-06-10 12:191035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\161b423dc4e86e569af019e838d39de5\System.Printing.ni.dll
      + 2010-06-10 12:25 . 2010-06-10 12:251070080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\ad4fb86064d7a1ebcb9ee997e7208ac1\System.IdentityModel.ni.dll
      + 2010-06-10 12:18 . 2010-06-10 12:181587200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:291116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\7deab2494d53763cd83c567e71e0d8e0\System.DirectoryServices.ni.dll
      + 2010-06-10 12:28 . 2010-06-10 12:281801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\b81efadfee7702624b713c6d86f7e369\System.Deployment.ni.dll
      + 2010-06-10 12:16 . 2010-06-10 12:166616576 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\50130ef751b98a4a11bd4ab73af7cab5\System.Data.ni.dll
      + 2010-06-10 12:27 . 2010-06-10 12:272510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\f71abf392c5ca05a4e46a5d1c4c72856\System.Data.SqlXml.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:311328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\5e6311aff5ada83d0f854922fa62faf6\System.Data.Services.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:291115136 c:\windows\assembly\NativeImages_v2.0.5072
      + 2010-06-10 12:29 . 2010-06-10 12:291115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\f249a2dbc8dcb91860d0997c163c73ff\System.Data.OracleClient.ni.dll
      + 2010-06-10 12:16 . 2010-06-10 12:162516480 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\c3ba3367d03779ad6e76c5d4cdfe572a\System.Data.Linq.ni.dll
      + 2010-06-10 12:30 . 2010-06-10 12:309924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6abf820d8ec57a0561c3367727d274df\System.Data.Entity.ni.dll
      + 2010-06-10 12:16 . 2010-06-10 12:162295296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\e98726349766935ec0e9b980f19a046a\System.Core.ni.dll
      + 2010-06-10 12:16 . 2010-06-10 12:162128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\fc373f0a8dbd173c63b6b95551b1c673\ReachFramework.ni.dll
      + 2010-06-24 07:10 . 2010-06-24 07:102128896 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\57abb757c1f38586390dcc63bf056322\ReachFramework.ni.dll
      + 2010-06-10 12:16 . 2010-06-10 12:161657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\ead93b6a4f0101cb99d09f3e3fc6491c\PresentationUI.ni.dll
      + 2010-06-24 07:10 . 2010-06-24 07:101657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\0095ba60255d4addaf5b8ebee697a027\PresentationUI.ni.dll
      + 2010-06-10 12:09 . 2010-06-10 12:091451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\20ef773b20f6ce721ae60e5c2c2e8f80\PresentationBuildTasks.ni.dll
      + 2010-06-10 12:30 . 2010-06-10 12:301712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\935b855860088a86bb65d37a19f059cc\Microsoft.VisualBasic.ni.dll
      + 2010-06-10 12:26 . 2010-06-10 12:261093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\7a266de493d30eed21cb60ebe300be53\Microsoft.Transactions.Bridge.ni.dll
      + 2010-06-10 12:31 . 2010-06-10 12:312332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\9db8f9f7fe63ca4451bb5316a3ebb009\Microsoft.JScript.ni.dll
      + 2010-06-10 12:30 . 2010-06-10 12:301966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\c96be82d6cb00367db4e3553272165ef\Microsoft.Build.Tasks.v3.5.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:291620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\3815de5b052187b5d9375681a6784255\Microsoft.Build.Tasks.ni.dll
      + 2010-06-10 12:29 . 2010-06-10 12:291888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\43fc6723d08e9ce88701c29653efd224\Microsoft.Build.Engine.ni.dll
      + 2010-06-24 07:07 . 2010-06-24 07:071249280 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
      + 2010-06-24 07:04 . 2010-06-24 07:043182592 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
      - 2009-10-17 07:14 . 2009-10-17 07:142048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
      + 2010-06-24 07:04 . 2010-06-24 07:042048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
      - 2009-10-17 07:13 . 2009-10-17 07:135025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
      + 2010-06-24 07:04 . 2010-06-24 07:045025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
      + 2010-06-10 12:10 . 2010-06-10 12:105967872 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
      - 2009-10-17 07:13 . 2009-10-17 07:135062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
      + 2010-06-24 07:04 . 2010-06-24 07:045062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
      + 2010-06-24 07:07 . 2010-06-24 07:075279744 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
      + 2010-06-24 07:03 . 2010-06-24 07:035242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
      - 2009-10-17 07:13 . 2009-10-17 07:135242880 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
      - 2009-10-17 07:14 . 2009-10-17 07:142933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
      + 2010-06-24 07:04 . 2010-06-24 07:042933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
      + 2010-06-24 07:07 . 2010-06-24 07:074210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
      - 2009-01-28 15:35 . 2009-01-28 15:354210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
      + 2010-06-24 07:04 . 2010-06-24 07:044546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
      - 2009-10-17 07:14 . 2009-10-17 07:144546560 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
      + 2010-06-10 12:23 . 2010-06-10 12:231232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
      - 2009-10-17 07:02 . 2009-10-17 07:021232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
      + 2010-06-10 12:23 . 2010-06-10 12:231265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
      - 2009-10-17 07:02 . 2009-10-17 07:021265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
      + 2010-06-10 12:19 . 2009-08-14 13:211850624 c:\windows\$NtUninstallKB979559$\win32k.sys
      + 2010-06-10 12:13 . 2009-05-20 08:562458112 c:\windows\$NtUninstallKB978695_WM9$\wmvcore.dll
      + 2010-05-13 07:00 . 2009-07-10 13:271315328 c:\windows\$NtUninstallKB978542$\msoe.dll
      + 2010-06-10 12:12 . 2009-11-27 17:111291776 c:\windows\$NtUninstallKB975562$\quartz.dll
      + 2010-05-04 17:20 . 2010-05-04 17:201171968 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\urlmon.dll
      + 2010-05-04 17:20 . 2010-05-04 17:203603456 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\mshtml.dll
      + 2010-05-04 17:20 . 2010-05-04 17:206071296 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieframe.dll
      + 2010-06-09 23:07 . 2009-06-29 08:332452872 c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\ieapfltr.dat
      + 2010-05-02 06:34 . 2010-05-02 06:341860352 c:\windows\$hf_mig$\KB979559\SP3QFE\win32k.sys
      + 2010-01-29 14:53 . 2010-01-29 14:531315328 c:\windows\$hf_mig$\KB978542\SP3QFE\msoe.dll
      + 2010-02-05 18:29 . 2010-02-05 18:291291776 c:\windows\$hf_mig$\KB975562\SP3QFE\quartz.dll
      + 2009-01-28 15:27 . 2010-07-02 19:3934045896 c:\windows\system32\MRT.exe
      + 2010-04-02 23:29 . 2010-04-02 23:2911413504 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp
      + 2010-05-11 15:30 . 2010-05-11 15:3011194880 c:\windows\Installer\be07f58.msp
      + 2010-04-02 16:30 . 2010-04-02 16:3017456640 c:\windows\Installer\be07f2d.msp
      + 2010-04-24 21:09 . 2010-04-24 21:0911750912 c:\windows\Installer\be07ef2.msp
      + 2010-04-12 02:17 . 2010-04-12 02:1714599680 c:\windows\Installer\be07ea5.msp
      + 2010-03-31 05:23 . 2010-03-31 05:2315638528 c:\windows\Installer\43767bc.msp
      + 2010-05-04 17:25 . 2010-05-04 17:2520240896 c:\windows\Installer\352520c.msp
      + 2010-05-04 17:20 . 2010-05-04 17:2015710720 c:\windows\Installer\3525202.msp
      + 2010-06-04 07:00 . 2010-06-04 07:0020242432 c:\windows\Installer\2b89935.msp
      + 2010-06-10 12:19 . 2010-06-10 12:1912430848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll
      + 2010-06-10 12:28 . 2010-06-10 12:2811797504 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\d987cf1de4ba688da92e212a374232c2\System.Web.ni.dll
      + 2010-06-10 12:26 . 2010-06-10 12:2617403904 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\8b74f2fe3f3632f95ff4ddb8c4839a1e\System.ServiceModel.ni.dll
      + 2010-06-10 12:18 . 2010-06-10 12:1810683392 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\f352c5cb50bee105e4c873ca050f9f46\System.Design.ni.dll
      + 2010-06-10 12:13 . 2010-06-10 12:1314327808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ca898d942e4d85af4c3d5f14a77c359a\PresentationFramework.ni.dll
      + 2010-06-24 07:09 . 2010-06-24 07:0914328320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\560662ada034afb6ec78a152bd9a47b5\PresentationFramework.ni.dll
      + 2010-06-10 12:12 . 2010-06-10 12:1212216320 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\ba8f917fd89d7afa8885c2a326379f03\PresentationCore.ni.dll
      + 2010-06-24 07:09 . 2010-06-24 07:0912215808 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\9f5dff344ac6ac923b5ade8ba1ab9382\PresentationCore.ni.dll
      .
      -- Snapshot reset to current date --
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
      2010-05-26 19:231385864----a-w-c:\program files\Ask.com\GenericAskToolbar.dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\INTERNET Explorer\Toolbar]
      "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

      [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
      [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
      [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
      [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
      "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

      [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
      [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
      [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
      [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
      "nwiz"="nwiz.exe" [2008-09-18 1657376]
      "RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416]
      "SkyTel"="SkyTel.EXE" [2007-06-15 1826816]
      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-18 86016]
      "cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-05-22 181488]
      "CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2010-05-28 230736]
      "cafw"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2009-01-28 771312]
      "capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2009-01-28 173296]
      "capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2009-01-28 259312]
      "QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe" [2009-01-28 14088]
      "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-01-27 788880]
      "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
      "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
      "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
      "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [2009-07-24 240112]
      "CPMonitor"="c:\program files\Roxio 2010\5.0\CPMonitor.exe" [2009-07-21 84464]
      "Desktop Disc Tool"="c:\program files\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-23 494064]
      "WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-07-12 74752]

      c:\documents and settings\Toni\Start Menu\Programs\Startup\
      Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

      c:\documents and settings\All Users\Start Menu\Programs\Startup\
      Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
      HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
      Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-27 123904]

      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
      "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
      2007-05-18 21:3079368----a-w-c:\windows\system32\UmxWNP.dll

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
      @="Service"

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusOverride"=dword:00000001
      "FirewallOverride"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)
      "DisableNotifications"= 1 (0x1)[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\uTorrent\\uTorrent.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
      "c:\\Program Files\\iTunes\\iTunes.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
      "c:\\Program Files\\Roxio 2010\\Venue\\Venue.exe"=
      "c:\\Program Files\\CinemaNow\\CinemaNow Media Manager\\CinemaNowShell.exe"=
      "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

      R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [6/24/2008 11:08 PM 93712]
      R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/13/2009 7:20 PM 64288]
      R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [2/11/2010 8:42 AM 21488]
      R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [2/11/2010 8:42 AM 15856]
      R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [6/24/2008 11:08 PM 63504]
      R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [6/24/2008 11:08 PM 45584]
      R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [2/11/2010 8:42 AM 25584]
      R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [6/2/2009 8:05 PM 457200]
      R2 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [6/23/2009 6:40 PM 127352]
      R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [6/24/2008 11:08 PM 134648]
      R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [6/24/2008 11:08 PM 66576]
      R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 7:17 AM 1181328]
      R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [10/18/2007 2:24 PM 1010192]
      R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/18/2007 2:24 PM 801296]
      R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [6/24/2008 11:10 PM 281104]
      R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [6/24/2008 11:08 PM 88816]
      R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [1/28/2009 2:24 PM 185680]
      S1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [6/24/2008 11:08 PM 115216]
      S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/4/2010 1:27 PM 136176]
      S2 RoxWatch12;Roxio Hard Drive WATCHER 12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [7/24/2009 9:33 AM 219632]
      S3 RoxMediaDB12;RoxMediaDB12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [7/24/2009 9:33 AM 1116656]
      .
      Contents of the 'Scheduled Tasks' folder

      2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
      - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18]

      2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
      - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18]

      2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
      - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18]

      2010-07-22 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
      - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18]

      2010-07-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
      - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:18]

      2010-07-16 c:\windows\Tasks\AppleSoftwareUpdate.job
      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]

      2010-06-23 c:\windows\Tasks\CAAntiSpywareScan_Daily as Toni at 10 24 AM.job
      - c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2009-01-28 10:53]

      2010-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
      - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 17:26]

      2010-07-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
      - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 17:26]

      2010-07-22 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
      - c:\program files\Ask.com\UpdateTask.exe [2010-05-26 19:23]
      .
      .
      ------- SUPPLEMENTARY Scan -------
      .
      uLocal Page = \blank.htm
      uStart Page = hxxp://www.google.com/
      IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      LSP: c:\windows\system32\VetRedir.dll
      FF - ProfilePath - c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\r8se12d9.default\
      FF - prefs.js: browser.search.selectedEngine - Ask
      FF - prefs.js: browser.startup.homepage - www.google.com
      FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q=
      FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
      FF - plugin: c:\documents and settings\Toni\Application Data\Facebook\npfbplugin_1_0_1.dll
      FF - plugin: c:\documents and settings\Toni\Application Data\Facebook\npfbplugin_1_0_3.dll
      FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
      FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
      FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
      FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

      ---- FIREFOX POLICIES ----
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
      c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
      c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
      .
      - - - - ORPHANS REMOVED - - - -

      BHO-{675B23E3-279D-4AEF-B6F7-5783DA94959C} - c:\windows\system32\hbfqp.dll
      BHO-{6892BD80-AD3F-4F86-BF67-05DDFC491C6E} - c:\windows\system32\lbfqp.dll
      HKCU-Run-Usorijaxesab - c:\windows\dimspstl.dll
      AddRemove-$NtUninstallMTF1011$ - c:\windows\$NtUninstallMTF1011$\apUninstall.exe



      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-07-22 02:19
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      --------------------- LOCKED REGISTRY KEYS ---------------------

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe,-101"

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
      "Enabled"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
      @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe"

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker4"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------

      - - - - - - - > 'winlogon.exe'(712)
      c:\windows\system32\UmxWnp.Dll
      c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
      c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
      c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll

      - - - - - - - > 'explorer.exe'(4608)
      c:\windows\system32\WININET.dll
      c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
      c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
      c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
      c:\windows\system32\ieframe.dll
      c:\windows\system32\WPDShServiceObj.dll
      c:\windows\system32\PortableDeviceTypes.dll
      c:\windows\system32\PortableDeviceApi.dll
      .
      ------------------------ Other Running Processes ------------------------
      .
      c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
      c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
      c:\program files\Bonjour\mDNSResponder.exe
      c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
      c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
      c:\program files\Java\jre6\bin\jqs.exe
      c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
      c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
      c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      c:\windows\system32\nvsvc32.exe
      c:\windows\system32\HPZipm12.exe
      c:\windows\RTHDCPL.EXE
      c:\windows\system32\RUNDLL32.EXE
      c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
      c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
      c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
      c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
      c:\windows\system32\SearchIndexer.exe
      c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
      c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
      c:\program files\Canon\CAL\CALMAIN.exe
      c:\windows\system32\wbem\unsecapp.exe
      c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
      c:\program files\iPod\bin\iPodService.exe
      .
      **************************************************************************
      .
      Completion time: 2010-07-22 02:23:33 - machine was rebooted
      ComboFix-quarantined-files.txt 2010-07-22 06:23
      ComboFix2.txt 2010-04-16 12:27
      ComboFix3.txt 2010-04-16 12:16
      ComboFix4.txt 2010-04-15 11:59

      Pre-Run: 108,868,366,336 bytes free
      Post-Run: 108,861,652,992 bytes free

      - - End Of File - - 5D4E06B3AA9DEF8BD66DE6468C4CB7D0
      Hi,

      Please download Malwarebytes Anti-Malware from Here.


      Double Click mbam-setup.exe to install the application.
      • Make sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
      • If an update is found, it will download and install the latest version.
      • Once the program has loaded, select "Perform Quick Scan", then click Scan.
      • The scan may take some time to finish,so please be patient.
      • When the scan is complete, click OK, then Show Results to view the results.
      • Make sure that everything is checked, and click Remove Selected.
      • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
      • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
      • Copy&Paste the entire report in your next reply.
      Extra Note:
      If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.Malwarebytes' log:


      Malwarebytes' Anti-Malware 1.46
      www.malwarebytes.org

      Database version: 4339

      Windows 5.1.2600 Service Pack 3
      Internet Explorer 7.0.5730.13

      7/22/2010 7:58:40 PM
      mbam-log-2010-07-22 (19-58-40).txt

      Scan type: Quick scan
      Objects scanned: 143606
      Time elapsed: 6 minute(s), 21 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 5
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 0

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      (No malicious items detected)
      329.

      Solve : THINKPOINT boot virus?

      Answer»

      SuperDave!

      Quote

      Re-running ComboFix to remove infections:

      It worked; now the boot virus messages from the motherboard are gone

      Here are the OTL logs:
      ----------------------------------------------------------------------
      OTL logfile created on: 11/16/2010 12:42:16 AM - Run 1
      OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Rob\Desktop\war on spyware
      Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
      Internet Explorer (Version = 8.0.6001.18702)
      Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

      1,024.00 Mb Total Physical Memory | 596.00 Mb Available Physical Memory | 58.00% Memory free
      2.00 Gb Paging File | 2.00 Gb Available in Paging File | 91.00% Paging File free
      Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
      Drive C: | 76.33 Gb Total Space | 15.50 Gb Free Space | 20.31% Space Free | Partition Type: NTFS
      Unable to calculate disk information.

      Computer Name: CROMWELL | User Name: Rob | Logged in as Administrator.
      Boot Mode: Normal | Scan Mode: Current user | Quick Scan
      Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

      ========== Processes (SafeList) ==========

      PRC - [2010/11/16 00:39:43 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rob\Desktop\war on spyware\OTL.exe
      PRC - [2010/09/10 23:41:42 | 001,901,056 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
      PRC - [2010/09/07 17:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
      PRC - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      PRC - [2010/08/13 11:58:56 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      PRC - [2010/07/20 08:09:40 | 000,080,384 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files\Kodak\MediaImpression\ArcMonitor.exe
      PRC - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
      PRC - [2009/12/16 17:38:20 | 000,375,296 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe
      PRC - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
      PRC - [2006/03/03 20:03:10 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
      PRC - [2004/08/03 23:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
      PRC - [2003/12/10 02:53:46 | 000,056,320 | R--- | M] (Doug Fetter Software Wizardry) -- C:\WINDOWS\system32\delttray.exe


      ========== Modules (SafeList) ==========

      MOD - [2010/11/16 00:39:43 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rob\Desktop\war on spyware\OTL.exe
      MOD - [2010/09/10 23:41:40 | 000,285,480 | ---- | M] (COMODO) -- C:\WINDOWS\system32\guard32.dll
      MOD - [2004/08/03 23:57:02 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll


      ========== Win32 Services (SafeList) ==========

      SRV - [2010/09/10 23:41:42 | 001,901,056 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
      SRV - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
      SRV - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
      SRV - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
      SRV - [2010/08/13 11:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
      SRV - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
      SRV - [2010/02/05 20:44:23 | 001,181,328 | ---- | M] (Lavasoft) [Auto | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
      SRV - [2009/12/16 17:38:20 | 000,375,296 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
      SRV - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
      SRV - [2006/03/03 20:03:10 | 000,069,632 | ---- | M] (HP) [Unknown | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


      ========== Driver Services (SafeList) ==========

      DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Internet Explorer\SABProcEnum.sys -- (SABProcEnum)
      DRV - File not found [Kernel | On_Demand | Running] -- C:\commy\catchme.sys -- (catchme)
      DRV - [2010/09/10 23:40:54 | 000,091,560 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
      DRV - [2010/09/10 23:40:52 | 000,239,240 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard)
      DRV - [2010/09/10 23:40:52 | 000,025,240 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
      DRV - [2010/09/07 16:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
      DRV - [2010/09/07 16:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
      DRV - [2010/09/07 16:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
      DRV - [2010/09/07 16:47:19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
      DRV - [2010/09/07 16:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
      DRV - [2010/09/07 16:46:51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
      DRV - [2010/05/10 19:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
      DRV - [2010/02/17 19:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
      DRV - [2010/01/21 01:59:58 | 000,020,864 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbdiag.sys -- (UsbDiag)
      DRV - [2010/01/21 01:59:56 | 000,024,960 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbmodem.sys -- (USBModem)
      DRV - [2010/01/21 01:59:56 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbbus.sys -- (usbbus)
      DRV - [2009/09/23 13:55:23 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
      DRV - [2007/11/06 12:22:00 | 000,036,224 | ---- | M] (ArcSoft Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ArcCD.sys -- (ArcCD)
      DRV - [2007/04/25 07:55:02 | 000,134,912 | ---- | M] (ArcSoft Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\ArcUdfs.sys -- (ArcUdfs)
      DRV - [2006/11/10 14:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
      DRV - [2005/12/23 10:03:02 | 000,020,224 | R--- | M] (Initio Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\inic1620.sys -- (inic1620)
      DRV - [2005/11/18 17:29:38 | 010,192,896 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snp2sxp.sys -- (SNP2STD) USB2.0 PC Camera (SNP2STD)
      DRV - [2004/08/04 00:08:22 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
      DRV - [2004/08/03 23:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
      DRV - [2004/08/03 22:10:12 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\61883.sys -- (61883)
      DRV - [2004/08/03 22:10:12 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avc.sys -- (Avc)
      DRV - [2004/08/03 22:10:00 | 000,051,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msdv.sys -- (MSDV)
      DRV - [2004/08/03 22:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
      DRV - [2004/06/10 21:42:38 | 000,015,429 | R--- | M] ( ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Sacm2K.sys -- (USBCM)
      DRV - [2003/12/10 02:53:45 | 000,386,464 | R--- | M] (Midiman/M-Audio) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\delta.sys -- (DELTA) Service for Delta Driver (WDM)
      DRV - [2002/10/16 03:57:04 | 000,084,529 | R--- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\si3112r.sys -- (Si3112r)
      DRV - [2002/03/21 20:21:32 | 000,134,784 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
      DRV - [2001/08/17 14:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)


      ========== Standard Registry (SafeList) ==========


      ========== Internet Explorer ==========


      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

      ========== FireFox ==========

      FF - prefs.js..browser.search.defaultenginen ame: "Web Search"
      FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="
      FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=867034"
      FF - prefs.js..browser.search.selectedEngine: "Web Search"
      FF - prefs.js..browser.search.useDBForOrder: true
      FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/403"
      FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.783
      FF - prefs.js..extensions.enabledItems: [emailprotected]:2.14
      FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
      FF - prefs.js..extensions.enabledItems: [emailprotected]:1.2.3
      FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1
      FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=403&q="
      FF - prefs.js..browser.search.order.1: "Web Search"

      FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/30 19:29:13 | 000,000,000 | ---D | M]
      FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/30 19:29:13 | 000,000,000 | ---D | M]

      [2009/12/11 13:40:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Mozilla\Extensions
      [2009/12/11 13:40:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Rob\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
      [2010/11/02 22:32:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\extensions
      [2010/02/27 14:08:29 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
      [2009/10/06 00:08:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\extensions\[emailprotected]
      [2009/10/06 20:37:34 | 000,001,649 | ---- | M] () -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\searchplugins\Ask.xml
      [2010/08/16 15:07:36 | 000,005,529 | ---- | M] () -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\searchplugins\SearchquWebSearch.xml
      [2010/03/20 13:07:37 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\searchplugins\winamp-search.xml
      [2010/03/20 13:07:34 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
      [2007/03/27 10:50:58 | 001,093,632 | ---- | M] (UNISYS France) -- C:\Program Files\Mozilla Firefox\plugins\npornap.dll
      [2010/01/13 23:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
      [2010/08/16 15:07:36 | 000,005,529 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml

      O1 HOSTS File: ([2010/11/16 00:32:05 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
      O1 - Hosts: 127.0.0.1 localhost
      O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
      O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
      O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
      O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
      O4 - HKLM..\Run: [ArcSoft MediaImpression Monitor] C:\Program Files\Kodak\MediaImpression\ArcMonitor.exe (ArcSoft, Inc.)
      O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
      O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
      O4 - HKLM..\Run: [DeltTray] C:\WINDOWS\System32\delttray.exe (Doug Fetter Software Wizardry)
      O4 - HKLM..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe (Sonix)
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
      O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
      O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
      O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
      O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
      O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
      O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1251900866625 (WUWebControl Class)
      O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/win/ActiveXPlugin.cab (ScorchPlugin Class)
      O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2
      O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
      O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
      O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
      O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
      O32 - HKLM CDRom: AutoRun - 1
      O32 - AutoRun File - [2009/09/02 14:50:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
      O34 - HKLM BootExecute: (autocheck autochk *) - File not found
      O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
      O35 - HKLM\..comfile [open] -- "%1" %*
      O35 - HKLM\..exefile [open] -- "%1" %*
      O37 - HKLM\...com [@ = ComFile] -- "%1" %*
      O37 - HKLM\...exe [@ = exefile] -- "%1" %*

      NetSvcs: 6to4 - File not found
      NetSvcs: Ias - File not found
      NetSvcs: Iprip - File not found
      NetSvcs: Irmon - File not found
      NetSvcs: NWCWorkstation - File not found
      NetSvcs: Nwsapagent - File not found
      NetSvcs: WmdmPmSp - File not found

      MsConfig - State: "system.ini" - 0
      MsConfig - State: "win.ini" - 0
      MsConfig - State: "bootini" - 0
      MsConfig - State: "services" - 0
      MsConfig - State: "startup" - 0

      SafeBootMin: Base - Driver Group
      SafeBootMin: Boot Bus Extender - Driver Group
      SafeBootMin: Boot file system - Driver Group
      SafeBootMin: File system - Driver Group
      SafeBootMin: Filter - Driver Group
      SafeBootMin: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
      SafeBootMin: PCI Configuration - Driver Group
      SafeBootMin: PNP Filter - Driver Group
      SafeBootMin: Primary disk - Driver Group
      SafeBootMin: SCSI Class - Driver Group
      SafeBootMin: sermouse.sys - Driver
      SafeBootMin: System Bus Extender - Driver Group
      SafeBootMin: vga.sys - Driver
      SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
      SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
      SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
      SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
      SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
      SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
      SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
      SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
      SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
      SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
      SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
      SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
      SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
      SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

      SafeBootNet: Base - Driver Group
      SafeBootNet: Boot Bus Extender - Driver Group
      SafeBootNet: Boot file system - Driver Group
      SafeBootNet: File system - Driver Group
      SafeBootNet: Filter - Driver Group
      SafeBootNet: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
      SafeBootNet: NDIS Wrapper - Driver Group
      SafeBootNet: NetBIOSGroup - Driver Group
      SafeBootNet: NetDDEGroup - Driver Group
      SafeBootNet: Network - Driver Group
      SafeBootNet: NetworkProvider - Driver Group
      SafeBootNet: PCI Configuration - Driver Group
      SafeBootNet: PNP Filter - Driver Group
      SafeBootNet: PNP_TDI - Driver Group
      SafeBootNet: Primary disk - Driver Group
      SafeBootNet: SCSI Class - Driver Group
      SafeBootNet: sermouse.sys - Driver
      SafeBootNet: Streams Drivers - Driver Group
      SafeBootNet: System Bus Extender - Driver Group
      SafeBootNet: TDI - Driver Group
      SafeBootNet: vga.sys - Driver
      SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
      SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
      SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
      SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
      SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
      SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
      SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
      SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
      SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
      SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
      SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
      SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
      SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
      SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
      SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
      SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
      SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
      SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

      ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics RENDERING (VML)
      ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
      ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
      ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
      ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
      ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
      ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
      ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
      ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
      ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
      ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
      ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
      ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
      ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
      ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
      ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
      ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
      ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
      ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
      ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
      ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
      ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
      ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web FOLDERS
      ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
      ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
      ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
      ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
      ActiveX: {8AD33C5C-9B70-434C-A412-9AD6EFB50373} - Microsoft Silverlight 2.0
      ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
      ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
      ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
      ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
      ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
      ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
      ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
      ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
      ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
      ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
      ActiveX: >{0CD71F12-53B7-4AAB-9324-AB16F6484AC2} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
      ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
      ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
      ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

      Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
      Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
      Drivers32: msacm.divxa32 - C:\WINDOWS\System32\DivXa32.acm (Packed With Joy !)
      Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
      Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
      Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
      Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
      Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
      Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
      Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
      Drivers32: vidc.divx - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
      Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
      Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
      Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
      Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
      Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
      Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
      Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
      Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
      Drivers32: vidc.xvid - C:\WINDOWS\System32\xvidvfw.dll ()
      Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

      ========== Files/Folders - Created Within 30 Days ==========

      [2010/11/16 00:36:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
      [2010/11/14 03:34:38 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Defender
      [2010/11/14 01:57:32 | 000,000,000 | RHSD | C] -- C:\cmdcons
      [2010/11/14 01:53:51 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
      [2010/11/14 01:53:51 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
      [2010/11/14 01:53:51 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
      [2010/11/14 01:53:51 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
      [2010/11/14 01:51:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
      [2010/11/13 20:32:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Desktop\TWA charts
      [2010/11/13 15:35:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Desktop\1989 - Oh Mercy
      [2010/11/13 15:18:09 | 000,165,584 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
      [2010/11/13 15:18:09 | 000,017,744 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
      [2010/11/13 15:18:07 | 000,023,376 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
      [2010/11/13 15:18:05 | 000,046,672 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
      [2010/11/13 15:18:03 | 000,100,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
      [2010/11/13 15:18:03 | 000,094,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
      [2010/11/13 15:18:03 | 000,028,880 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
      [2010/11/13 15:17:26 | 000,038,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
      [2010/11/13 15:17:25 | 000,167,592 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
      [2010/11/13 15:17:18 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
      [2010/11/13 15:17:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
      [2010/11/13 14:17:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
      [2010/11/11 14:44:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Desktop\back up Nov 11 2010
      [2010/11/10 23:43:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\Celemony Software GmbH
      [2010/11/10 23:42:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\VST3
      [2010/11/10 23:42:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Celemony
      [2010/11/10 23:41:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Celemony Software GmbH
      [2010/11/10 23:41:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Celemony
      [2010/11/08 05:09:39 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
      [2010/11/06 13:19:07 | 000,000,000 | ---D | C] -- C:\Qoobox
      [2010/11/04 03:55:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
      [2010/11/03 20:23:06 | 000,000,000 | ---D | C] -- C:\VritualRoot
      [2010/11/03 12:39:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\Malwarebytes
      [2010/11/03 12:39:40 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
      [2010/11/03 12:39:39 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
      [2010/11/03 12:39:39 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
      [2010/11/03 12:39:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
      [2010/11/03 03:22:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\SUPERAntiSpyware.com
      [2010/11/03 03:22:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
      [2010/11/03 03:22:13 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
      [2010/11/03 03:09:42 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Rob\Recent
      [2010/11/03 02:59:18 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
      [2010/11/03 02:45:31 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
      [2010/11/03 02:42:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Comodo
      [2010/11/02 20:30:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
      [2010/11/02 20:27:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
      [2010/11/02 19:00:08 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Documents\Server
      [2010/11/02 09:52:11 | 000,368,640 | ---- | C] (Propellerhead Software AB) -- C:\WINDOWS\System32\ReWire.dll
      [2010/10/31 00:44:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\DriverCure
      [2010/10/29 00:34:47 | 000,000,000 | ---D | C] -- C:\Program Files\u-he
      [2010/10/29 00:34:41 | 000,000,000 | ---D | C] -- C:\Program Files\Celemony
      [2010/10/27 22:40:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\Antares
      [2010/10/27 22:33:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\My Documents\Images
      [2010/10/27 22:33:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\My Documents\Audio
      [2010/10/27 22:18:39 | 000,000,000 | ---D | C] -- C:\Program Files\Antares Audio Technologies
      [2010/10/27 13:15:47 | 000,000,000 | ---D | C] -- C:\found.001
      [2010/10/26 18:15:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Desktop\UTORRENT DOWNLOADS
      [2010/10/26 18:12:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\uTorrent
      [2010/10/26 13:49:52 | 000,000,000 | ---D | C] -- C:\Program Files\Syncrosoft
      [2010/10/26 13:49:49 | 000,045,056 | ---- | C] (Syncrosoft Hard- und Software GmbH) -- C:\WINDOWS\System32\Synsopos.exe
      [2010/10/25 23:37:43 | 000,249,856 | ---- | C] (Brooks Younce Software) -- C:\Documents and Settings\Rob\Desktop\DupFinder.exe
      [2010/10/25 23:24:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\Easy Duplicate Finder
      [2010/10/23 23:32:56 | 000,134,912 | ---- | C] (ArcSoft Inc.) -- C:\WINDOWS\System32\drivers\ArcUdfs.sys
      [2010/10/23 23:32:56 | 000,036,224 | ---- | C] (ArcSoft Inc.) -- C:\WINDOWS\System32\drivers\ArcCD.sys
      [2010/10/23 23:32:56 | 000,007,680 | ---- | C] (ArcSoft Inc.) -- C:\WINDOWS\System32\drivers\ArcRec.sys
      [2010/10/21 14:47:20 | 000,000,000 | ---D | C] -- C:\Program Files\Kodak
      [2010/10/20 21:17:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\My Documents\Any Video CONVERTER
      [2010/10/20 21:16:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\AnvSoft
      [2010/10/20 21:16:33 | 000,000,000 | ---D | C] -- C:\Program Files\Any Video Converter
      [2010/10/20 21:15:17 | 016,847,824 | ---- | C] (Any-Video-Converter.com ) -- C:\Documents and Settings\Rob\Desktop\avc-free.exe
      [2010/10/20 20:29:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\My Documents\Video Converter
      [2010/10/20 20:29:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Local Settings\Application Data\Video Converter
      [2010/10/20 20:28:38 | 000,000,000 | ---D | C] -- C:\Program Files\Free Video Converter
      [2010/10/20 20:27:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\VideoConverter
      [2010/10/20 20:26:42 | 024,527,365 | ---- | C] (Extensoft) -- C:\Documents and Settings\Rob\Desktop\FreeVideoConverter.exe
      [2010/10/19 16:46:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Local Settings\Application Data\ArcSoft
      [2010/10/19 16:42:09 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\ArcSoft
      [2010/10/19 16:40:12 | 000,018,688 | ---- | C] (Arcsoft, Inc.) -- C:\WINDOWS\System32\drivers\afc.sys
      [2010/10/19 16:40:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ArcSoft
      [2010/10/19 16:39:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rob\Application Data\ArcSoft
      [2010/06/01 20:46:55 | 000,225,350 | ---- | C] ( ) -- C:\WINDOWS\rsnp2std.dll
      [2010/06/01 20:46:55 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2std.dll
      [2009/09/02 15:00:24 | 000,015,429 | R--- | C] ( ) -- C:\WINDOWS\System32\drivers\Sacm2K.sys
      [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
      [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
      [13 C:\*.tmp files -> C:\*.tmp -> ]
      [1 C:\Documents and Settings\Rob\Local Settings\Application Data\*.tmp files -> C:\Documents and Settings\Rob\Local Settings\Application Data\*.tmp -> ]

      ========== Files - Modified Within 30 Days ==========

      [2010/11/16 00:36:03 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
      [2010/11/16 00:36:03 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
      [2010/11/16 00:36:02 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
      [2010/11/16 00:36:01 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
      [2010/11/16 00:36:01 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
      [2010/11/16 00:34:52 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
      [2010/11/16 00:32:05 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
      [2010/11/16 00:31:47 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
      [2010/11/16 00:31:46 | 1073,319,936 | -HS- | M] () -- C:\hiberfil.sys
      [2010/11/15 23:44:16 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
      [2010/11/14 01:57:40 | 000,000,327 | RHS- | M] () -- C:\boot.ini
      [2010/11/13 20:47:58 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Rob\Local Settings\Application Data\prvlcl.dat
      [2010/11/13 15:18:10 | 000,001,710 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
      [2010/11/13 15:18:03 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
      [2010/11/11 21:10:01 | 000,012,477 | ---- | M] () -- C:\WINDOWS\System32\234.js
      [2010/11/11 16:23:45 | 000,000,515 | ---- | M] () -- C:\Documents and Settings\Rob\Desktop\Shortcut to Incoming.lnk
      [2010/11/10 04:10:17 | 000,001,673 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\FileZilla Client.lnk
      [2010/11/08 18:36:54 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
      [2010/11/08 05:09:39 | 000,001,980 | ---- | M] () -- C:\Documents and Settings\Rob\Desktop\HiJackThis.lnk
      [2010/11/08 01:20:24 | 000,089,088 | ---- | M] () -- C:\WINDOWS\MBR.exe
      [2010/11/05 00:08:05 | 000,000,211 | ---- | M] () -- C:\Boot.bak
      [2010/11/03 00:06:41 | 000,290,088 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
      [2010/11/02 08:54:47 | 000,000,834 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Cubase SX 3.lnk
      [2010/10/31 12:38:49 | 000,397,560 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
      [2010/10/31 12:38:49 | 000,059,780 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
      [2010/10/26 21:17:20 | 000,000,801 | ---- | M] () -- C:\Documents and Settings\Rob\Desktop\Cubase SX.lnk
      [2010/10/25 18:29:47 | 000,000,029 | ---- | M] () -- C:\WINDOWS\AudACM.ini
      [2010/10/24 11:55:42 | 000,001,245 | ---- | M] () -- C:\Documents and Settings\Rob\Desktop\everything is broken.rtf
      [2010/10/23 19:42:24 | 000,000,419 | ---- | M] () -- C:\WINDOWS\cdplayer.ini
      [2010/10/20 21:17:00 | 000,000,725 | ---- | M] () -- C:\Documents and Settings\Rob\Desktop\Any Video Converter.lnk
      [2010/10/20 21:15:17 | 016,847,824 | ---- | M] (Any-Video-Converter.com ) -- C:\Documents and Settings\Rob\Desktop\avc-free.exe
      [2010/10/20 20:26:54 | 024,527,365 | ---- | M] (Extensoft) -- C:\Documents and Settings\Rob\Desktop\FreeVideoConverter.exe
      [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
      [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
      [13 C:\*.tmp files -> C:\*.tmp -> ]
      [1 C:\Documents and Settings\Rob\Local Settings\Application Data\*.tmp files -> C:\Documents and Settings\Rob\Local Settings\Application Data\*.tmp -> ]

      ========== Files Created - No Company Name ==========

      [2010/11/16 00:12:58 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
      [2010/11/14 03:37:51 | 000,000,330 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
      [2010/11/14 01:57:40 | 000,000,211 | ---- | C] () -- C:\Boot.bak
      [2010/11/14 01:57:35 | 000,260,272 | RHS- | C] () -- C:\cmldr
      [2010/11/14 01:53:51 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
      [2010/11/14 01:53:51 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
      [2010/11/14 01:53:51 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
      [2010/11/14 01:53:51 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
      [2010/11/13 15:18:10 | 000,001,710 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
      [2010/11/13 14:03:38 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
      [2010/11/10 04:10:17 | 000,001,673 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\FileZilla Client.lnk
      [2010/11/10 04:10:03 | 000,012,477 | ---- | C] () -- C:\WINDOWS\System32\234.js
      [2010/11/08 05:09:39 | 000,001,980 | ---- | C] () -- C:\Documents and Settings\Rob\Desktop\HiJackThis.lnk
      [2010/11/03 12:33:11 | 1073,319,936 | -HS- | C] () -- C:\hiberfil.sys
      [2010/11/02 21:25:57 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
      [2010/11/02 09:07:41 | 002,402,025 | ---- | C] () -- C:\WINDOWS\System32\dongle.dll
      [2010/11/02 08:54:47 | 000,000,834 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Cubase SX 3.lnk
      [2010/10/26 21:17:20 | 000,000,801 | ---- | C] () -- C:\Documents and Settings\Rob\Desktop\Cubase SX.lnk
      [2010/10/24 11:55:42 | 000,001,245 | ---- | C] () -- C:\Documents and Settings\Rob\Desktop\everything is broken.rtf
      [2010/10/20 21:17:00 | 000,000,725 | ---- | C] () -- C:\Documents and Settings\Rob\Desktop\Any Video Converter.lnk
      [2010/06/01 20:46:57 | 000,015,497 | ---- | C] () -- C:\WINDOWS\snp2std.ini
      [2010/06/01 20:46:55 | 010,192,896 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2sxp.sys
      [2010/03/20 14:15:14 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Rob\Local Settings\Application Data\prvlcl.dat
      [2010/03/04 13:42:39 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\CommonDL.dll
      [2010/03/04 13:42:39 | 000,002,412 | ---- | C] () -- C:\WINDOWS\System32\lgAxconfig.ini
      [2010/01/29 17:27:28 | 000,000,419 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
      [2010/01/12 21:26:23 | 000,005,103 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\amjmwaey.gaf
      [2010/01/12 02:00:49 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
      [2009/11/03 17:48:21 | 000,000,051 | ---- | C] () -- C:\WINDOWS\npornap.INI
      [2009/10/30 14:51:15 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
      [2009/10/21 17:06:03 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
      [2009/10/15 02:56:31 | 000,000,155 | ---- | C] () -- C:\WINDOWS\winamp.ini
      [2009/10/09 20:16:31 | 000,189,952 | ---- | C] () -- C:\Documents and Settings\Rob\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
      [2009/10/06 13:27:58 | 000,400,384 | ---- | C] () -- C:\WINDOWS\System32\SYNSOACC.dll
      [2009/09/24 12:27:36 | 001,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
      [2009/09/24 12:27:36 | 000,585,728 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
      [2009/09/11 15:05:30 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
      [2009/09/11 15:05:15 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
      [2009/09/08 15:14:46 | 000,000,030 | R--- | C] () -- C:\WINDOWS\System32\drivers\RevHDD.ini
      [2009/09/07 21:28:16 | 000,000,029 | ---- | C] () -- C:\WINDOWS\AudACM.ini
      [2009/09/07 12:09:23 | 000,000,312 | ---- | C] () -- C:\WINDOWS\MusicStudio.INI
      [2009/09/07 12:09:23 | 000,000,047 | ---- | C] () -- C:\WINDOWS\SamControlpanel95.INI
      [2009/09/07 11:37:43 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\mgxasio2.dll
      [2009/09/07 11:36:49 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll
      [2009/09/07 11:35:46 | 000,005,937 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini
      [2009/09/04 17:06:34 | 000,003,637 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
      [2009/09/04 17:06:32 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
      [2009/09/02 16:37:42 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
      [2009/09/02 15:00:24 | 000,053,693 | R--- | C] () -- C:\WINDOWS\UNDPX2K.sys
      [2009/08/27 20:04:44 | 000,557,003 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
      [2009/08/27 20:04:32 | 000,811,835 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
      [2009/08/27 20:03:52 | 004,456,201 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
      [2009/08/25 19:07:36 | 000,328,334 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
      [2009/08/25 18:38:04 | 000,425,040 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
      [2009/08/25 17:37:02 | 000,146,098 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
      [2009/06/02 18:15:44 | 000,113,152 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
      [2009/06/02 18:15:18 | 000,146,944 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
      [2009/06/02 18:15:04 | 000,183,296 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
      [2009/06/02 18:14:56 | 000,178,688 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
      [2009/06/02 18:14:30 | 000,486,400 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
      [2009/06/02 18:13:58 | 000,257,024 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
      [2009/06/02 18:13:50 | 000,142,848 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
      [2009/06/02 18:11:26 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
      [2009/06/02 18:11:16 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
      [2009/01/10 23:17:32 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
      [2009/01/10 23:16:56 | 000,148,480 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
      [2009/01/10 23:16:50 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
      [2009/01/10 23:16:14 | 000,141,312 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
      [2009/01/10 23:15:54 | 000,120,832 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
      [2009/01/10 23:15:44 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\mmfinfo.dll
      [2009/01/10 23:15:32 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
      [2009/01/10 23:15:28 | 000,246,784 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
      [2009/01/10 23:15:12 | 000,097,280 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
      [2009/01/10 23:14:08 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
      [2009/01/10 23:14:06 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
      [2008/11/06 17:37:32 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
      [2007/10/13 10:30:20 | 000,000,137 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini
      [2004/07/17 10:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
      [2003/02/19 01:26:28 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
      [2002/06/06 01:01:58 | 000,029,696 | ---- | C] () -- C:\WINDOWS\System32\asutl8.dll
      [2001/07/07 02:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini

      ========== LOP Check ==========

      [2010/11/13 15:17:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
      [2010/11/14 01:35:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
      [2010/11/10 23:43:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Celemony Software GmbH
      [2010/03/24 17:14:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Whiz
      [2010/10/03 17:06:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Empress Effects Inc
      [2010/10/04 14:37:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileCure
      [2010/02/27 18:17:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\flag ace stupid data
      [2009/10/06 13:07:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
      [2010/04/07 18:47:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LGMOBILEAX
      [2010/03/12 17:11:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MAGIX
      [2010/11/13 14:27:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
      [2009/10/06 13:28:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
      [2009/12/02 21:01:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spell Check Anywhere
      [2010/10/20 20:27:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VideoConverter
      [2010/09/30 19:30:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
      [2009/10/24 13:35:39 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
      [2010/10/27 22:40:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Antares
      [2010/07/29 01:09:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Anvil Studio
      [2010/10/20 21:16:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\AnvSoft
      [2010/11/11 00:50:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Celemony Software GmbH
      [2010/10/31 00:44:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\DriverCure
      [2010/10/25 23:36:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Easy Duplicate Finder
      [2010/11/13 15:11:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\FileZilla
      [2010/01/21 20:06:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\FreeVideoConverter
      [2010/03/24 17:19:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\GetRightToGo
      [2009/10/06 20:41:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\GlobalSCAPE
      [2010/07/02 09:40:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Image Zone Express
      [2010/04/07 19:57:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\LG Electronics
      [2009/10/31 18:10:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Likno
      [2010/01/21 20:18:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Search Settings
      [2009/10/14 00:40:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Softplicity
      [2010/10/28 00:55:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Steinberg
      [2009/12/11 13:39:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\Thunderbird
      [2010/11/13 14:10:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\uTorrent
      [2010/10/07 23:33:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\WhiteSmokeSetup
      [2010/10/04 14:19:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rob\Application Data\WhiteSmokeTranslator
      [2010/11/16 00:36:01 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
      [2010/11/16 00:36:01 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
      [2010/11/16 00:36:02 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
      [2010/11/16 00:36:03 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
      [2010/11/16 00:36:03 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
      [2010/11/16 00:34:52 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job

      ========== Purity Check ==========



      ========== Custom Scans ==========


      < %SYSTEMDRIVE%\*.exe >

      < %systemroot%\*. /mp /s >

      < c:\$recycle.bin\*.* /s >

      < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-09-02 14:34:02


      < MD5 for: AGP440.SYS >
      [2004/08/04 00:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
      [2004/08/04 00:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\ERDNT\cache\AGP440.SYS
      [2004/08/04 00:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\AGP440.SYS

      < MD5 for: ATAPI.SYS >
      [2004/08/04 00:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
      [2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
      [2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys

      < MD5 for: AUTOCHK.EXE >
      [2004/08/03 23:56:48 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=B3415B9D6026F65E43089ABED096C38C -- C:\cmdcons\autochk.exe
      [2004/08/03 23:56:48 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=B3415B9D6026F65E43089ABED096C38C -- C:\WINDOWS\system32\autochk.exe
      [2004/08/03 23:56:48 | 000,588,800 | ---- | M] (Microsoft Corporation) MD5=B3415B9D6026F65E43089ABED096C38C -- C:\WINDOWS\system32\dllcache\autochk.exe

      < MD5 for: BEEP.SYS >
      [2002/08/29 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\ERDNT\cache\beep.sys
      [2002/08/29 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\dllcache\beep.sys
      [2002/08/29 13:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\drivers\beep.sys

      < MD5 for: EVENTLOG.DLL >
      [2004/08/03 23:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
      [2004/08/03 23:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\dllcache\eventlog.dll
      [2004/08/03 23:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll

      < MD5 for: EXPLORER.EXE >
      [2004/08/03 23:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\ERDNT\cache\explorer.exe
      [2004/08/03 23:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\explorer.exe
      [2004/08/03 23:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\system32\dllcache\explorer.exe

      < MD5 for: IMM32.DLL >
      [2004/08/03 23:56:44 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=87CA7CE6469577F059297B9D6556D66D -- C:\WINDOWS\ERDNT\cache\imm32.dll
      [2004/08/03 23:56:44 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=87CA7CE6469577F059297B9D6556D66D -- C:\WINDOWS\system32\dllcache\imm32.dll
      [2004/08/03 23:56:44 | 000,110,080 | ---- | M] (Microsoft Corporation) MD5=87CA7CE6469577F059297B9D6556D66D -- C:\WINDOWS\system32\imm32.dll

      < MD5 for: KERNEL32.DLL >
      [2004/08/03 23:56:44 | 000,983,552 | ---- | M] (Microsoft Corporation) MD5=888190E31455FAD793312F8D087146EB -- C:\WINDOWS\ERDNT\cache\kernel32.dll
      [2004/08/03 23:56:44 | 000,983,552 | ---- | M] (Microsoft Corporation) MD5=888190E31455FAD793312F8D087146EB -- C:\WINDOWS\system32\dllcache\kernel32.dll
      [2004/08/03 23:56:44 | 000,983,552 | ---- | M] (Microsoft Corporation) MD5=888190E31455FAD793312F8D087146EB -- C:\WINDOWS\system32\kernel32.dll

      < MD5 for: MSWSOCK.DLL >
      [2004/08/03 23:56:46 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=4E74AF063C3271FBEA20DD940CFD1184 -- C:\WINDOWS\ERDNT\cache\mswsock.dll
      [2004/08/03 23:56:46 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=4E74AF063C3271FBEA20DD940CFD1184 -- C:\WINDOWS\system32\dllcache\mswsock.dll
      [2004/08/03 23:56:46 | 000,245,248 | ---- | M] (Microsoft Corporation) MD5=4E74AF063C3271FBEA20DD940CFD1184 -- C:\WINDOWS\system32\mswsock.dll

      < MD5 for: NDIS.SYS >
      [2004/08/03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\ERDNT\cache\ndis.sys
      [2004/08/03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys
      [2004/08/03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys

      < MD5 for: NETLOGON.DLL >
      [2004/08/03 23:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\ERDNT\cache\netlogon.dll
      [2004/08/03 23:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll
      [2004/08/03 23:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll

      < MD5 for: NTFS.SYS >
      [2004/08/03 23:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\cmdcons\NTFS.SYS
      [2004/08/03 22:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\WINDOWS\ERDNT\cache\ntfs.sys
      [2004/08/03 22:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\WINDOWS\system32\dllcache\ntfs.sys
      [2004/08/03 22:15:10 | 000,574,592 | ---- | M] (Microsoft Corporation) MD5=B78BE402C3F63DD55521F73876951CDD -- C:\WINDOWS\system32\drivers\ntfs.sys

      < MD5 for: NTMSSVC.DLL >
      [2004/08/03 23:56:46 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=B62F29C00AC55A761B2E45877D85EA0F -- C:\WINDOWS\ERDNT\cache\ntmssvc.dll
      [2004/08/03 23:56:46 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=B62F29C00AC55A761B2E45877D85EA0F -- C:\WINDOWS\system32\dllcache\ntmssvc.dll
      [2004/08/03 23:56:46 | 000,435,200 | ---- | M] (Microsoft Corporation) MD5=B62F29C00AC55A761B2E45877D85EA0F -- C:\WINDOWS\system32\ntmssvc.dll

      < MD5 for: PROQUOTA.EXE >
      [2004/08/03 23:56:56 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=4D9D45A4370E0C2AD00C362B7118E2A4 -- C:\WINDOWS\system32\dllcache\proquota.exe
      [2004/08/03 23:56:56 | 000,050,176 | ---- | M] (Microsoft Corporation) MD5=4D9D45A4370E0C2AD00C362B7118E2A4 -- C:\WINDOWS\system32\proquota.exe

      < MD5 for: QMGR.DLL >
      [2004/08/03 23:56:46 | 000,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\ERDNT\cache\qmgr.dll
      [2004/08/03 23:56:46 | 000,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\system32\dllcache\qmgr.dll
      [2004/08/03 23:56:46 | 000,382,464 | ---- | M] (Microsoft Corporation) MD5=2C69EC7E5A311334D10DD95F338FCCEA -- C:\WINDOWS\system32\qmgr.dll

      < MD5 for: SCECLI.DLL >
      [2004/08/03 23:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\ERDNT\cache\scecli.dll
      [2004/08/03 23:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\dllcache\scecli.dll
      [2004/08/03 23:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll

      < MD5 for: SFCFILES.DLL >
      [2004/08/03 23:56:46 | 001,580,544 | ---- | M] (Microsoft Corporation) MD5=30A609E00BD1D4FFC49D6B5A432BE7F2 -- C:\WINDOWS\ERDNT\cache\sfcfiles.dll
      [2004/08/03 23:56:46 | 001,580,544 | ---- | M] (Microsoft Corporation) MD5=30A609E00BD1D4FFC49D6B5A432BE7F2 -- C:\WINDOWS\system32\dllcache\sfcfiles.dll
      [2004/08/03 23:56:46 | 001,580,544 | ---- | M] (Microsoft Corporation) MD5=30A609E00BD1D4FFC49D6B5A432BE7F2 -- C:\WINDOWS\system32\sfcfiles.dll

      < MD5 for: SPOOLSV.EXE >
      [2004/08/03 23:56:58 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=7435B108B935E42EA92CA94F59C8E717 -- C:\WINDOWS\ERDNT\cache\spoolsv.exe
      [2004/08/03 23:56:58 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=7435B108B935E42EA92CA94F59C8E717 -- C:\WINDOWS\system32\dllcache\spoolsv.exe
      [2004/08/03 23:56:58 | 000,057,856 | ---- | M] (Microsoft Corporation) MD5=7435B108B935E42EA92CA94F59C8E717 -- C:\WINDOWS\system32\spoolsv.exe

      < MD5 for: SRSVC.DLL >
      [2004/08/03 23:56:46 | 000,170,496 | ---- | M] (Microsoft Corporation) MD5=92BDF74F12D6CBEC43C94D4B7F804838 -- C:\WINDOWS\ERDNT\cache\srsvc.dll
      [2004/08/03 23:56:46 | 000,170,496 | ---- | M] (Microsoft Corporation) MD5=92BDF74F12D6CBEC43C94D4B7F804838 -- C:\WINDOWS\system32\dllcache\srsvc.dll
      [2004/08/03 23:56:46 | 000,170,496 | ---- | M] (Microsoft Corporation) MD5=92BDF74F12D6CBEC43C94D4B7F804838 -- C:\WINDOWS\system32\srsvc.dll

      < MD5 for: SVCHOST.EXE >
      [2004/08/03 23:56:58 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4EHow's your computer running now?

      I'd like to scan your machine with ESET OnlineScan

      •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
      ESET OnlineScan
      •Click the button.
      •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      • Click on to download the ESET Smart Installer. Save it to your desktop.
      • Double click on the icon on your desktop.
      •Check
      •Click the button.
      •Accept any security warnings from your browser.
      •Check
      •Push the Start button.
      •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      •When the scan completes, push
      •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
      •Push the button.
      •Push
      A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

      SuperDave!

      Quote
      How's your computer running now?

      Better malware symtoms seem to be gone.

      here is the ESET log:

      C:\Documents and Settings\All Users\Documents\Server\hlp.datWin32/Bamital.EK trojancleaned by deleting - quarantined
      C:\Documents and Settings\Rob\Desktop\back up Nov 11 2010\Incoming\adobe premier pro 7 serial.zipprobably a variant of Win32/Spy.Agent.MJJETOK trojandeleted - quarantined
      C:\Documents and Settings\Rob\Desktop\back up Nov 11 2010\VST Native Instruments B4 II + KeyGen\b4 II\(Vst Plug-In) Native Instruments Hammond b4 v1.11.zipa variant of Win32/Keygen.AA applicationdeleted - quarantined
      C:\Documents and Settings\Rob\Desktop\back up Nov 11 2010\VST Native Instruments B4 II + KeyGen\keygen b4 II\h-nib42a.zipa variant of Win32/Keygen.AA applicationdeleted - quarantined
      C:\Program Files\Trend Micro\HiJackThis\backups\backup-20101109-135051-994.dllWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined
      C:\Qoobox\Quarantine\MBR_HardDisk0.mbrWin32/Olmarik.ADA trojancleaned by deleting - quarantined
      C:\Qoobox\Quarantine\C\Program Files\Search Settings\SearchSettings.exe.virWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined
      C:\Qoobox\Quarantine\C\Program Files\Search Settings\SearchSettingsRes409.dll.virWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined
      C:\Qoobox\Quarantine\C\Program Files\Search Settings\SearchSettings_AVG_RESTORED.exe.virWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined
      C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP11\A0029830.exemultiple threatsdeleted - quarantined
      C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP15\A0035135.exeWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined
      C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP15\A0035136.exeWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined
      C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP15\A0035137.dllWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined
      C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP2\A0004339.exeNSIS/TrojanDownloader.FakeAlert.DK.Gen trojandeleted - quarantined
      C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP20\A0040902.dllWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined
      C:\System Volume Information\_restore{09DE9538-F9A6-4E16-9F05-01F1FA9ECC38}\RP6\A0021602.dllWin32/Adware.Toolbar.Dealio applicationcleaned by deleting - quarantined
      That's good news. If there are no other issues, let's do some cleanup.

      * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.
      * Now type commy /uninstall in the runbox
      * Make sure there's a space between commy and /Uninstall
      * Then hit Enter

      * The above procedure will:
      * Delete the following:
      * ComboFix and its associated files and folders.
      * Reset the clock settings.
      * Hide file extensions, if required.
      * Hide System/Hidden files, if required.
      * Set a new, clean Restore Point.

      ******************************
      To remove all of the tools we used and the files and folders they created do the following:
      Double click OTL.exe.
      • Click the CleanUp button.
      • Select Yes when the "Begin cleanup Process?" prompt appears.
      • If you are prompted to Reboot during the cleanup, select Yes.
      • The tool will delete itself once it finishes.
      Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
      ******************************************
      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
      ****************************************
      Use the Secunia Software Inspector to check for out of date software.

      •Click Start Now

      •Check the box next to Enable thorough system inspection.

      •Click Start

      •Allow the scan to finish and scroll down to see if any updates are needed.
      •Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe Surfing! ;DSuperDave!
      Sorry it took so long to reply, i was called out of town for work.
      Thank you the computer is running much better now and seems to be malware free
      I can't uninstal SuperAntiSpyware though
      I would suggest that you keep SAS and MBAM. Update them and run them about once a week to keep your computer clean.
      330.

      Solve : Google redirect & random ads?

      Answer»

      Ok. How's your computer running now?it goes back to normal now. no more redirect or ads. thank you very much daveThat good. It's time for some cleanup.

      To remove all of the tools we used and the files and folders they created do the following:
      Double click OTL.exe.

      • Click the CleanUp button.
      • Select Yes when the "Begin cleanup Process?" prompt appears.
      • If you are prompted to Reboot during the cleanup, select Yes.
      • The tool will delete itself once it finishes.
      Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
      ******************************************
      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have SAVED all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
      ***************************************
      To set a new Restore Point.

      Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box NEXT to the disk, and then click OK. Reboot to Normal Mode.
      Click the Start button , click Control Panel, click System and Maintenance, and then click System.
      In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
      To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
      ********************************************
      Some information about third-party firewalls.

      Firewalls protect against hackers and malicious intruders. You need to download a free firewall from ONE of these reliable vendors.

      Remember only install ONE firewall

      1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
      2) Online Armor
      3) Agnitum Outpost
      4) PC Tools Firewall Plus

      If you are using the built-in Windows XP firewall, it is not recommended as it does not BLOCK outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
      **********************************************
      Use the Secunia Software Inspector to check for out of date software.

      •Click Start Now

      •Check the box next to Enable thorough system inspection.

      •Click Start

      •Allow the scan to finish and scroll down to see if any updates are needed.
      •Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's EASY and it's free.

      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe Surfing!
      So should I keep both the Superantimalware and MBAM or just one of them and download the Spybot-search and destroy?

      And which of the firewall would you most recommend? Comodo personal firewall?Quote
      So should I keep both the Superantimalware and MBAM or just one of them and download the Spybot-search and destroy?
      Yes. It wouldn't hurt to run their scans every so often to keep the bugs out.

      Quote
      And which of the firewall would you most recommend? Comodo personal firewall?
      I'm running Comodo now. It takes a bit of getting used but after a while you don't know it's even there. It's the price you pay for being secure.thanks for answering my questions. I have one more question if you don't mind answering. Is the spywareblaster and spybot have similar function? Do I need to have both of them?They target different malware.ok got it. thanks a lot for your help again
      331.

      Solve : Zlob-LO Virus?

      Answer»

      Please do a search for that file. Go to Start, Search, All files or folders and copy and paste the file in the code box below to see if it's still there.

      Code: [Select]C:\Documents and Settings\Luna\Application Data\Sun\Java\Deployment\cache\6.0\44\1f28756c-6ad594e5
      Found it and deleted itGood. How's your computer running now?Everything seems to be running smoothQuote

      Everything seems to be running smooth
      Good. Let's do some cleanup.

      * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.
      * Now type commy /uninstall in the runbox
      * Make sure there's a space between commy and /Uninstall
      * Then hit Enter

      * The above procedure will:
      * Delete the following:
      * ComboFix and its associated files and folders.
      * Reset the clock settings.
      * Hide file extensions, if required.
      * Hide System/Hidden files, if required.
      * Set a new, clean Restore Point.
      **********************************
      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
      *******************************************
      Looking over your log it seems you don't have any evidence of a third party firewall.

      Firewalls protect against hackers and malicious intruders. You need to download a FREE firewall from one of these reliable vendors.

      Remember only install ONE firewall

      1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
      2) Online Armor
      3) Agnitum Outpost
      4) PC Tools Firewall Plus

      If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone HOME" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
      **************************************************************
      Use the Secunia Software Inspector to check for out of date software.

      •Click Start Now

      •Check the box next to Enable thorough system inspection.

      •Click Start

      •Allow the scan to finish and scroll down to see if any updates are needed.
      •Update anything LISTED.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. ALSO stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe SURFING!

      Great, steps taken and onward to a safer journey. Much Thanks!
      332.

      Solve : My 1st bad, (?) virus: I don't even know where to start on this. I'm stuck...?

      Answer»

      Dave:

      It ran for a long time, but showing progress continually. I think it scanned OK. However, at the end it, "found no infections." Hence, (I think), it offered NO option for keeping a log.

      My novice opinion can be no other than to think it just didn't find anything to do.

      ??

      I finished, and chose the uninstall option. I can do this over again if you wish or if I did anything wrong. But it acted fine.

      DennisSo, how's your computer working now?Based on everything I now observe, my laptop seems perfectly healthy. That appearing to be the situation, my only remaining desire is to load whatever basic protection programs that are appropriate, that I do not now have.

      Judging from what I remember of your signature line, you run AV, (AVG?), SpyBot and maybe the SuperSpyWare you had me run. I'm open for basic recommendations.

      You may have noticed I'm not quick to jump up and say everything is fixed. That's because I have a bit of mis-trust for computers.

      What do things look like to you?

      DennisWe ran a lot of scans and haven't picked anything too serious. Let's do some cleanup.
      You may keep SAS and MBAM. Update them and run them every so often to keep the bugs out.

      * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.
      * Now type commy /uninstall in the runbox
      * Make sure there's a space between commy and /Uninstall
      * Then hit Enter

      * The above procedure will:
      * Delete the following:
      * ComboFix and its associated files and folders.
      * Reset the clock settings.
      * Hide file extensions, if required.
      * Hide System/Hidden files, if required.
      * Set a new, clean Restore Point.
      *********************************
      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
      **************************************
      Looking over your log it seems you don't have any evidence of a third party firewall.

      Firewalls protect against hackers and malicious INTRUDERS. You need to download a free firewall from one of these reliable vendors.

      Remember only install ONE firewall

      1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
      2) Online Armor
      3) Agnitum Outpost
      4) PC Tools Firewall Plus

      If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
      *********************************
      Use the Secunia Software Inspector to check for out of date software.

      •Click Start Now

      •Check the box next to Enable thorough system inspection.

      •Click Start

      •Allow the scan to finish and scroll down to see if any updates are needed.
      •Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe Surfing!
      Dave:

      Evidently I already uninstalled Commy earlier when I was following one of your directives and had trouble, "turning off," programs. (So I uninstalled it) All that I had was the desktop icon, which in now deleted. I hope this didn't hurt anything.

      I created a restore point.

      I ran TFC and re-started.

      I loaded a firewall....choosing Online Armor. QUESTION: How do I find out if I'm using the MS firewall? Apparently, my wireless router is not a firewall as I've been told. (I thought I was good already for firewalls)

      I brought up Secunia, but it wants Sun Java. I guess I don't have that. It's been a long day, I'll continue with downloading Java tomorrow. (So far, I've often avoided Java)

      DennisQuote

      Question: How do I find out if I'm using the MS firewall? Apparently, my wireless router is not a firewall as I've been told. (I thought I was good already for firewalls)
      Look for it in the Control Panel under Windows Firewall or the Security Center. Java is your choice.Dave:

      After a few sessions here's where I stand:

      MS Firewall is in this laptop, however, it was and is disabled.

      I ran Secunia and updated that list.

      I am now updating MS Windows update.

      I will nex add Web of Trust.

      I've never used SpyWare Blaster, but will add that too.

      I'll update, again, SpyBot.

      ?

      DennisDave:

      Thank you so much for all your help. Things look like they are running fine now. Plus, I've learned a lot. You are a great benefit to the forum.

      Cheers,
      Dennis
      333.

      Solve : Mouse/screen pointer freezes near end of laptop startup?

      Answer» WELL, Dave, if you're energetic enough to check this post of mine too, this is a very similar, but different laptop. When I told my wife you fixed the floater laptop, she rushed in with her's that she's not used for about 3 months. HP 4800, XP WINDOWS. I fired it up and all looked fine until just after the start screen populated with icons. Then pointer/MOUSE pad freezes. Hard power down and a few restarts produced no better results. It has AVG, but certainly needs updating.

      This machine has been used at times with external mouse. I tried that as well. Nothing. I can hit numeric key and it toggles light back-and-forth which I read is a GOOD sign. There is some minimal access to arrow keys being useful, but not entirely.

      So I guess I need to figure out how to work-around the freeze to get something going. I once used safe mode, but it's been a LONG time.

      ??

      DennisAfter a few attempted restarts, when powered down, I tried the external mouse in a different USB port and it worked when I fired it back up.

      ?? Beats me.

      Thank you; this request can be closed now.

      Dennis
      334.

      Solve : Tidserv?

      Answer»

      Quote

      Also can I run a live update with "Symantec Endpoint" or will it interfere with all the programs that were installed to help resolve my issues?
      Yes. Go ahead and run it . We will be removing those programs now. You may keep SAS and MBAM, if you wish. Update them and run them every so often to keep the bugs out.

      Quote
      Also I am currently using Mozilla and it is asking me to upgrade, should I.

      If I am to upgrade to latest Mozilla should I delete old one first.
      Mozilla is a safer browser than Internet Explorer. Not sure about Chrome. You can just download the updates and it will install over itself and it will save all your settings.

      * Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.
      * Now type Combofix /uninstall in the runbox
      * Make sure there's a space between Combofix and /Uninstall
      * Then hit Enter

      * The above procedure will:
      * Delete the following:
      * ComboFix and its associated files and folders.
      * Reset the clock settings.
      * Hide file extensions, if required.
      * Hide System/Hidden files, if required.
      * Set a new, clean Restore Point.
      *******************************
      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
      ******************************************
      Use the Secunia Software Inspector to check for out of date software.

      •Click Start Now

      •Check the box next to Enable thorough system inspection.

      •Click Start

      •Allow the scan to finish and scroll down to see if any updates are needed.
      •Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe Surfing!

      Thanks for all your help !!

      Just wondering do I keep Symantec Endpoint with all the programs that I downloaded like Malwarebytes, SUPERantispyware, spybot, spywarebuster and HijackThis. Can you run all these programs at the same time?


      Thanks again !!!Quote
      Just wondering do I keep Symantec Endpoint with all the programs that I downloaded like Malwarebytes, SUPERantispyware, spybot, spywarebuster and HijackThis. Can you run all these programs at the same time?
      You can uninstall HiJackThis. We won't need it anymore. You may keep SAS, MBAM and Spybot. Keep them updated and run the scans every so often to keep your computer clean and for peace of mind. SpywareBlaster can be uninstalled but it won't hurt to keep it running.

      Hey SuperDave,

      What about TDSSKiller should it still be on my system?

      Also will there be any problems when I run Symantec Endpoint at the same time as all these other programs in my system?

      Sorry just want to make sure because from what I heard, running more than one system will CAUSE your system to crash? Is this true ??The systems conflict with each other??? Remember I'm a rookie Ha Ha

      Thanks again. Quote
      What about TDSSKiller should it still be on my system?
      Ok. Please delete it.

      Quote
      Also will there be any problems when I run Symantec Endpoint at the same time as all these other programs in my system?

      Sorry just want to make sure because from what I heard, running more than one system will cause your system to crash? Is this true ??The systems conflict with each other??? Remember I'm a rookie Ha Ha

      No. The only things you should only have one of, is your Anti-Virus and your Firewall. I run at least 4 malware programs on my computer with no problem.
      You can try running this tool to check to see what's running at start-up. Also, read the link I mentioned earlier in my closing speech about Slow computer for maintenance you can do to improve performance.
      StartupLite

      Download StartupLite by MalwareBytes to your Desktop.
      Doubleclick StartupLite.exe to launch the program.
      Ensure the Disable box is checked.
      Click Continue.
      A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
      Re-start your computer.
      Do you think with this "Tidserv" virus that any of my passwords have been comprised ?? Or was it strictly hijacking web searches and web pages ?

      Thanks again for all your help in ridding my computer of this problem!!! Tidserv is known as a backdoor trojan but all the scans didn't reveal this infection. However, we did find and fixed a rootkit infection.
      We cannot guarantee that your computer is 100% clean.
      While looking over this thread I realized that I had FORGOT one important scan. I will also give you some information about rootkits and then the decision will be up to you on your course of action. If you don't use your computer for financial transactions it shouldn't bother you too much.

      I'd like to scan your machine with ESET OnlineScan

      •Hold down CONTROL and click on the following link to open ESET OnlineScan in a new window.
      ESET OnlineScan
      •Click the button.
      •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      • Click on to download the ESET Smart Installer. Save it to your desktop.
      • Double click on the icon on your desktop.
      •Check
      •Click the button.
      •Accept any security warnings from your browser.
      •Check
      •Push the Start button.
      •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      •When the scan completes, push
      •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
      •Push the button.
      •Push
      A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
      *****************************************
      It appears your system was infected with a rootkit. A rootkit is a powerful piece of malware, that allows hackers full control over your computer for means of sending attacks over the Internet, or using your computer to generate revenue.

      Malware experts have recommended that we make it clear that with the system under control of a hacker, your computer might become impossible to clean 100%.

      Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. They can disable your antivirus and security tools to prevent detection and removal. This type of exploit allows them to steal sensitive information like passwords, personal and financial data which is sent back to the hacker. To learn more about these types of infections, you can refer to:

      What danger is presented by rootkits?
      Rootkits and how to combat them
      r00tkit Analysis: What Is A Rootkit

      If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable. Do NOT change passwords or do any transactions while using the infected computer because the attacker may get the new passwords and transaction information. (If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again.) Banking and credit card institutions should be notified to apprise them of your situation (possible security breach). To protect your information that may have been compromised, I recommend reading these references:
      How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
      What Should I Do If I've Become A Victim Of Identity Theft?
      Identity Theft Victims Guide - What to do
      It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed. In some instances an infection may have caused so much damage to your system that it cannot
      be completely cleaned or repaired so you can never be sure that you have completely removed a rootkit. The malware may leave so many remnants behind that security tools cannot find them. Tools that claim to be able to remove rootkits cannot guarantee that all traces of it will be removed. Many experts in the security community believe that once infected with such a piece of malware, the best course of action would be a reformat and clean reinstall of the OS. This is something I don't like to recommend normally, but in most cases it is the best solution for your safety. Making this decision is based on what the computer is used for, and what information can be accessed from it. For more information, please read these references very carefully:
      When should I re-format? How should I reinstall?
      Help: I Got Hacked. Now What Do I Do?
      Help: I Got Hacked. Now What Do I Do? Part II
      Where to draw the line? When to recommend a format and reinstall?

      Guides for format and reinstall:

      how-to-reformat-and-reinstall-your-operating-system-the-easy-way

      However, if you do not have the resources to reinstall your computer's OS and would like me to attempt to clean it, I will be happy to do so. But please consider carefully before deciding against a reformat.
      If you do make that decision, I will do my best to help you clean the computer of any infections, but you must understand that once a machine has been taken over by this type of malware, I cannot guarantee that it will be 100% secure even after disinfection or that the removal will be successful.

      Please let me know what you have DECIDED to do in your next post. Should you have any questions, please feel free to ask.
      The scan ran for about 25 minutes and found no THREATS (0 threats) the following is the log from eset:

      [emailprotected] as downloader log:
      all ok
      # version=7
      # OnlineScannerApp.exe=1.0.0.1
      # OnlineScanner.ocx=1.0.0.6211
      # api_version=3.0.2
      # EOSSerial=9dd46370711cd64da8d35ff45b4f10f7
      # end=finished
      # remove_checked=false
      # archives_checked=true
      # unwanted_checked=true
      # unsafe_checked=false
      # antistealth_checked=true
      # utc_time=2010-11-23 03:22:10
      # local_time=2010-11-23 10:22:10 (-0500, Eastern Standard Time)
      # country="Canada"
      # lang=1033
      # osver=5.1.2600 NT Service Pack 3
      # compatibility_mode=512 16777215 100 0 1314078 1314078 0 0
      # compatibility_mode=8192 67108863 100 0 0 0 0 0
      # scanned=48118
      # found=0
      # cleaned=0
      # scan_time=2934

      Upon completeion Eset asked if I wanted to remove program when finished and I opted yes remove it.

      Just to keep you up to speed, computer is running very good with no problems since you fixed rootkit issue. I have used computer in the past (very sparingly) to do banking, but have not done anything in the past 3 months or so. The problems with tidserv started about a month and a half or so ago, so nothing was done on computer (financial) while "Tidserv" was detected.

      As I mentioned before, the decision is yours to make. If you don't feel comfortable doing financial transactions or other personal business then you should back-up whatever important documents, files and pictures and reformat. My laptop was hit with a rootkit a few days after I puchased it and I still won't conduct financial business on it. Plus, I'm not too happy with Vista. I appreciate all your guidance and advice !! I have read alot of the links you have attached in a previous thread about rootkits and malware. I did a search in virus and malware database but didn't find "Tidserv Backdoor", do you have any info on it? is it high risk, low risk?

      Also in my reading it says that alot of these rootkit issues are undetectable, does that mean that a computer can have these issues and never even get a warning that something is wrong? In my case the Symantec Endpoint was constantly giving me a popup warning that "Tidserv" was detected.

      You also directed me to Panda Security website for reading about rootkits and they have a tool called "Panda Anti-Rootkit" Is this worth running?

      Again thanks for your direction !!!Quote
      do you have any info on it? is it high risk, low risk?
      You can find some info here.

      Quote
      does that mean that a computer can have these issues and never even get a warning that something is wrong?
      The most difficult thing about rootkits is their ability to hide themselves. That's why we have to run so many tools/scans to find them.

      Quote
      Is this worth running?
      Yes, by all means. Download it and run it. Most major AV companies have their own rootkit scanner.Thanks again for all your help! I have read the article from symantec about tidserv very informative. In one of the articles from symantec it states the following:

      Response
      A removal tool is available to clean infections of Backdoor.Tidserv.

      The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.

      1. Disable System Restore (Windows Me/XP).
      2. Update the virus definitions.
      3. Run a full system scan.
      4. Delete any values added to the registry.

      When I went into My Computer and system restore I noticed my system restore was already disabled?? Should this be changed back to enable restore?

      When it says delete any values added to the registry, where would i find that info? Will Symantec tell me if there is any values added? Quote
      Disable System Restore (Windows Me/XP).
      I would never ask a user to disable their System Restore. An infected Restore Point is better than no Restore Point.

      Quote
      Should this be changed back to enable restore?
      Yes.

      Quote
      When it says delete any values added to the registry, where would i find that info?
      Only an expert should mess around in the registry. You could turn your computer into a doorstop.
      Thanks I will set my computer to have restore enabled. I don't ever remember disabling it??? Could it of been the "Tidserv" malware doing this??Also I was thinking could it have been EvilFantasy that turned system restore off while doing one of his processes?? Also he installed something whereas when I first turn on my computer i get a black screen for only about 3-5 seconds that has different options on it to help me in case there are issues (I believe this is for if computer has issues i can debug, start in safe mode, reboot etc.)

      Thanks again to yourself and EvilFantasy for all your help!!
      335.

      Solve : Changes to my computer that I did not make?

      Answer»

      Hello!

      Whew! I think I've DONE EVERYTHING... I will tell you that my computer is running much faster now. Is there anything else I should do at this point?

      I can't thank you enough for your consideration and time. All of you are great.

      Most sincerely,
      nhchapQuote

      Is there anything else I should do at this point?

      No. Just STAY safe.Alright then. Have a great day and THANK YOU again.

      (I SHALL pursue my other questions in another AREA on this site )

      nhchap
      336.

      Solve : Pc Problems?

      Answer»

      Still FINISHING off the cleanup and preventative maintenance items you suggested, but WANTED to give you a huge thanks for all your HELP. It has been a long PROCESS but got there with your help. Everything has been running great now.

      337.

      Solve : Neep help removing remnants of "AntiMalware Doctor" infection?

      Answer»

      The only thing I can suggest now is to relocate your computer to a location where you can hardwire it to a modem and then try to connect to the internet. If it works, that would indicate the problem is with the Wi-fi connection.Before you attempt to move your computer, let's try this. Since we can't flush the DNS, we'll disable it and then try to connect to the net. If it doesn't work, go back and start it again and then attempt what I've suggested in the previous post.

      DNS Client Service

      • Go to Start and click on Run.
      • Type Services.msc in the Run command box.
      • A window listing all the services will popup. Search for a service called DNS Client.
      • Double click on the listed DNS Client service and click Stop. Similarly, you can restart it by clicking Start.
      okay, i could not click "stop" or "start" or "pause" or "resume" they were all there, but blanked out.

      "Service status" says "Stopped"

      "Startup type" is set as "disabled", with the option of setting it to "automatic" or "manual". should i change this setting? would it help?Try setting it to Automatic.ok, i turned it to automatic, and unfortunately, it did not change anything. so i figured maybe if i restarted my computer it might start working. so i restarted, and now it won't let me open anything. the cursor moves, but if i double or single click any icon, nothing happens. also, i tried doing ctrl/alt/del to find out if something was eating up cpu power, and the task manager window never popped up. do i need to restart in safe mode or something?That shouldn't HAPPEN. Try starting in Safe Mode and see what happens. Do you have your OS disk?ok, so i started in safe mode. everything worked normally. unfortunately, in safe mode, no internet is allowed, so i can't really CHECK it. at the F8 menu at startup, there was an option for safe mode with networking. should i do that instead?

      YES, i do have the OS disk.Ok. Let's try this:Try a System Restore to see if you can get your computer working again. You can do this in Safe Mode. If you can get it to work, please try below:

      Make sure, your computer is set to obtain IP address automatically.
      1. Go Start>Settings>Control Panel (Vista/7 users: Start>Control Panel)
      2. Double click Network Connections (Vista/7 users: Network and Sharing Center)
      3. Vista/7 users - From the list of tasks on the left, click Manage network connections.
      4. For a WIRED network connection, right-click Local AREA Connection, and then select Properties.
      For a wireless network connection, right-click Wireless Network Connection, and then select Properties.
      5. From the General tab (Vista/7 users: Networking tab), click Internet Protocol (TCP/IP), make sure it is checked, and then click Properties
      6. Click Obtain an IP Address Automatically, and then click OK.okay, suddenly my computer is working again, no explanation. so i followed your directions, and my tcp/ip is already set to obtain the IP address automatically.And still no connection?nope, still no connection. like i said, i do have the OS disk. should i just go ahead and reformat my hard drive? i've done it before, so i'm no stranger to it. it might be the most simple fix to this problem.Quote from: piratesteve83 on November 16, 2010, 06:34:05 PM
      nope, still no connection. like i said, i do have the OS disk. should i just go ahead and reformat my hard drive? i've done it before, so i'm no stranger to it. it might be the most simple fix to this problem.
      If you don't mind doing it, it would be the best solution. You'll be starting off with a clean slate. Please let me know your course-of-action.yeah, i'll go ahead and reformat. thanks so much for all of your effort, anyway!
      338.

      Solve : Personal Internet Security 2011 Virus Removal?

      Answer»

      I ran the ciscoeapfast.xsd file through Jotti and it came up with nothing.

      I did find something interesting. When I tried to run ciscoeapgtc.dll into Jotti the computer would crash. Even in safe mode. I went into windows explorer thinking I would copy the file, rename it, and see if I could submit it into Jotti. Anytime I click on that file the computer crashes. I right clicked on the file and got the blue screen of death. Only the blue screen once. I right clicked on all the other files in the directory without issue, but once I right clicked on that file it would lock up the computer.A new twist to see what was up - I dusted off my old DOS skills and tried something. Booted in safe mode and got the command prompt.
      Moved to the right directory and tried to copy the file to the desktop. Below is what came up -

      Microsoft Windows [Version 6.0.6002]
      Copyright (c) 2006 Microsoft Corporation. All rights reserved.

      C:\Program Files\Cisco\Cisco EAP-FAST Module>copy ciscoeapgtc.dll c:\desktop
      The REQUEST could not be performed because of an I/O device error.
      0 file(s) copied.

      C:\Program Files\Cisco\Cisco EAP-FAST Module>

      So my question, based on this is - Are we dealing with some residual effect of a virus or a hardware problem? Also, if you think it would be best, I think I could back up everything of value off the computer and reformat the drive. There is one program that I don't have disks for that I would have to investigate how to get it back, but everything else, I believe, would be pretty easy to backup prior to a re-format.

      Thanks,

      ScottQuote

      Are we dealing with some residual effect of a virus or a hardware problem? Also, if you think it would be best, I think I could back up everything of value off the computer and reformat the drive. There is one program that I don't have disks for that I would have to investigate how to get it back, but everything else, I believe, would be pretty easy to backup prior to a re-format.
      It's looking more and more like a hardware or software problem. Of course, a full re-format is a good route to take but not everyone can or want to take that route. If you don't have the disks for that particular program I don't see anyway to get it back. Of course, the choice is yours. Please try this:

      Do you have your OS CD/DVD?

      If so,

      1/ Click the Start button.

      2/ From the Start Menu, Click All programs followed by Accessories.

      3/ In the Accessories menu, Right Click on the Command Prompt option.

      4/ From the drop down menu that appears, Click on the Run as administrator option.

      5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc.

      6/ In the Command Prompt window, type: sfc /scannow and then press Enter.

      7/ A message will appear stating that the system scan will begin.

      8/ Be patient because the scan may take some time.

      9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue.

      10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations.

      11/ After the scan has completed, Close the command prompt window.
      Here's the final story on this computer.

      I believe there is a hard drive issue or something else that is gumming things up and not any virus.

      I ran the SFC and, surprise, it found errors but was unable to repair them.

      I came up with a work around for MBAM where I told it to ignore any of the igfx*.* files (which was a PITA) and ran a scan. The scan completed without issue and no malware was found. I then set up SAS to ignore the Cisco file folder that it normally was hanging up on. I could not find a WAY to get SAS to ignore individual files, but this tool rarely hung up on the igfx files. I ran the scan and it caused the blue screen of death. When the computer restarted I got a windows message about a disk I/O issue and in the Help context it mentioned that heavy disk access programs such as malware scanners could be early detectors of POSSIBLE disk issues. Also, PERIODICALLY, when the computer boots it goes into the check disk screen and reports unindexed files or other issues that seem to suggest the life of the drive may be drawing to a close.
      I am going to back up the computer data and continue to run it. When the issue becomes enough of a pain I will replace the drive and start over with the operating system.

      The scanner issues seem to suggest more of a hang up trying to access data on a physical location of the disk than some remnant of malware. There are no more re-directs in I-Explorer and the rest of the system seems to be operating well.

      I thank you for your time on this and your help walking through all of this. I will keep MBAM on the MACHINE and get rid of the other tools we have downloaded. If you could give me some direction on that cleanup, please let me know. Once done we can close the thread. If something comes up I will PM you to reopen the thread.

      Thank You,

      ScottThis is all I have. You can keep SAS and MBAM, if you wish. Be sure to update them before running any scans.

      To remove all of the tools we used and the files and folders they created do the following:
      Double click OTL.exe.
      • Click the CleanUp button.
      • Select Yes when the "Begin cleanup Process?" prompt appears.
      • If you are prompted to Reboot during the cleanup, select Yes.
      • The tool will delete itself once it finishes.
      Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
      339.

      Solve : Security Defendender Virus! Please help - Windows 7 x64?

      Answer»

      Hi there,
      A friend of mine has a pretty bad virus which I believe to be a Security Defender virus.
      He has an icon on his desktop which frequently pops-up saying he has viruses etc. on his PC and it requests that he order the "Security Defender" software. I am certain this is a virus.


      I asked him to download SUPERAntiSpyware and Malwarebytes' Anti-Malware free edition to perform scans. Threats were detected and removed however the Security Defender pop-ups persist.
      How can I help him clean his PC?


      Any help is greatly appreciated. HELLO and welcome to Computer HOPE Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
      2. The fixes are specific to your problem and should only be used for this issue on this machine.
      3. If you don't know or understand something, please don't hesitate to ask.
      4. Please DO NOT run any other tools or scans while I am helping you.
      5. It is important that you reply to this thread. Do not start a new topic.
      6. Your security PROGRAMS may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
      7. ABSENCE of symptoms does not mean that everything is clear.

      If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
      **************************************************
      This will not run if you have AVG on your computer. If that is the case, let me know and I'll give you some free AV's and a tool to remove AVG.

      Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop.

      link # 1
      Link # 2
      If you are using Firefox, make sure that your download settings are as follows:

      * Tools->Options->Main TAB
      * Set to "Always ask me where to Save the files".

      Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

      Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

      Right-click combofix.exe and select Run as Administrator and follow the prompts.
      When finished, ComboFix will produce a log for you.
      Post the ComboFix log and a new HijackThis log in your next reply.

      NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

      Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.Quote from: SuperDave on February 11, 2011, 05:10:28 PM

      Post the ComboFix log and a new HijackThis log in your next reply.


      Did you want a HiJackThis log as well?
      If so, do you have a download link?

      ThanksQuote
      Did you want a HiJackThis log as well?
      If so, do you have a download link?
      Yes, I would like to see both logs.
      Please don't post download links, especially the ones I can't see. Copy and paste the logs in your replies.Where do I download HijackThis?Please download: HiJackThis to your Desktop.
      • Double Click the HijackThis icon, located on your Desktop.
      • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
      • Accept the license agreement.
      • Click the Open the Misc Tools section button.
      • Click Do a System Scan and Save a Logfile. Or, if you see a white screen, click Scan.
      • Please post the log in your next reply.
      340.

      Solve : Help with System Tools virus?

      Answer»

      Quote from: SuperDave on February 09, 2011, 12:04:44 PM

      That's it. You can keep SAS and MBAM on your computer, if you wish. Update them and run them on a regular basis. Good Luck!

      Really?? Seriously???...You're not messing with me right? lol

      Well let me just SAY again...THANK YOU SuperDave from the bottom of my heart!!! I don't know what I would have done WITHOUT this great website and all the wonderful people here donating their time!

      Your the best!
      ginaQuote
      You're not messing with me right? lol
      Gina, I wouldn't mess with you with something as IMPORTANT as your computer.
      Quote
      THANK YOU SuperDave from the bottom of my heart!!!
      You're welcome. I will lock this thread. If you need it re-opened, PLEASE SEND me a pm.
      341.

      Solve : Yahoo IM "IQ Test Hack"?

      Answer»

      Yay! This one worked!

      Scan results are posted below.
      (I had to POST it in a code box so there wouldn't be a smiley extravaganza.)

      Code: [Select]Rooter.exe (v1.0.2) by Eric_71
      .
      SeDebugPrivilege granted successfully ...
      .
      Windows 7 . (6.1.7600)
      [32_bits] - Intel64 Family 6 Model 23 Stepping 7, GenuineIntel
      .
      [wscsvc] (Security Center) RUNNING (state:4)
      [MpsSvc] RUNNING (state:4)
      Windows Firewall -> Disabled !
      Windows Defender -> Enabled
      User Account Control (UAC) -> Enabled
      .
      Internet Explorer 8.0.7600.16385
      Mozilla Firefox 3.6.13 (en-US)
      .
      C:\ [Fixed-NTFS] .. ( Total:596 Go - Free:537 Go )
      D:\ [CD_Rom]
      E:\ [Fixed-NTFS] .. ( Total:465 Go - Free:346 Go )
      F:\ [Removable]
      G:\ [Removable]
      H:\ [Removable]
      I:\ [Removable]
      .
      Scan : 16:23.51
      Path : C:\Users\owner\Desktop\Rooter.exe
      User : owner ( Administrator -> YES )
      .
      ----------------------\\ Processes
      .
      Locked [System Process] (0)
      Locked System (4)
      ______ ?????????? (288)
      ______ ?????????? (428)
      ______ ?????????? (488)
      ______ ?????????? (508)
      ______ ?????????? (556)
      ______ ?????????? (564)
      ______ ?????????? (572)
      ______ ?????????? (656)
      ______ ?????????? (720)
      ______ ?????????? (784)
      ______ ?????????? (824)
      ______ ?????????? (912)
      ______ ?????????? (956)
      ______ ?????????? (992)
      ______ ?????????? (568)
      ______ ?????????? (1080)
      ______ ?????????? (1116)
      ______ ?????????? (1324)
      ______ ?????????? (1368)
      ______ ?????????? (1540)
      ______ C:\Program Files (x86)\PC Tools Firewall Plus\FWService.exe (1608)
      ______ ?????????? (1700)
      ______ ?????????? (1728)
      ______ ?????????? (1796)
      ______ C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (1872)
      ______ ?????????? (1916)
      ______ ?????????? (2472)
      ______ ?????????? (2516)
      ______ ?????????? (2856)
      ______ ?????????? (2900)
      ______ ?????????? (2968)
      ______ ?????????? (2268)
      ______ C:\Program Files (x86)\COMMON Files\Java\Java Update\jusched.exe (3088)
      ______ C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (3148)
      ______ C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (3172)
      ______ ?????????? (3520)
      ______ ?????????? (3716)
      ______ ?????????? (3876)
      ______ ?????????? (3320)
      ______ ?????????? (4776)
      Locked audiodg.exe (212)
      ______ ?????????? (4308)
      ______ ?????????? (4320)
      ______ ?????????? (2312)
      ______ C:\Program Files (x86)\PC Tools Firewall Plus\FirewallGUI.exe (2700)
      ______ ?????????? (364)
      ______ ?????????? (2344)
      ______ C:\Users\owner\Desktop\Rooter.exe (4400)
      .
      ----------------------\\ Device\Harddisk0\
      .
      \Device\Harddisk0 [Sectors : 63 x 512 Bytes]
      .
      \Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:1048576 | Length:104857600)
      \Device\Harddisk0\Partition2 (Start_Offset:105906176 | Length:640027721728)
      .
      ----------------------\\ Scheduled Tasks
      .
      C:\Windows\Tasks\SA.DAT
      C:\Windows\Tasks\SCHEDLGU.TXT
      .
      ----------------------\\ Registry
      .
      .
      ----------------------\\ Files & Folders
      .
      ----------------------\\ Scan completed at 16:23.56Good work. Let's run this scan:

      I'd like to scan your machine with ESET OnlineScan

      •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
      ESET OnlineScan
      •Click the button.
      •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

      • Click on to download the ESET Smart Installer. Save it to your desktop.
      • Double click on the icon on your desktop.
      •Check
      •Click the button.
      •Accept any security warnings from your browser.
      •Check
      •Push the Start button.
      •ESET will then download UPDATES for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
      •When the scan completes, push
      •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
      •Push the button.
      •Push
      A log file will be saved here: C:\Program Files\ESET\ESET ONLINE Scanner\log.txt
      Here's the report from ESET:

      C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\65891f0d-3955331bmultiple threatsdeleted - quarantined
      C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\286463dc-2a9a9656multiple threatsdeleted - quarantined
      C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29\330b03dd-3763c60cmultiple threatsdeleted - quarantined
      C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\4cad16f7-383f81fbmultiple threatsdeleted - quarantined
      C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\73d2f5b8-4ecc26demultiple threatsdeleted - quarantined
      C:\Users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\7127249-4a57221bmultiple threatsdeleted - quarantinedThat looks good. If there are no other issues, let's do some cleanup.

      To uninstall ComboFix

      • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
      • In the field, type in ComboFix /uninstall


      (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

      • Then, press Enter, or click OK.
      • This will uninstall ComboFix, delete its folders and files, HIDES System files and folders, and resets System Restore.
      **********************************************
      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
      *************************************************
      Use the Secunia Software Inspector to check for out of date software.

      •Click Start Now

      •Check the box next to Enable thorough system inspection.

      •Click Start

      •Allow the scan to finish and scroll down to see if any updates are needed.
      •Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe Surfing!
      No other issues I can think of.
      Thank you so much for all the help! You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
      342.

      Solve : application can not be executed - xy is infected - trojan horse?

      Answer»

      with web cure it same thing as last time: i could not open the page - server not found...
      and what about the two threats that were found by eset this time? since i pressed merely the 'scan archives' button and not the 'remove found threats'-one?
      thanks again
      i just had windows defender finding that PWS:Win32/Daurso.A again-and i removed it again....
      i really hope we will ultimately solve this.
      many thanks for all the help up until now!
      eQuote

      and what about the two threats that were found by eset this time? since i pressed merely the 'scan archives' button and not the 'remove found threats'-one?
      Run the ESET scan again and, this time remove them please.this time i removed the threats (which amounted to 5 now...) and these are the results:

      C:\Windows\temp\37716533.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined
      C:\Windows\temp\5f9d0076.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined
      C:\Windows\temp\8d556260.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined
      C:\Windows\temp\a879b485.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined
      C:\Windows\temp\d7db9f3.tmpa variant of Win32/Kryptik.FKM trojancleaned by deleting - quarantined

      web Cureit still does not work however...
      i don't know if it would work if i just didn't use the link you posted but would download it from here http://www.freedrweb.com/cureit/?lng=en -> is this the right thing?
      many thanks!Quote from: ekluever on July 13, 2010, 04:41:29 PM
      i don't know if it would work if i just didn't use the link you posted but would download it from here http://www.freedrweb.com/cureit/?lng=en -> is this the right thing?
      many thanks!
      Yes, that's correct. We don't normally send users to websites; by clicking on the link you should get a download message.hello dave, i ran the dr.web cure it quick scan (while i was gone to work) and when i returned it said it didn't find any threats. in the meantime my friend said however, that i should have cut my internet connection, while doing the scan.
      i did not do the complete scan - cause i wasn't sure since it hadn't found anything in the first place.
      what do you recommend next?
      thanks,
      elisa

      ps: yes, i know, usually clicking your links always directly opened the download window, just this one tried to open a new tab and then said it couldn't find the server...Elisa, could you please give it a few days and then come back and tell how everything is working. If it's ok by then, we'll do some cleanup.hello dave
      malicious software removal tool today alerted me and said it found a Trojan:WinNT/Bubnix.gen!A which it partially removed.
      what keeps happening unfortunately, is that it won't properly start, it'll say a problem has been detected and windows has been shut down to prevent damage to your computer acpi.sys
      then it'll restart, come to the site i described before, where you can choose one of five start-options. the normal starting is the highlighted choice which will be chosen automatically after 30 sec.
      this cycle will be gone through a COUPLE of times, until eventually, with the automatic choice it'll start normally...
      i just wanted to describe this problem again.
      other than that, it seems to be working fine.
      i'll shut it down now and then run a complete antivir scan, as this is whast was suggested after finding the above mentioned file...
      else, i'll follow your advice and call back in a couple of days.
      many thanks!
      elisaoh, and something was found when i started another antivr-scan just now, i'll paste the log:

      Avira AntiVir Personal
      Report file date: Thursday, July 15, 2010 09:27

      Scanning for 2346510 virus strains and unwanted programs.

      The program is running as an UNRESTRICTED full version.
      Online services are available:

      Licensee : Avira AntiVir Personal - FREE Antivirus
      Serial number : 0000149996-ADJIE-0000001
      Platform : Windows Vista
      Windows version : (Service Pack 2) [6.0.6002]
      Boot mode : Normally booted
      Username : SYSTEM
      Computer name : ELISA-PC

      Version information:
      BUILD.DAT : 10.0.0.567 32097 Bytes 4/19/2010 15:07:00
      AVSCAN.EXE : 10.0.3.0 433832 Bytes 4/1/2010 12:37:38
      AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 12:57:04
      LUKE.DLL : 10.0.2.3 104296 Bytes 3/7/2010 18:33:04
      LUKERES.DLL : 10.0.0.1 12648 Bytes 2/10/2010 23:40:49
      VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 09:05:36
      VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 19:27:49
      VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 17:37:42
      VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 16:37:42
      VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 11:29:03
      VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 11:09:48
      VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 11:09:54
      VBASE007.VDF : 7.10.7.219 2048 Bytes 6/2/2010 11:09:54
      VBASE008.VDF : 7.10.7.220 2048 Bytes 6/2/2010 11:09:54
      VBASE009.VDF : 7.10.7.221 2048 Bytes 6/2/2010 11:09:54
      VBASE010.VDF : 7.10.7.222 2048 Bytes 6/2/2010 11:09:54
      VBASE011.VDF : 7.10.7.223 2048 Bytes 6/2/2010 11:09:54
      VBASE012.VDF : 7.10.7.224 2048 Bytes 6/2/2010 11:09:54
      VBASE013.VDF : 7.10.8.37 270336 Bytes 6/10/2010 11:09:55
      VBASE014.VDF : 7.10.8.69 138752 Bytes 6/14/2010 11:09:55
      VBASE015.VDF : 7.10.8.102 130560 Bytes 6/16/2010 11:09:56
      VBASE016.VDF : 7.10.8.135 152064 Bytes 6/21/2010 11:09:56
      VBASE017.VDF : 7.10.8.163 432128 Bytes 6/23/2010 11:09:57
      VBASE018.VDF : 7.10.8.194 133632 Bytes 6/27/2010 11:09:57
      VBASE019.VDF : 7.10.8.220 134656 Bytes 6/29/2010 11:09:58
      VBASE020.VDF : 7.10.8.252 171520 Bytes 7/4/2010 11:09:58
      VBASE021.VDF : 7.10.9.19 131072 Bytes 7/6/2010 11:09:59
      VBASE022.VDF : 7.10.9.36 297472 Bytes 7/7/2010 11:09:59
      VBASE023.VDF : 7.10.9.60 150016 Bytes 7/11/2010 08:02:27
      VBASE024.VDF : 7.10.9.79 113152 Bytes 7/13/2010 08:02:27
      VBASE025.VDF : 7.10.9.80 2048 Bytes 7/13/2010 08:02:27
      VBASE026.VDF : 7.10.9.81 2048 Bytes 7/13/2010 08:02:27
      VBASE027.VDF : 7.10.9.82 2048 Bytes 7/13/2010 08:02:27
      VBASE028.VDF : 7.10.9.83 2048 Bytes 7/13/2010 08:02:28
      VBASE029.VDF : 7.10.9.84 2048 Bytes 7/13/2010 08:02:28
      VBASE030.VDF : 7.10.9.85 2048 Bytes 7/13/2010 08:02:28
      VBASE031.VDF : 7.10.9.90 95744 Bytes 7/14/2010 08:02:30
      Engineversion : 8.2.4.10
      AEVDF.DLL : 8.1.2.0 106868 Bytes 7/8/2010 11:10:09
      AESCRIPT.DLL : 8.1.3.39 1335674 Bytes 7/8/2010 11:10:09
      AESCN.DLL : 8.1.6.1 127347 Bytes 7/8/2010 11:10:08
      AESBX.DLL : 8.1.3.1 254324 Bytes 7/8/2010 11:10:10
      AERDL.DLL : 8.1.4.6 541043 Bytes 7/8/2010 11:10:08
      AEPACK.DLL : 8.2.2.5 430453 Bytes 7/8/2010 11:10:08
      AEOFFICE.DLL : 8.1.1.6 201081 Bytes 7/8/2010 11:10:07
      AEHEUR.DLL : 8.1.1.38 2724214 Bytes 7/8/2010 11:10:07
      AEHELP.DLL : 8.1.11.6 242038 Bytes 7/8/2010 11:10:04
      AEGEN.DLL : 8.1.3.13 381300 Bytes 7/8/2010 11:10:04
      AEEMU.DLL : 8.1.2.0 393588 Bytes 7/8/2010 11:10:03
      AECORE.DLL : 8.1.15.3 192886 Bytes 7/8/2010 11:10:02
      AEBB.DLL : 8.1.1.0 53618 Bytes 7/8/2010 11:10:00
      AVWINLL.DLL : 10.0.0.0 19304 Bytes 1/14/2010 12:03:38
      AVPREF.DLL : 10.0.0.0 44904 Bytes 1/14/2010 12:03:35
      AVREP.DLL : 10.0.0.8 62209 Bytes 2/18/2010 16:47:40
      AVREG.DLL : 10.0.3.0 53096 Bytes 4/1/2010 12:35:46
      AVSCPLR.DLL : 10.0.3.0 83816 Bytes 4/1/2010 12:39:51
      AVARKT.DLL : 10.0.0.14 227176 Bytes 4/1/2010 12:22:13
      AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 1/26/2010 09:53:30
      SQLITE3.DLL : 3.6.19.0 355688 Bytes 1/28/2010 12:57:58
      AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/16/2010 15:38:56
      NETNT.DLL : 10.0.0.0 11624 Bytes 2/19/2010 14:41:00
      RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 13:10:20
      RCTEXT.DLL : 10.0.53.0 97128 Bytes 4/9/2010 14:14:29

      Configuration settings for the scan:
      Jobname.............................: Complete system scan
      Configuration file..................: C:\program files\avira\antivir desktop\sysscan.avp
      Logging.............................: low
      Primary action......................: interactive
      Secondary action....................: ignore
      Scan master boot sector.............: on
      Scan boot sector....................: on
      Boot sectors........................: C:, D:,
      Process scan........................: on
      Extended process scan...............: on
      Scan registry.......................: on
      Search for rootkits.................: on
      Integrity checking of system files..: off
      Scan all files......................: All files
      Scan archives.......................: on
      Recursion depth.....................: 20
      Smart extensions....................: on
      Macro heuristic.....................: on
      File heuristic......................: medium

      Start of the scan: Thursday, July 15, 2010 09:27

      Starting search for hidden objects.

      The scan of running processes will be started
      Scan process 'winamp.exe' - '190' Module(s) have been scanned
      Scan process 'svchost.exe' - '30' Module(s) have been scanned
      Scan process 'vssvc.exe' - '49' Module(s) have been scanned
      Scan process 'avscan.exe' - '79' Module(s) have been scanned
      Scan process 'SkypeNames.exe' - '25' Module(s) have been scanned
      Scan process 'skypePM.exe' - '67' Module(s) have been scanned
      Scan process 'Skype.exe' - '123' Module(s) have been scanned
      Scan process 'firefox.exe' - '118' Module(s) have been scanned
      Scan process 'mobsync.exe' - '38' Module(s) have been scanned
      Scan process 'igfxsrvc.exe' - '30' Module(s) have been scanned
      Scan process 'FirewallGUI.exe' - '48' Module(s) have been scanned
      Scan process 'avgnt.exe' - '54' Module(s) have been scanned
      Scan process 'pctsTray.exe' - '59' Module(s) have been scanned
      Scan process 'winampa.exe' - '21' Module(s) have been scanned
      Scan process 'jusched.exe' - '24' Module(s) have been scanned
      Scan process 'OEM02Mon.exe' - '34' Module(s) have been scanned
      Scan process 'igfxpers.exe' - '26' Module(s) have been scanned
      Scan process 'hkcmd.exe' - '26' Module(s) have been scanned
      Scan process 'GrooveMonitor.exe' - '43' Module(s) have been scanned
      Scan process 'MSASCui.exe' - '40' Module(s) have been scanned
      Scan process 'taskeng.exe' - '47' Module(s) have been scanned
      Scan process 'RapportService.exe' - '72' Module(s) have been scanned
      Scan process 'Explorer.EXE' - '160' Module(s) have been scanned
      Scan process 'taskeng.exe' - '82' Module(s) have been scanned
      Scan process 'Dwm.exe' - '29' Module(s) have been scanned
      Scan process 'WUDFHost.exe' - '33' Module(s) have been scanned
      Scan process 'SearchIndexer.exe' - '60' Module(s) have been scanned
      Scan process 'svchost.exe' - '9' Module(s) have been scanned
      Scan process 'svchost.exe' - '44' Module(s) have been scanned
      Scan process 'avshadow.exe' - '33' Module(s) have been scanned
      Scan process 'pctsAuxs.exe' - '26' Module(s) have been scanned
      Scan process 'svchost.exe' - '40' Module(s) have been scanned
      Scan process 'IoctlSvc.exe' - '21' Module(s) have been scanned
      Scan process 'FWService.exe' - '61' Module(s) have been scanned
      Scan process 'avguard.exe' - '64' Module(s) have been scanned
      Scan process 'svchost.exe' - '62' Module(s) have been scanned
      Scan process 'sched.exe' - '56' Module(s) have been scanned
      Scan process 'spoolsv.exe' - '85' Module(s) have been scanned
      Scan process 'svchost.exe' - '91' Module(s) have been scanned
      Scan process 'svchost.exe' - '86' Module(s) have been scanned
      Scan process 'SLsvc.exe' - '23' Module(s) have been scanned
      Scan process 'svchost.exe' - '153' Module(s) have been scanned
      Scan process 'svchost.exe' - '115' Module(s) have been scanned
      Scan process 'svchost.exe' - '66' Module(s) have been scanned
      Scan process 'RapportMgmtService.exe' - '68' Module(s) have been scanned
      Scan process 'svchost.exe' - '54' Module(s) have been scanned
      Scan process 'svchost.exe' - '35' Module(s) have been scanned
      Scan process 'svchost.exe' - '40' Module(s) have been scanned
      Scan process 'lsm.exe' - '22' Module(s) have been scanned
      Scan process 'winlogon.exe' - '30' Module(s) have been scanned
      Scan process 'lsass.exe' - '60' Module(s) have been scanned
      Scan process 'services.exe' - '33' Module(s) have been scanned
      Scan process 'csrss.exe' - '14' Module(s) have been scanned
      Scan process 'wininit.exe' - '26' Module(s) have been scanned
      Scan process 'csrss.exe' - '14' Module(s) have been scanned
      Scan process 'smss.exe' - '2' Module(s) have been scanned

      Starting master boot sector scan:
      Master boot sector HD0
      [INFO] No virus was found!
      Master boot sector HD1
      [INFO] No virus was found!

      Start scanning boot sectors:
      Boot sector 'C:\'
      [INFO] No virus was found!
      Boot sector 'D:\'
      [INFO] No virus was found!

      Starting to scan executable files (registry).
      The registry was scanned ( '350' files ).


      Starting the file scan:

      BEGIN scan in 'C:\'
      C:\Program Files\7-Zip\Uninstall.exe
      [WARNING] Insufficient memory. The file was not scanned.
      C:\Users\Elisa\Downloads\7z465.exe
      [WARNING] Insufficient memory. The file was not scanned.
      C:\Windows\System32\drivers\igcmc.sys
      [DETECTION] Is the TR/Rootkit.Gen Trojan
      Begin scan in 'D:\'

      Beginning disinfection:
      C:\Windows\System32\drivers\igcmc.sys
      [DETECTION] Is the TR/Rootkit.Gen Trojan
      [NOTE] The file was moved to the quarantine directory under the name '48757dfe.qua'.


      End of the scan: Thursday, July 15, 2010 10:46
      Used time: 1:14:10 Hour(s)

      The scan has been done completely.

      17360 Scanned directories
      274560 Files were scanned
      1 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      0 files were deleted
      0 Viruses and unwanted programs were repaired
      1 Files were moved to quarantine
      0 Files were renamed
      0 Files cannot be scanned
      274559 Files not concerned
      1061 Archives were scanned
      2 Warnings
      1 Notes
      462110 Objects were scanned with rootkit scan
      0 Hidden objects were found

      cheersDownload the GMER Rootkit Scanner. Unzip it to your Desktop.

      Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

      Double-click gmer.exe. The program will begin to run.

      **Caution**
      These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised!

      If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
      • Click NO
      • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
      • Now click the Scan button.
      • Once the scan is complete, you may receive another notice about rootkit activity.
      • Click OK.
      • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
      • Save it where you can easily find it, such as your desktop.
      dear dave
      everything went a bit different from the description, i wasn't asked whether i wanted to perform any scan, so i just checked whether the boxes were all checked/unchecked and then started the scan, which seemed to have finished but again i didn't receive any notice.
      here is the log:

      GMER 1.0.15.15281 - http://www.gmer.net
      Rootkit scan 2010-07-16 15:01:42
      Windows 6.0.6002 Service Pack 2
      Running: gmer.exe; Driver: C:\Users\Elisa\AppData\Local\Temp\uglcapoc.sys


      ---- System - GMER 1.0.15 ----

      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAllocateVirtualMemory [0xA82F5752]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAlpcConnectPort [0xA82F5388]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwAssignProcessToJobObject [0xA82F5440]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwConnectPort [0xA82F5482]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateFile [0xA82F5530]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateProcess [0xA82F5DD8]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateProcessEx [0xA82F5E64]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateThread [0xA82F5EF4]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwDebugActiveProcess [0xA82F5580]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwDuplicateObject [0xA82F55C2]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwLoadDriver [0xA82F5606]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenKey [0xA82F5648]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenSection [0xA82F568A]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwOpenThread [0xA82F56CC]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwProtectVirtualMemory [0xA82F579A]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwRequestWaitReplyPort [0xA82F570E]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwRestoreKey [0xA82F57DC]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwResumeThread [0xA82F5824]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSecureConnectPort [0xA82F58B4]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSetValueKey [0xA82F5866]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSuspendProcess [0xA82F5958]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwSystemDebugControl [0xA82F599A]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwTerminateProcess [0xA82F59DC]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwWriteVirtualMemory [0xA82F5A2A]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateThreadEx [0xA82F5F96]
      SSDT \??\C:\Windows\system32\drivers\PCTAppEvent.sys ZwCreateUserProcess [0xA82F5D68]

      INT 0x62 ? 854F6BF8
      INT 0x72 ? 854F6BF8
      INT 0x72 ? 854F6BF8
      INT 0x72 ? 854F6BF8
      INT 0x82 ? 854F6BF8
      INT 0x82 ? 854F6BF8
      INT 0x82 ? 854F6BF8
      INT 0x82 ? 854F6BF8
      INT 0xA2 ? 84606BF8
      INT 0xB2 ? 84606BF8
      INT 0xB2 ? 84606BF8
      INT 0xB2 ? 84606BF8

      ---- Kernel code sections - GMER 1.0.15 ----

      .text ntkrnlpa.exe!KeSetEvent + 131 81AEE894 4 Bytes [52, 57, 2F, A8]
      .text ntkrnlpa.exe!KeSetEvent + 13D 81AEE8A0 4 Bytes [88, 53, 2F, A8]
      .text ntkrnlpa.exe!KeSetEvent + 191 81AEE8F4 4 Bytes [40, 54, 2F, A8]
      .text ntkrnlpa.exe!KeSetEvent + 1C1 81AEE924 4 Bytes [82, 54, 2F, A8]
      .text ntkrnlpa.exe!KeSetEvent + 1D9 81AEE93C 4 Bytes [30, 55, 2F, A8]
      .text ...
      ? System32\Drivers\spxo.sys The system cannot find the path specified. !
      .text USBPORT.SYS!DllUnload 8C5A341B 5 Bytes JMP 854F61D8
      .text au8ydgj3.SYS 8BA35000 22 Bytes [82, 63, A1, 81, 6C, 62, A1, ...]
      .text au8ydgj3.SYS 8BA35017 181 Bytes [00, 32, B7, 79, 80, 3D, B5, ...]
      .text au8ydgj3.SYS 8BA350CE 10 Bytes [00, 00, 00, 00, 00, 00, 02, ...]
      .text au8ydgj3.SYS 8BA350DA 12 Bytes [00, 00, 02, 00, 00, 00, 24, ...]
      .text au8ydgj3.SYS 8BA350E7 714 Bytes [00, F0, 0E, 00, 00, 00, 00, ...]
      .text ...
      ? \ArcName\multi(0)disk(0)rdisk(0)partition(1)\Windows\system32\drivers\PctWfpFilter.sys The system cannot find the path specified. !

      ---- User code sections - GMER 1.0.15 ----

      .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 00414A50 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.)
      .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] USER32.dll!InSendMessageEx + 3B1 76FAE6B0 6 Bytes JMP 0044C7F0 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.)
      .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] WS2_32.dll!getaddrinfo 77A2418A 5 Bytes JMP 71640022
      .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] WS2_32.dll!gethostbyname 77A362D4 5 Bytes JMP 71670022
      .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] ntdll.dll!LdrLoadDll 77819390 5 Bytes JMP 00B013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
      .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 02187B40 c:\program files\trusteer\rapport\bin\rooksdol.dll (Rooks/Dolomite/Trusteer Ltd.)
      .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] kernel32.dll!SetUnhandledExceptionFilter 76E4A84F 6 Bytes PUSH 71510022; RET
      .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!DdeInitializeW 76FA7921 6 Bytes PUSH 714E0022; RET
      .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!RegisterClassExW 76FADA30 6 Bytes PUSH 716E0022; RET
      .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!GetMessageW 76FBFEF7 6 Bytes PUSH 71480022; RET
      .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!TranslateMessage 76FC01AD 6 Bytes PUSH 71410022; RET
      .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] USER32.dll!GetClipboardData 76FE715A 6 Bytes PUSH 714B0022; RET
      .text C:\Program Files\Mozilla Firefox\firefox.exe[3200] GDI32.dll!BitBlt 76F070A6 6 Bytes PUSH 71540022; RET
      .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] ntdll.dll!KiUserApcDispatcher 77855D18 5 Bytes JMP 00438CE0 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (RapportService/Trusteer Ltd.)
      .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] WS2_32.dll!getaddrinfo 77A2418A 5 Bytes JMP 71670022
      .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] WS2_32.dll!gethostbyname 77A362D4 5 Bytes JMP 716E0022
      .text C:\Program Files\Spyware Doctor\pctsTray.exe[3848] kernel32.dll!CreateThread + 1A 76E6C928 4 Bytes CALL 0044B8D9 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)

      ---- Kernel IAT/EAT - GMER 1.0.15 ----

      IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [806916D6] \SystemRoot\System32\Drivers\spxo.sys
      IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80691042] \SystemRoot\System32\Drivers\spxo.sys
      IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [80691800] \SystemRoot\System32\Drivers\spxo.sys
      IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [806910C0] \SystemRoot\System32\Drivers\spxo.sys
      IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8069113E] \SystemRoot\System32\Drivers\spxo.sys
      IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [806A0E9C] \SystemRoot\System32\Drivers\spxo.sys
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortNotification] CC358B04
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortUchar] 838BA5AF
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortUlong] 458B38C6
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetPhysicalAddress] A5A5A514
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortConvertPhysicalAddressToUlong] 100D8BA5
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetScatterGatherList] 5F8BA580
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortUchar] 30810889
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortStallExecution] 54771129
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetParentBusType] 10C25D5E
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortRequestCallback] 8B55CC00
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortWritePortBufferUshort] 084D8BEC
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetUnCachedExtension] 0CF0918B
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortCompleteRequest] 458B0000
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortMoveMemory] 8B108910
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortCompleteAllActiveRequests] 000CF491
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReleaseRequestSenseIrb] 04508900
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortBuildRequestSenseIrb] 053C7980
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortUshort] 560C558B
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortReadPortBufferUshort] C6127557
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortInitialize] B18D0502
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortGetDeviceBase] 00000CF8
      IAT \SystemRoot\System32\Drivers\au8ydgj3.SYS[ataport.SYS!AtaPortDeviceStateChange] A508788D

      ---- User IAT/EAT - GMER 1.0.15 ----

      IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1104] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 71670000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\GDI32.dll [USER32.dll!GetWindowRect] 71450000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\ole32.dll [USER32.dll!GetWindowRect] 71450000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetWindowRect] 71450000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Mozilla Firefox\firefox.exe[3200] @ C:\Windows\system32\WININET.dll [USER32.dll!GetWindowRect] 71450000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3328] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 716B0000
      IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3848] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
      IAT C:\Program Files\Spyware Doctor\pctsTray.exe[3848] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044BA30] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)

      ---- Devices - GMER 1.0.15 ----

      Device \FileSystem\Ntfs \Ntfs 8460C1F8
      Device \Driver\volmgr \Device\VolMgrControl 846081F8
      Device \Driver\usbuhci \Device\USBPDO-0 854F31F8
      Device \Driver\sptd \Device\1136032336 spxo.sys
      Device \Driver\usbuhci \Device\USBPDO-1 854F31F8
      Device \Driver\usbehci \Device\USBPDO-2 854E41F8
      Device \Driver\usbuhci \Device\USBPDO-3 854F31F8
      Device \Driver\usbuhci \Device\USBPDO-4 854F31F8

      AttachedDevice \Driver\tdx \Device\Tcp pctgntdi.sys

      Device \Driver\usbuhci \Device\USBPDO-5 854F31F8
      Device \Driver\usbehci \Device\USBPDO-6 854E41F8
      Device \Driver\volmgr \Device\HarddiskVolume1 846081F8
      Device \Driver\PCI_PNP0319 \Device\00000058 spxo.sys
      Device \Driver\volmgr \Device\HarddiskVolume2 846081F8
      Device \Driver\cdrom \Device\CdRom0 8551E1F8
      Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8460A1F8
      Device \Driver\atapi \Device\Ide\IdePort0 8460A1F8
      Device \Driver\atapi \Device\Ide\IdePort1 8460A1F8
      Device \Driver\atapi \Device\Ide\IdePort2 8460A1F8
      Device \Driver\msahci \Device\Ide\PciIde1Channel0 8460B1F8
      Device \Driver\msahci \Device\Ide\PciIde1Channel2 8460B1F8
      Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-2 8460A1F8
      Device \Driver\cdrom \Device\CdRom1 8551E1F8
      Device \Driver\netbt \Device\NetBT_Tcpip_{D1957ABD-6FAC-430A-98F1-B0F3C259C5C7} 85B68500
      Device \Driver\netbt \Device\NetBt_Wins_Export 85B68500
      Device \Driver\Smb \Device\NetbiosSmb 85C3F1F8
      Device \Driver\iScsiPrt \Device\RaidPort0 855771F8
      Device \Driver\usbuhci \Device\USBFDO-0 854F31F8
      Device \Driver\usbuhci \Device\USBFDO-1 854F31F8
      Device \Driver\netbt \Device\NetBT_Tcpip_{0C10FA32-146C-4B41-A940-8A06AA1733CB} 85B68500
      Device \Driver\usbehci \Device\USBFDO-2 854E41F8
      Device \Driver\usbuhci \Device\USBFDO-3 854F31F8
      Device \Driver\usbuhci \Device\USBFDO-4 854F31F8
      Device \Driver\usbuhci \Device\USBFDO-5 854F31F8
      Device \Driver\usbehci \Device\USBFDO-6 854E41F8
      Device \Driver\au8ydgj3 \Device\Scsi\au8ydgj31Port4Path0Target0Lun0 855621F8
      Device \Driver\au8ydgj3 \Device\Scsi\au8ydgj31 855621F8
      Device \FileSystem\cdfs \Cdfs 855111F8

      ---- EOF - GMER 1.0.15 ----


      many thanks!Quote
      malicious software removal tool today alerted me and said it found a Trojan:WinNT/Bubnix.gen!A which it partially removed.
      What do you mean by "partially removed"?

      Do you have your OS CD/DVD?

      If so,

      1/ Click the Start button.

      2/ From the Start Menu, Click All programs followed by Accessories.

      3/ In the Accessories menu, Right Click on the Command Prompt option.

      4/ From the drop down menu that appears, Click on the Run as administrator option.

      5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc.

      6/ In the Command Prompt window, type: sfc /scannow and then press Enter.

      7/ A message will appear stating that the system scan will begin.

      8/ Be patient because the scan may take some time.

      9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue.

      10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations.

      11/ After the scan has completed, Close the command prompt window.
      Dear Dave
      I just wanted to thank you for all your help!!!
      You definitely got it working again and then I was really busy for a few days and always planning to eventually do all the last things you suggested and never got round to it.
      In the meantime my laptop entirely broke, but I just wanna thank you for all your efforts. I felt really lucky that there was a forum like this and someone out there who understood all these logs...
      Thank you!!! You're welcome. I will lock this thread. If you need it opened for any reason, please pm me.
      343.

      Solve : Blue screen + AVG not working + webcam not working + unknown USB software?

      Answer»

      You're welcome. I will lock this THREAD. If you NEED it re-opened, PLEASE pm me.

      344.

      Solve : Opening/Saving files kicks me off the internet?

      Answer»

      Yes we have done that many times, waiting for several minutes. Also, every time that we get disconnected after opening or SAVING a file, and use the troubleshooter to get reconnected, it prompts us at the end to unplug the POWER cord, wait 10 seconds and plug it back in. After that is done, we click "CHECK to see if the problem is resolved". That's when it checks the connection and gives me that message about the DEFAULT gateway not being available and the local area connection not having a valid IP address. It always says that the local area connection issue is fixed and that the default gateway issue is still detected. When we unplug that cord, we remove it from the back of the router, but the other end of the cord stays plugged into the power strip under the desk. That's what the technicians from the cable company said to do. Also they have been out several times to check our connection and they say there is no problem. I'm pretty sure they've also tested the router and the modem and said that they were ok too. They've told us that we probably either have a virus or it's a problem in the settings somewhere in the computer. Another thing I forgot to TELL you is that we have a laptop that connects through the same router. The only time it gets disconnected is when this computer gets disconnected first. When we first got this computer (last January) I tried to set it up to be able to share files with the laptop and every time I attempted I was disconnected from this one and then the laptop. I eventually gave up on that.Quote

      The only time it gets disconnected is when this computer gets disconnected first.
      This really sounds like a problem with the router. Think about it. The laptop is running well on the router and then you start up your pc and it gets disconnected and, at the same time, your laptop gets disconnected. The router is dropping out but I'm not sure what's causing it. S suspect it's something that was caused when you attempted to swap files. Please try this.

      Reset Explorer Settings IE I've done that before and I just did it again. It did not fix the problem.Quote
      I've done that before and I just did it again. It did not fix the problem.
      Just as I thought. The problem appears to be with the router. You can post a thread in the this forum. Someone there could possibly help you with this problem.
      Thank you for your help so far.You're welcome. I will lock this thread. If you need it opened, please pm me.
      345.

      Solve : System Tool 2011?

      Answer»

      C:\Users\McGilvray\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00004ePDF/Exploit.Pidief.PFK.Gen trojanHeather, please run the ESET scan again and fix the problem. How's your computer running now?Sorry for the late reply was UNAVAILABLE for a few days.

      I ran the latest scan and deleted the infected file.

      My computer seems to be running great!!!!

      Thanks so much for you help.....I so appreciate it. If ony we could get rid of the people that make these stupid THINGS to get on computers!

      I do have a couple quick questions:

      1. Is there a way to prevent this from happening in the future?

      2. We have an older PC that has Windows XP. Following the instrctions on this site I added an extra FIREWALL but now it seems to be running funny. Should I post as a seperate problem.

      Thank you again for all you do to help people!

      HeatherQuote

      1. Is there a way to prevent this from happening in the future?
      Yes. Make sure your Anti-Virus is kept up-to-date and follow the instructions below.

      Quote
      2. We have an older PC that has Windows XP. Following the instrctions on this site I added an extra firewall but now it seems to be running funny. Should I post as a seperate problem.
      You should only have one firewall running on your computer. You should disable the Windows firewall. It that doesn't help, please start a new thread in the proper forum, not this one.

      We should do some cleanup. You can keep SAS and MBAM, if you wish. Update them and run them regularly.

      To remove all of the tools we used and the files and folders they created do the following:
      Double click OTL.exe.
      • Click the CleanUp button.
      • Select Yes when the "Begin cleanup Process?" prompt appears.
      • If you are prompted to Reboot during the cleanup, select Yes.
      • The tool will delete itself once it finishes.
      Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
      ************************************************
      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
      ************************************************
      Looking over your log it seems you don't have any evidence of a third party firewall.

      Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

      Remember only install ONE firewall

      1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
      2) Online Armor
      3) Agnitum Outpost
      4) PC Tools Firewall Plus

      If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to USE only one firewall at the same time.
      *******************************************************
      Use the Secunia Software Inspector to check for out of date software.

      •Click Start Now

      •Check the box next to Enable thorough system inspection.

      •Click Start

      •Allow the scan to finish and scroll down to see if any updates are needed.
      •Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe Surfing!
      Hi,

      Looks like I have some more work to do. But it will be worth it if this stops things from happening again. Hopefully I can get through it all without too many questions.

      I do have one question at first glance:

      Should I download a firewall if the computers that is using the OPERATING system Windows 7 or only for the computer that is using the operating system Windows XP?

      Thanks, Heather Quote
      Should I download a firewall if the computers that is using the operating system Windows 7 or only for the computer that is using the operating system Windows XP?
      You should consider using a Firewall on XP especially if your using your computer for banking and other financial transactions.
      You will have to research the Firewall on Windows 7 to see if it blocks traffic in both directions.
      346.

      Solve : Application cannot be executed. The file (insert file).exe is infected.?

      Answer»

      So I just had this happen to me tonight, and I am getting quite annoyed with 50 porn websites come up, a popup asking me to run the antivirus software, and not being able to connect to the internet, or run anything. I looked up on my parents' computer for a fix to this problem, and realized firefox works. So i decided to fix the proxy settings so i can browse the internet on my laptop rather than walk back and forth between rooms.

      I start browsing to find out what I should do, and i try OTL, the response is, OTL.exe is infected. I try malwarebytes, the response is, mbam.exe is infected. So i try avg, the response was something quite longer, but ended up .exe is infected. I figured there was nothing i can do but try and find a way to stop the popups for the TIME being. I try and run task manager to stop the popups, and tasmgr.exe is infected. I browse some more and i see i need to change the file names to explorer.exe. That did not help me at all either. It just said explorer.exe is infected.

      I had already tried backup and restore center, but when i tried restoring, it said something else. SDLCT.exe is infected. So I had come to the point where I knew I was screwed. I came to the conclusion, after reading as well, to start my computer in safe mode. Finally I am in safe mode, I am running OTL with a log that was to be posted in custom scans/box, and I am currently waiting the 2 logs to appear. I just figured I would bring this up because apparently, someone should get sued for this.

      Anyhow, as soon as the logs appear, I shall post them in the topic.

      Thank you, and I appreciate the help.

      Sincerely,
      gdamatov77OTL.Txt - First part of log


      OTL logfile created on: 1/2/2011 2:06:06 AM - Run 1
      OTL by OldTimer - Version 3.1.27.0 Folder = C:\Users\Gabi\Downloads
      64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
      Internet Explorer (Version = 8.0.6001.18999)
      Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

      4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 74.00% Memory free
      8.00 Gb Paging File | 7.00 Gb Available in Paging File | 91.00% Paging File free
      Paging file location(s): ?:\pagefile.sys [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
      Drive C: | 286.37 Gb Total Space | 54.03 Gb Free Space | 18.87% Space Free | Partition Type: NTFS
      D: Drive not present or media not loaded
      E: Drive not present or media not loaded
      F: Drive not present or media not loaded
      G: Drive not present or media not loaded
      H: Drive not present or media not loaded
      I: Drive not present or media not loaded

      Computer Name: ADMINISTRATOR
      Current User Name: Gabi
      Logged in as Administrator.

      Current Boot Mode: SafeMode with Networking
      Scan Mode: Current user
      Include 64bit Scans
      Company Name Whitelist: Off
      Skip Microsoft Files: On
      File Age = 14 Days
      Output = Standard

      ========== Processes (SafeList) ==========

      PRC - [2011/01/02 01:48:16 | 00,548,352 | ---- | M] (OldTimer Tools) -- C:\Users\Gabi\Downloads\OTL.exe
      PRC - [2010/12/08 18:28:23 | 00,991,800 | ---- | M] (Google Inc.) -- C:\Users\Gabi\AppData\Local\Google\Chrome\Application\chrome.exe


      ========== Modules (SafeList) ==========

      MOD - [2011/01/02 01:48:16 | 00,548,352 | ---- | M] (OldTimer Tools) -- C:\Users\Gabi\Downloads\OTL.exe
      MOD - [2010/08/31 10:39:57 | 01,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll
      MOD - [2008/11/26 23:35:06 | 01,748,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\GdiPlus.dll
      MOD - [2008/01/20 21:51:41 | 02,537,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wpdshext.dll
      MOD - [2008/01/20 21:50:46 | 00,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\fontext.dll
      MOD - [2008/01/20 21:50:03 | 00,450,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll


      ========== Win32 Services (SafeList) ==========

      SRV:64bit: - [2010/12/13 17:16:22 | 00,932,640 | ---- | M] (Apple Inc.) [On_Demand | Stopped] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
      SRV:64bit: - [2009/09/26 03:28:30 | 04,924,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
      SRV:64bit: - [2008/03/31 04:55:48 | 00,225,280 | ---- | M] (ASUSTek Computer Inc.) [Auto | Stopped] -- C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe -- (ADSMService)
      SRV:64bit: - [2008/01/20 21:47:32 | 00,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
      SRV:64bit: - [2007/08/08 02:08:40 | 00,094,208 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
      SRV - [2010/12/17 12:35:28 | 00,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
      SRV - [2010/12/08 18:01:35 | 03,020,888 | ---- | M] () [Auto | Stopped] -- c:\Program Files (x86)\Common Files\Akamai\netsession_win_aeec0f0.dll -- (Akamai)
      SRV - [2010/10/16 00:40:40 | 00,037,664 | ---- | M] (Apple Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
      SRV - [2010/09/19 21:09:26 | 00,030,192 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-051210-111108)
      SRV - [2010/07/27 17:44:08 | 00,345,376 | ---- | M] (Apple Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe -- (Bonjour Service)
      SRV - [2010/06/13 22:08:26 | 00,075,064 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
      SRV - [2010/03/18 13:27:14 | 01,020,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
      SRV - [2010/03/18 13:27:14 | 00,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
      SRV - [2010/03/18 12:16:28 | 00,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
      SRV - [2010/02/19 13:37:14 | 00,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
      SRV - [2009/09/26 06:35:02 | 00,819,600 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE -- (cvhsvc)
      SRV - [2009/09/23 14:04:42 | 00,447,848 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
      SRV - [2009/09/23 14:04:42 | 00,203,608 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
      SRV - [2009/08/13 16:34:07 | 00,182,768 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
      SRV - [2008/12/08 16:01:58 | 00,533,344 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
      SRV - [2008/08/13 22:59:52 | 00,100,920 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe -- (ASLDRService)
      SRV - [2008/07/27 13:01:49 | 00,093,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
      SRV - [2008/06/09 12:21:58 | 00,073,728 | ---- | M] (Hewlett-Packard Company) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService)
      SRV - [2006/11/02 08:34:14 | 00,000,000 | ---D | M] [Unknown | Stopped] -- C:\Windows\SysWOW64\Msdtc -- (MSDTC)
      SRV - [2006/11/02 01:35:15 | 00,060,994 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vds.mof -- (vds)
      SRV - [2006/11/02 01:35:15 | 00,055,846 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vss.mof -- (VSS)


      ========== Driver Services (SafeList) ==========

      DRV:64bit: - [2010/09/28 15:44:52 | 00,051,712 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64)
      DRV:64bit: - [2009/09/23 14:04:52 | 00,025,944 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\Sftredirlh.sys -- (Sftredir)
      DRV:64bit: - [2009/05/18 14:17:08 | 00,034,152 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM)
      DRV:64bit: - [2009/02/11 04:26:17 | 00,407,576 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\iaStor.sys -- (iaStor)
      DRV:64bit: - [2008/12/08 16:35:52 | 00,061,792 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\fssfltr.sys -- (fssfltr)
      DRV:64bit: - [2008/10/08 22:39:01 | 01,821,952 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
      DRV:64bit: - [2008/08/28 10:57:23 | 04,745,216 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\NETw5v64.sys -- (NETw5v64) Intel(R)
      DRV:64bit: - [2008/08/06 19:26:07 | 00,174,592 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169)
      DRV:64bit: - [2008/06/24 15:50:00 | 00,065,024 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\rimmpx64.sys -- (rimmptsk)
      DRV:64bit: - [2008/06/03 17:41:49 | 00,017,464 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\kbfiltr.sys -- (kbfiltr)
      DRV:64bit: - [2008/01/20 21:47:28 | 00,046,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
      DRV:64bit: - [2008/01/20 21:47:27 | 00,168,704 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbvideo.sys -- (usbvideo) USB Video Device (WDM)
      DRV:64bit: - [2008/01/20 21:46:55 | 00,111,104 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\sdbus.sys -- (sdbus)
      DRV:64bit: - [2008/01/20 21:46:51 | 00,017,792 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\CmBatt.sys -- (CmBatt)
      DRV:64bit: - [2007/12/18 19:57:12 | 00,059,392 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\itecir.sys -- (itecir)
      DRV:64bit: - [2007/08/10 22:19:44 | 00,034,872 | ---- | M] () [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\AsDsm.sys -- (AsDsm)
      DRV:64bit: - [2007/08/02 16:33:04 | 00,012,672 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dadder.sys -- (DAdderFltr)
      DRV:64bit: - [2007/07/27 21:45:52 | 00,057,856 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\rixdpx64.sys -- (rismxdp)
      DRV:64bit: - [2007/07/26 22:33:54 | 00,055,296 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\rimspx64.sys -- (rimsptsk)
      DRV:64bit: - [2007/07/24 13:11:32 | 00,014,904 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Program Files\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)
      DRV:64bit: - [2006/11/02 00:28:10 | 00,273,920 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HdAudio.sys -- (HdAudAddService)
      DRV:64bit: - [2006/10/28 09:01:07 | 00,013,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\ATK64AMD.sys -- (MTsensor)
      DRV:64bit: - [2006/10/03 20:45:36 | 00,273,408 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\yk60x64.sys -- (yukonx64)
      DRV - [2009/12/29 14:13:10 | 00,023,120 | ---- | M] (The Nielsen Company) [Kernel | System | Stopped] -- C:\Program Files (x86)\NetRatingsNetSight\NetSight\meter1\nnfwdk64.sys -- (nnfwdk)
      DRV - [2009/09/23 14:04:42 | 00,261,480 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\drivers\sftplaylh.sys -- (sftplay)
      DRV - [2009/09/23 14:04:42 | 00,017,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\drivers\SftVollh.sys -- (sftvol)
      DRV - [2009/09/23 14:04:38 | 00,712,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\drivers\SftFSlh.sys -- (sftfs)
      DRV - [2009/06/29 08:13:36 | 00,000,000 | ---D | M] [Kernel | On_Demand | Running] -- C:\Windows\ITECIR -- (itecir)
      DRV - [2008/10/08 22:38:27 | 00,015,497 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\snp2uvc.ini -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
      DRV - [2006/09/18 16:36:40 | 00,003,066 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysWOW64\wbem\tcpip.mof -- (Tcpip)
      DRV - [2006/09/18 16:35:23 | 00,001,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\wbem\mpsdrv.mof -- (mpsdrv)


      ========== Standard Registry (SafeList) ==========


      ========== Internet Explorer ==========

      IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
      IE - HKLM\..\URLSearchHook: {3a9262ef-45b5-46fc-b460-7053539c9176} - C:\Program Files (x86)\1Club.FM\tb1Clu.dll (Conduit Ltd.)
      IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)

      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
      IE - HKCU\..\URLSearchHook: {3a9262ef-45b5-46fc-b460-7053539c9176} - C:\Program Files (x86)\1Club.FM\tb1Clu.dll (Conduit Ltd.)
      IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8074

      ========== FireFox ==========

      FF - prefs.js..browser.search.defaultenginen ame: "Secure Search"
      FF - prefs.js..browser.search.selectedEngine: "Secure Search"
      FF - prefs.js..extensions.enabledItems: [emailprotected]:7
      FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
      FF - prefs.js..extensions.enabledItems: {8C59A18B-3C74-48F4-B107-39794720E289}:1.9.1
      FF - prefs.js..extensions.enabledItems: [emailprotected]:3.9.1.14019
      FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5
      FF - prefs.js..extensions.enabledItems: {D908A1CC-54B4-4af9-9BB4-964F5BD3CDB7}:5.2.4.10
      FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p="
      FF - prefs.js..network.proxy.http: "127.0.0.1"
      FF - prefs.js..network.proxy.http_port: 50370


      FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/10/18 01:04:11 | 00,000,000 | ---D | M]
      FF - HKLM\software\mozilla\Firefox\Extensions\\{D908A1CC-54B4-4af9-9BB4-964F5BD3CDB7}: C:\Program Files (x86)\NetRatingsNetSight\NetSight\meter1\FFAddon\ [2010/10/19 17:01:06 | 00,000,000 | ---D | M]
      FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/12/11 23:49:50 | 00,000,000 | ---D | M]
      FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/12/11 23:49:50 | 00,000,000 | ---D | M]

      [2010/02/10 14:39:40 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Mozilla\Extensions
      [2011/01/02 01:14:35 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Mozilla\Firefox\Profiles\f82upv91.default\extensions
      [2010/02/11 20:24:36 | 00,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Gabi\AppData\Roaming\Mozilla\Firefox\Profiles\f82upv91.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
      [2010/11/16 19:34:25 | 00,000,000 | ---D | M] (No name found) -- C:\Users\Gabi\AppData\Roaming\Mozilla\Firefox\Profiles\f82upv91.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
      [2010/10/26 19:05:17 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Mozilla\Firefox\Profiles\f82upv91.default\extensions\[emailprotected]
      [2010/03/25 12:48:37 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
      [2010/07/06 22:44:03 | 00,002,024 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\McSiteAdvisor.xml

      O1 HOSTS File: ([2006/09/18 16:37:24 | 00,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
      O1 - Hosts: 127.0.0.1 localhost
      O1 - Hosts: ::1 localhost
      O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
      O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg64.dll (Google Inc.)
      O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
      O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
      O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
      O2 - BHO: (1Club.FM Toolbar) - {3a9262ef-45b5-46fc-b460-7053539c9176} - C:\Program Files (x86)\1Club.FM\tb1Clu.dll (Conduit Ltd.)
      O2 - BHO: (Smart-Shopper) - {4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} - C:\Program Files (x86)\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll (SmartShopper Networks)
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
      O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
      O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
      O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
      O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
      O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
      O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
      O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
      O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
      O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
      O3 - HKLM\..\Toolbar: (1Club.FM Toolbar) - {3a9262ef-45b5-46fc-b460-7053539c9176} - C:\Program Files (x86)\1Club.FM\tb1Clu.dll (Conduit Ltd.)
      O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
      O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
      O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
      O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
      O3 - HKCU\..\Toolbar\WebBrowser: (1Club.FM Toolbar) - {3A9262EF-45B5-46FC-B460-7053539C9176} - C:\Program Files (x86)\1Club.FM\tb1Clu.dll (Conduit Ltd.)
      O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files (x86)\Vuze_Remote\tbVuze.dllĀ File not found
      O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
      O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
      O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
      O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
      O4 - HKLM..\Run: [iTunesHelper] C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
      O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
      O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
      O4 - HKCU..\Run: [cvfvixmq] C:\Users\Gabi\AppData\Local\Temp\drqjnfnkx\niftdpklajb.exe ()
      O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
      O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
      O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
      O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
      O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
      O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
      O9 - Extra Button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files (x86)\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll (SmartShopper Networks)
      O9 - Extra Button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files (x86)\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll (SmartShopper Networks)
      O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
      O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
      O13 - gopher Prefix: missing
      O13 - gopher Prefix: missing
      O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
      O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
      O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
      O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
      O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
      O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
      O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
      O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
      O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
      O18:64bit: - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - Reg Error: Key error. File not found
      O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
      O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (OldTimer Tools)
      O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (OldTimer Tools)
      O20 - HKCU Winlogon: Shell - (explorer.exe) - explorer.exe (OldTimer Tools)
      O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img29.jpg
      O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img29.jpg
      O32 - HKLM CDRom: AutoRun - 1
      O33 - MountPoints2\{47c70dec-167b-11df-b4f3-00261857549c}\Shell - "" = AutoRun
      O33 - MountPoints2\{47c70dec-167b-11df-b4f3-00261857549c}\Shell\AutoRun\command - "" = D:\LaunchU3.exe -- File not found
      O34 - HKLM BootExecute: (autocheck autochk *) - File not found
      64bit: O35 - comfile [open] -- "%1" %* File not found
      64bit: O35 - exefile [open] -- "%1" %* File not found
      O35 - comfile [open] -- "%1" %*
      O35 - exefile [open] -- "%1" %*

      ========== Files/Folders - Created Within 14 Days ==========

      [2011/01/02 01:26:59 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
      [2011/01/02 01:26:59 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
      [2011/01/02 01:26:56 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
      [2010/12/22 01:38:24 | 00,000,000 | ---D | C] -- C:\Users\Gabi\AppData\Roaming\Broken Rules
      [2010/12/21 00:05:26 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
      [2010/12/21 00:05:24 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
      [2010/12/21 00:04:14 | 00,000,000 | -HSD | C] -- C:\Config.Msi
      [2010/12/17 01:50:47 | 00,337,040 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistMSI200D.txt
      [2010/12/17 01:50:47 | 00,011,434 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistUI200D.txt
      [2010/12/12 12:23:02 | 00,329,354 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistMSI7D4A.txt
      [2010/12/12 12:23:02 | 00,011,202 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistUI7D4A.txt
      [2010/12/06 19:32:49 | 00,175,767 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_depcheck_NETFX_EXP_35.txt
      [2010/12/06 19:32:36 | 00,118,382 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_dotnetfx35install.txt
      [2010/12/06 19:32:36 | 00,001,678 | ---- | C] () -- C:\Users\Gabi\AppData\Local\uxeventlog.txt
      [2010/12/06 19:32:36 | 00,000,002 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_dotnetfx35error.txt
      [2010/12/06 19:31:47 | 00,382,680 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistMSI70A5.txt
      [2010/12/06 19:31:47 | 00,011,136 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistUI70A5.txt
      [2010/11/28 20:45:51 | 00,327,834 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistMSI3842.txt
      [2010/11/28 20:45:50 | 00,011,138 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistUI3842.txt
      [2010/11/16 19:31:00 | 00,407,316 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistMSI555C.txt
      [2010/11/16 19:30:58 | 00,114,630 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistUI555C.txt
      [2010/11/09 13:56:21 | 00,333,982 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistMSI3253.txt
      [2010/11/09 13:56:21 | 00,011,170 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistUI3253.txt
      [2010/10/18 02:59:19 | 03,595,691 | -H-- | C] () -- C:\Users\Gabi\AppData\Local\IconCache.db
      [2010/09/19 20:41:07 | 00,333,222 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistMSI5756.txt
      [2010/09/19 20:41:07 | 00,011,138 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistUI5756.txt
      [2010/07/19 22:13:39 | 00,000,120 | ---- | C] () -- C:\Users\Gabi\AppData\Local\Rsupegigusobo.dat
      [2010/07/19 22:13:39 | 00,000,000 | ---- | C] () -- C:\Users\Gabi\AppData\Local\Utagohomalo.bin
      [2010/05/04 16:13:17 | 00,333,016 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistMSI6BFE.txt
      [2010/05/04 16:13:17 | 00,011,918 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistUI6BFE.txt
      [2010/02/24 22:24:22 | 00,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
      [2010/02/11 20:24:40 | 00,076,407 | ---- | C] () -- C:\Users\Gabi\AppData\Roaming\Smiley.ico
      [2010/01/14 18:28:33 | 00,414,010 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistMSI40E2.txt
      [2010/01/14 18:28:32 | 00,012,156 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistUI40E2.txt
      [2009/12/29 20:40:42 | 00,001,356 | ---- | C] () -- C:\Users\Gabi\AppData\Local\d3d9caps.dat
      [2009/12/17 16:13:12 | 00,412,060 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistMSI4D91.txt
      [2009/12/17 16:13:11 | 00,011,410 | ---- | C] () -- C:\Users\Gabi\AppData\Local\dd_vcredistUI4D91.txt
      [2009/11/23 03:32:51 | 00,022,016 | ---- | C] () -- C:\Users\Gabi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
      [2009/08/13 04:19:10 | 00,002,039 | ---- | C] () -- C:\Users\Gabi\AppData\Roaming\install.dat
      [2009/08/13 04:10:07 | 00,070,760 | ---- | C] () -- C:\Users\Gabi\AppData\Local\GDIPFONTCACHEV1.DAT
      [2009/08/13 04:09:48 | 00,048,544 | ---- | C] () -- C:\ProgramData\nvModes.001
      [2009/06/29 08:32:41 | 00,048,544 | ---- | C] () -- C:\ProgramData\nvModes.dat
      [2006/11/02 10:25:49 | 00,000,174 | -HS- | C] () -- C:\Program Files (x86)\desktop.ini
      [2006/11/02 10:07:25 | 00,030,808 | ---- | C] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
      [2006/11/02 10:07:25 | 00,029,779 | ---- | C] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
      [2006/11/02 10:07:25 | 00,026,489 | ---- | C] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
      [2006/11/02 10:07:25 | 00,026,040 | ---- | C] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
      [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

      ========== Files - Modified Within 14 Days ==========

      [2011/01/02 01:59:09 | 10,485,760 | -HS- | M] () -- C:\Users\Gabi\NTUSER.DAT
      [2011/01/02 01:51:21 | 00,001,356 | ---- | M] () -- C:\Users\Gabi\AppData\Local\d3d9caps.dat
      [2011/01/02 01:45:45 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
      [2011/01/02 01:44:18 | 00,524,288 | -HS- | M] () -- C:\Users\Gabi\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
      [2011/01/02 01:44:18 | 00,065,536 | -HS- | M] () -- C:\Users\Gabi\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
      [2011/01/02 01:44:14 | 00,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
      [2011/01/02 01:44:14 | 00,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
      [2011/01/02 01:44:14 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
      [2011/01/02 01:44:04 | 03,595,691 | -H-- | M] () -- C:\Users\Gabi\AppData\Local\IconCache.db
      [2011/01/02 01:26:59 | 00,000,955 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
      [2011/01/02 01:11:00 | 00,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2960448035-153725743-1241152918-1000UA.job
      [2011/01/02 00:43:02 | 00,048,544 | ---- | M] () -- C:\ProgramData\nvModes.dat
      [2011/01/02 00:42:57 | 00,048,544 | ---- | M] () -- C:\ProgramData\nvModes.001
      [2011/01/01 09:57:00 | 00,000,466 | ---- | M] () -- C:\Windows\tasks\COMODO System Cleaner Update.job
      [2011/01/01 04:11:00 | 00,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2960448035-153725743-1241152918-1000Core.job
      [2010/12/21 20:30:45 | 00,007,062 | ---- | M] () -- C:\Users\Gabi\.recently-used.xbel
      [2010/12/21 00:06:07 | 00,001,701 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
      [2010/12/21 00:02:07 | 00,000,629 | ---- | M] () -- C:\Windows\SysNative\mapisvc.inf
      [2010/12/20 18:09:00 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
      [2010/12/20 18:08:40 | 00,024,152 | ---- | M] () -- C:\Windows\SysNative\drivers\mbam.sys
      [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

      ========== Files Created - No Company Name ==========

      [2011/01/02 01:26:59 | 00,000,955 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
      [2011/01/02 01:26:56 | 00,024,152 | ---- | C] () -- C:\Windows\SysNative\drivers\mbam.sys
      [2010/12/21 20:30:45 | 00,007,062 | ---- | C] () -- C:\Users\Gabi\.recently-used.xbel
      [2010/12/21 00:06:07 | 00,001,701 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
      [2010/09/15 20:35:42 | 00,000,268 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
      [2010/05/16 07:46:55 | 00,709,336 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
      [2008/11/07 20:08:20 | 00,362,029 | ---- | C] () -- C:\Windows\SysWow64\sqlite3.dll
      [2008/10/08 22:38:27 | 00,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini
      [2008/09/19 06:41:00 | 00,000,010 | ---- | C] () -- C:\Windows\SysWow64\ABLKSR.ini
      [2008/01/20 21:50:05 | 00,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
      [2008/01/20 21:49:49 | 00,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

      ========== LOP Check ==========

      [2009/09/07 16:10:22 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Absolute
      [2009/10/02 01:38:41 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\acccore
      [2010/12/10 15:07:19 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Atlus
      [2009/11/23 21:25:40 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\aVinci
      [2010/11/16 19:34:14 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Azureus
      [2010/12/14 17:05:13 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Beat Hazard
      [2010/10/17 12:55:49 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Blender Foundation
      [2010/12/22 01:38:24 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Broken Rules
      [2010/12/06 19:35:11 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Chime
      [2010/05/16 07:37:37 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\GetRightToGo
      [2010/12/09 01:22:35 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\gtk-2.0
      [2010/09/29 16:00:37 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\HLSW
      [2010/05/16 07:48:03 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\NVD
      [2010/08/11 17:38:46 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Pogo
      [2010/12/14 01:39:32 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\ReactGames
      [2011/01/02 01:41:45 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\SoftGrid Client
      [2010/05/16 07:48:04 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\TP
      [2010/11/16 20:07:52 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\TuneUpMedia
      [2010/02/11 20:21:02 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Uniblue
      [2010/07/25 09:56:17 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\Unity
      [2010/10/19 00:44:16 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\WhiteSmoke
      [2010/09/22 00:54:16 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\X-Chat 2
      [2010/12/17 01:51:05 | 00,000,000 | ---D | M] -- C:\Users\Gabi\AppData\Roaming\ZombieDriver
      [2011/01/02 01:44:14 | 00,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

      ========== Purity Check ==========



      ========== Custom Scans ==========


      < %systemroot%\*. /mp /s >

      < %systemroot%\system32\*.dll /lockedfiles >

      < %systemroot%\system32\*.exe /lockedfiles >

      < %systemroot%\Tasks\*.job /lockedfiles >

      < %systemroot%\system32\drivers\*.sys /lockedfiles >

      < %systemroot%\System32\config\*.sav >

      < %systemroot%\system32\*.sys >

      < %systemroot%\system32\drivers\*.dll >

      < %systemroot%\system32\drivers\*.ini >

      < %systemroot%\system32\drivers\*.exe >

      < %SYSTEMDRIVE%\*.* >
      [2008/11/27 21:10:54 | 00,000,016 | ---- | M] () -- C:\app14.log
      [2009/05/11 08:49:02 | 00,000,022 | ---- | M] () -- C:\app2.log
      [2008/11/25 05:07:32 | 00,000,081 | ---- | M] () -- C:\app4.log
      [2010/10/04 14:06:08 | 00,000,322 | ---- | M] () -- C:\BnetLog.txt
      [2008/01/20 21:50:15 | 00,333,203 | RHS- | M] () -- C:\bootmgr
      [2008/09/18 09:01:40 | 00,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
      [2009/06/29 08:44:04 | 00,018,370 | ---- | M] () -- C:\devlist.txt
      [2009/05/03 21:55:51 | 00,000,025 | ---- | M] () -- C:\Driver.10
      [2007/11/07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.1028.txt
      [2007/11/07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.1031.txt
      [2007/11/07 08:00:40 | 00,010,134 | ---- | M] () -- C:\eula.1033.txt
      [2007/11/07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.1036.txt
      [2007/11/07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.1040.txt
      [2007/11/07 08:00:40 | 00,000,118 | ---- | M] () -- C:\eula.1041.txt
      [2007/11/07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.1042.txt
      [2007/11/07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.2052.txt
      [2007/11/07 08:00:40 | 00,017,734 | ---- | M] () -- C:\eula.3082.txt
      [2009/06/29 08:42:03 | 00,000,009 | ---- | M] () -- C:\Finish.log
      [2009/04/30 03:36:43 | 01,048,576 | RH-- | M] () -- C:\G60VxAS.BIN
      [2007/11/07 08:00:40 | 00,001,110 | ---- | M] () -- C:\globdata.ini
      [2009/06/29 08:34:51 | 01,553,388 | ---- | M] () -- C:\if.log
      [2009/06/29 08:12:56 | 23,134,208 | ---- | M] () -- C:\inject.log
      [2009/06/29 08:12:56 | 22,582,367 | ---- | M] () -- C:\inject.log.txt
      [2007/11/07 08:03:18 | 00,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
      [2007/11/07 08:00:40 | 00,000,843 | ---- | M] () -- C:\install.ini
      [2007/11/07 08:03:18 | 00,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
      [2007/11/07 08:03:18 | 00,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
      [2007/11/07 08:03:18 | 00,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
      [2007/11/07 08:03:18 | 00,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
      [2007/11/07 08:03:18 | 00,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
      [2007/11/07 08:03:18 | 00,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
      [2007/11/07 08:03:18 | 00,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
      [2007/11/07 08:03:18 | 00,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
      [2007/11/07 08:03:18 | 00,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
      [2009/10/02 01:38:31 | 00,000,363 | -H-- | M] () -- C:\IPH.PH
      [2008/09/19 06:33:21 | 00,000,003 | ---- | M] () -- C:\K522.txt
      [2008/08/08 02:22:19 | 00,000,030 | ---- | M] () -- C:\NERO.LOG
      [2010/10/19 16:54:27 | 00,000,451 | ---- | M] () -- C:\nsinst.log
      [2011/01/02 01:45:22 | 31,264,7679 | -HS- | M] () -- C:\pagefile.sys
      [2009/06/28 19:18:30 | 00,000,105 | ---- | M] () -- C:\Pass.txt
      [2009/06/04 03:00:23 | 00,003,412 | ---- | M] () -- C:\Patch.LOG
      [2010/04/08 00:00:22 | 00,013,030 | ---- | M] () -- C:\PDOXUSRS.NET
      [2009/06/29 08:08:38 | 00,002,000 | ---- | M] () -- C:\RHDSetup.log
      [2009/06/29 08:10:28 | 00,000,209 | ---- | M] () -- C:\setup.log
      [2008/09/19 06:43:09 | 00,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
      [2008/09/19 06:43:09 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
      [2006/05/15 19:22:24 | 00,000,005 | ---- | M] () -- C:\Store.LOG
      [2009/06/29 07:01:51 | 00,000,166 | ---- | M] () -- C:\SumHidd.txt
      [2009/06/29 07:01:25 | 00,000,098 | ---- | M] () -- C:\SumOS.txt
      [2009/02/11 22:50:06 | 00,000,025 | ---- | M] () -- C:\V622.TXT
      [2007/11/07 08:00:40 | 00,005,686 | ---- | M] () -- C:\vcredist.bmp
      [2007/11/07 08:09:22 | 01,442,522 | ---- | M] () -- C:\VC_RED.cab
      [2007/11/07 08:12:28 | 00,232,960 | ---- | M] () -- C:\VC_RED.MSI
      [2009/02/10 21:46:26 | 00,000,041 | ---- | M] () -- C:\WindowsLive_US.TXT

      < %PROGRAMFILES%\*. >
      [2009/12/15 18:43:29 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\1Club.FM
      [2010/11/16 19:53:09 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe
      [2010/11/15 20:57:01 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Adobe Media Player
      [2009/12/17 09:02:48 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Apple Software Update
      [2010/10/22 14:05:26 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Ask.com
      [2009/06/29 08:29:23 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\ASUS
      [2010/07/19 23:00:23 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\AVG
      [2009/06/29 07:35:41 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\aVinci
      [2009/06/29 07:30:04 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Best Buy Games
      [2010/09/26 23:02:40 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Bonjour
      [2010/11/15 20:55:25 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Common Files
      [2010/11/04 08:56:35 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\COMODO
      [2009/12/15 18:43:28 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Conduit
      [2010/11/16 19:30:06 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\ConduitEngine
      [2010/03/25 12:43:24 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\ConsoleClassix.com
      [2009/06/29 07:30:00 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\CyberLink
      [2010/10/04 13:21:35 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Diablo II
      [2010/09/15 15:46:41 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\DivX
      [2009/06/29 08:33:50 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Downloaded Installations
      [2009/11/24 01:13:39 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Electronic Arts
      [2009/06/29 07:33:32 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Geek Squad
      [2009/12/21 12:20:55 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\GIMP-2.0
      [2008/09/19 06:10:59 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Google
      [2010/09/19 20:41:05 | 00,000,000 | --SD | M] -- C:\Program Files (x86)\HLSW
      [2010/11/04 10:16:18 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Image-Line
      [2010/11/07 16:01:59 | 00,000,000 | -H-D | M] -- C:\Program Files (x86)\InstallShield Installation Information
      [2009/06/29 07:44:14 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Intel
      [2010/12/16 03:22:50 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Internet Explorer
      [2010/12/21 00:06:01 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\iTunes
      [2010/03/25 12:47:16 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Java
      [2010/02/11 20:24:41 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\jZip
      [2009/06/29 07:33:49 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\LFLInstall
      [2011/01/02 01:29:42 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
      [2009/08/13 04:15:20 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft
      [2010/05/16 07:46:39 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Application Virtualization Client
      [2010/05/16 07:46:35 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office
      [2008/09/19 06:31:05 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Office Suite Activation Assistant
      [2010/10/02 21:13:28 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Silverlight
      [2009/08/13 04:14:18 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
      [2010/12/16 03:04:01 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft Works
      [2010/12/06 19:33:53 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft XNA
      [2010/06/25 02:02:22 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Microsoft.NET
      [2010/09/13 17:49:19 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mIRC
      [2010/09/19 21:09:27 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox
      [2006/11/02 10:07:27 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\MSBuild
      [2010/10/19 16:54:26 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\NetRatingsNetSight
      [2010/06/13 22:07:04 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\NVIDIA Corporation
      [2010/08/11 17:38:02 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Oberon Media
      [2010/01/14 18:28:30 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\OpenAL
      [2010/03/09 03:15:02 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Outsim
      [2008/09/19 06:12:07 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Picasa2
      [2010/12/02 13:48:10 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Project64 1.6
      [2010/12/11 23:49:49 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\QuickTime
      [2009/08/13 16:23:50 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Razer
      [2010/10/18 01:03:55 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Real
      [2009/06/29 08:15:03 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Realtek
      [2010/06/13 18:45:46 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Realtime Worlds
      [2006/11/02 10:07:27 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Reference Assemblies
      [2009/11/26 23:50:55 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Respondus LockDown Browser
      [2010/11/21 11:32:19 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Safari
      [2010/02/24 22:21:54 | 00,000,000 | R--D | M] -- C:\Program Files (x86)\Skype
      [2010/02/11 20:24:39 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Smart-Shopper
      [2011/01/02 00:36:29 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Steam
      [2009/06/29 08:08:38 | 00,000,000 | -H-D | M] -- C:\Program Files (x86)\Temp
      [2010/10/18 00:58:06 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\The Weather Channel FW
      [2010/11/16 19:31:33 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\TuneUpMedia
      [2006/11/02 10:36:07 | 00,000,000 | -H-D | M] -- C:\Program Files (x86)\Uninstall Information
      [2010/09/15 20:35:44 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Ventrilo
      [2010/08/28 23:06:09 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Veoh Networks
      [2010/11/04 10:15:58 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\VstPlugins
      [2010/04/12 09:04:36 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\VTFEdit
      [2010/11/16 19:30:12 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Vuze_Remote
      [2010/10/19 00:44:32 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\WhiteSmoke
      [2008/01/20 22:09:48 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Calendar
      [2008/01/20 22:09:47 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Collaboration
      [2008/01/20 22:09:41 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Defender
      [2009/08/13 04:15:12 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live
      [2009/08/13 04:13:12 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live SkyDrive
      [2008/09/19 06:07:15 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Live Toolbar
      [2010/12/16 03:22:50 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Mail
      [2010/10/14 06:33:38 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Media Player
      [2006/11/02 10:07:27 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Windows NT
      [2008/01/20 22:09:46 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Photo Gallery
      [2008/01/20 22:09:48 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Windows Sidebar
      [2009/06/29 08:16:18 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Wireless Console 2
      [2010/09/13 17:57:04 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\xchat

      < %appdata%\*.* >
      [2009/09/07 16:10:21 | 00,002,039 | ---- | M] () -- C:\Users\Gabi\AppData\Roaming\install.dat
      [2009/03/02 18:48:36 | 00,076,407 | ---- | M] () -- C:\Users\Gabi\AppData\Roaming\Smiley.ico


      < MD5 for: AGP440.SYS >
      [2008/01/20 21:46:51 | 00,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
      [2008/01/20 21:46:51 | 00,064,568 | ---- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys

      < MD5 for: ATAPI.SYS >
      [2008/01/20 21:46:50 | 00,022,584 | ---- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
      [2009/04/11 02:15:00 | 00,020,952 | ---- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 -- C:\Windows\SoftwareDistribution\Download\61da130e21aad3387c2fa3ca1d469de3\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys

      < MD5 for: CNGAUDIT.DLL >
      [2006/11/02 06:16:48 | 00,014,848 | ---- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 -- C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
      [2006/11/02 04:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
      [2006/11/02 04:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\SysWOW64\cngaudit.dll
      [2006/11/02 04:46:03 | 00,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

      < MD5 for: DISK.SYS >
      [2008/01/20 21:46:53 | 00,068,664 | ---- | M] (Microsoft Corporation) MD5=2DC415FC05FB8A079F896CBBACB19324 -- C:\Windows\winsxs\amd64_disk.inf_31bf3856ad364e35_6.0.6001.18000_none_55e51d682c89f490\disk.sys
      [2009/04/11 02:15:25 | 00,067,032 | ---- | M] (Microsoft Corporation) MD5=B0107E40ECDB5FA692EBF832F295D905 -- C:\Windows\SoftwareDistribution\Download\61da130e21aad3387c2fa3ca1d469de3\amd64_disk.inf_31bf3856ad364e35_6.0.6002.18005_none_57d0967429abbfdc\disk.sys

      < MD5 for: IASTORV.SYS >
      [2008/01/20 21:46:59 | 00,290,872 | ---- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 -- C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys

      < MD5 for: NETLOGON.DLL >
      [2008/01/20 21:51:03 | 00,716,800 | ---- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 -- C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
      [2009/04/11 01:28:23 | 00,592,896 | ---- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE -- C:\Windows\SoftwareDistribution\Download\61da130e21aad3387c2fa3ca1d469de3\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
      [2009/04/11 02:11:16 | 00,717,312 | ---- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB -- C:\Windows\SoftwareDistribution\Download\61da130e21aad3387c2fa3ca1d469de3\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
      [2008/01/20 21:48:28 | 00,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\SysWOW64\netlogon.dll
      [2008/01/20 21:48:28 | 00,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\SysWOW64\netlogon.dll
      [2008/01/20 21:48:28 | 00,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll

      < MD5 for: NVSTOR.SYS >
      [2008/01/20 21:46:54 | 00,054,328 | ---- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA -- C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys

      < MD5 for: SCECLI.DLL >
      [2008/01/20 21:50:28 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\SysWOW64\scecli.dll
      [2008/01/20 21:50:28 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\SysWOW64\scecli.dll
      [2008/01/20 21:50:28 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
      [2008/01/20 21:49:49 | 00,235,520 | ---- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
      [2009/04/11 01:28:24 | 00,177,152 | ---- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 -- C:\Windows\SoftwareDistribution\Download\61da130e21aad3387c2fa3ca1d469de3\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
      [2009/04/11 02:11:23 | 00,235,520 | ---- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B -- C:\Windows\SoftwareDistribution\Download\61da130e21aad3387c2fa3ca1d469de3\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll

      < MD5 for: USBSTOR.SYS >
      [2008/01/20 21:47:25 | 00,066,048 | ---- | M] (Microsoft Corporation) MD5=586D9876A4945779C8EEA926C0D16889 -- C:\Windows\winsxs\amd64_usbstor.inf_31bf3856ad364e35_6.0.6001.18000_none_a4a4ea3a50308c79\USBSTOR.SYS
      [2009/04/11 00:39:38 | 00,077,824 | ---- | M] (Microsoft Corporation) MD5=B854C1558FCA0C269A38663E8B59B581 -- C:\Windows\SoftwareDistribution\Download\61da130e21aad3387c2fa3ca1d469de3\amd64_usbstor.inf_31bf3856ad364e35_6.0.6002.18005_none_a69063464d5257c5\USBSTOR.SYS

      < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

      ========== Alternate Data Streams ==========

      @Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:F3AB0B43
      < End of report >
      Extras.Txt - Second part of log


      OTL Extras logfile created on: 1/2/2011 2:06:06 AM - Run 1
      OTL by OldTimer - Version 3.1.27.0 Folder = C:\Users\Gabi\Downloads
      64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
      Internet Explorer (Version = 8.0.6001.18999)
      Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

      4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 74.00% Memory free
      8.00 Gb Paging File | 7.00 Gb Available in Paging File | 91.00% Paging File free
      Paging file location(s): ?:\pagefile.sys [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
      Drive C: | 286.37 Gb Total Space | 54.03 Gb Free Space | 18.87% Space Free | Partition Type: NTFS
      D: Drive not present or media not loaded
      E: Drive not present or media not loaded
      F: Drive not present or media not loaded
      G: Drive not present or media not loaded
      H: Drive not present or media not loaded
      I: Drive not present or media not loaded

      Computer Name: ADMINISTRATOR
      Current User Name: Gabi
      Logged in as Administrator.

      Current Boot Mode: SafeMode with Networking
      Scan Mode: Current user
      Include 64bit Scans
      Company Name Whitelist: Off
      Skip Microsoft Files: On
      File Age = 14 Days
      Output = Standard

      ========== Extra Registry (SafeList) ==========


      ========== File Associations ==========

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
      .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

      [HKEY_CURRENT_USER\SOFTWARE\Classes\]
      .html [@ = ChromeHTML] -- C:\Users\Gabi\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)

      ========== Shell Spawning ==========

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
      batfile [open] -- "%1" %* File not found
      cmdfile [open] -- "%1" %* File not found
      comfile [open] -- "%1" %* File not found
      exefile [open] -- "%1" %* File not found
      helpfile [open] -- Reg Error: Key error.
      htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
      htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
      inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()
      InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
      piffile [open] -- "%1" %* File not found
      regfile [merge] -- Reg Error: Key error.
      scrfile [config] -- "%1" File not found
      scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l ()
      scrfile [open] -- "%1" /S File not found
      txtfile [edit] -- Reg Error: Key error.
      Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
      Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
      Directory [cmd] -- cmd.exe /s /k pushd "%V" ()
      Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
      Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
      Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
      Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
      batfile [open] -- "%1" %*
      cmdfile [open] -- "%1" %*
      comfile [open] -- "%1" %*
      cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
      exefile [open] -- "%1" %*
      helpfile [open] -- Reg Error: Key error.
      htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
      htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
      inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
      piffile [open] -- "%1" %*
      regfile [merge] -- Reg Error: Key error.
      scrfile [config] -- "%1"
      scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
      scrfile [open] -- "%1" /S
      txtfile [edit] -- Reg Error: Key error.
      Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
      Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
      Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
      Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
      Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
      Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
      Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

      ========== Security Center Settings ==========

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
      "cval" = 0

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
      "AntiVirusOverride" = 0
      "AntiSpywareOverride" = 0
      "FirewallOverride" = 0
      "VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
      "oobe_av" = 1

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
      "EnableFirewall" = 1
      "DisableNotifications" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
      "EnableFirewall" = 1
      "DisableNotifications" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
      "EnableFirewall" = 1
      "DisableNotifications" = 1

      ========== Authorized Applications List ==========

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
      "C:\Program Files (x86)\xchat\xchat.exe" = C:\Program Files (x86)\xchat\xchat.exe:*:Enabled:XChat IRC Client -- ()
      "C:\Program Files (x86)\xchat\xchat.exe" = C:\Program Files (x86)\xchat\xchat.exe:*:Enabled:XChat IRC Client -- ()


      ========== Vista Active Open Ports Exception List ==========

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
      "{5C05867D-AE80-415B-838B-0E1587633427}" = lport=2869 | protocol=6 | dir=in | app=system |
      "{81999F4B-E631-4A65-8C47-D0D94E8EF02A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
      "{94B2B59D-005C-4994-9E6E-348EC088B917}" = lport=49159 | protocol=6 | dir=in | name=akamai netsession interface |
      "{FC69A024-0641-4219-B345-29A378BD2C37}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |

      ========== Vista Active Application Exception List ==========

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
      "{0416ABB3-98FD-4553-8AC3-2C8D19BD81C7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\space marine\smp.exe |
      "{0497B8C2-1BEB-4BC4-9CE1-2416C3D39493}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
      "{04A0630D-75FD-4A1D-9702-3DCF48863860}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\poker night at the inventory\celebritypoker.exe |
      "{14D2E376-0669-4574-A1B4-11CAA1EF949D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shatter\shattersettingseditor.exe |
      "{16C8BF52-6372-4A77-82F0-974E1B333DE0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
      "{239ED6A4-C610-4F43-A448-CF4189733E22}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the undergarden\theundergarden.exe |
      "{24F3566D-CB4D-4EA7-8227-DADF19EBFECC}" = protocol=6 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |
      "{25F85BDD-4A5C-40B9-AD6F-6D2AF597D2F0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink - trailer 2\smp.exe |
      "{267FD3B0-2906-4598-8AFB-58E50483F938}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforever.exe |
      "{26C76CA5-A974-4030-AF10-0EF2CDBA0D00}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
      "{26DA1F79-A0D3-4ED1-8543-06E2538C5E9D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon trailer\smp.exe |
      "{28B71B79-BA72-4474-A5ED-4D0FBED4A1D7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe |
      "{2911559E-92D9-41D7-A7A9-E24D7B6302EF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\poker night at the inventory\celebritypoker.exe |
      "{2CEC7C06-0D7A-4A09-AD8B-CE27964635B7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
      "{300149CB-3837-49F6-A3F9-EA6CABA73CEF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bob came in pieces\bob.exe |
      "{300B6721-C8DB-4775-85DE-7C42F0B4A31C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
      "{32A78C1D-083B-45DD-9578-B415765D18CC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magic the gathering - duels of the planeswalkers\dotp.exe |
      "{355C2A97-4FC3-421D-AED4-966C06F8582F}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
      "{38FC6B98-A9F8-474C-9C24-0CDE518EEC91}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magic the gathering - duels of the planeswalkers\dotp.exe |
      "{39B8F5F8-F258-417A-9E84-3033828460FE}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
      "{3BD15056-EA2B-478E-B4FE-C1091064AEB3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
      "{3BD48580-0B7D-4F64-893C-2DFD3C02BD60}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\half-life\hl.exe |
      "{3CDFF474-2158-460D-9BE3-0A5D13B79D73}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shatter\shattersettingseditor.exe |
      "{3E35C7FD-0D7B-4E57-8D27-72F76A9AC3DD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\homefront - dev diary 2\smp.exe |
      "{3E592063-6387-4B6E-8306-D5ACC39673FE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chime\chime.exe |
      "{3FEC378F-934E-42B2-B41A-0114416F110D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rhythm zone demo\rhythmzone_demo.exe |
      "{4096E518-2AD0-40AD-A2CC-43CCA400C08B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\dystopia\hl2.exe |
      "{43249FE9-E98C-4AC2-B5B8-9CA1F8307A8B}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
      "{43CB8EDB-66D0-413F-86D9-ED8A09C61380}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
      "{499D9018-8697-4194-B437-A545C1E7F378}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\opposing force\hl.exe |
      "{4B358AB9-0F92-4AF2-866F-9A3F2A58EB96}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bob came in pieces\bob.exe |
      "{51291C35-28D6-494D-BF7D-2951E046D5E9}" = protocol=17 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |
      "{5273E6CD-FC31-464F-9942-900DF3D90432}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
      "{52DD2E37-5ED6-4637-B0FA-3DDBE5DC5713}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon trailer\smp.exe |
      "{5737FF33-A1E7-4797-8E31-6A7675C93514}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
      "{5CF317EC-40FC-49EB-990D-11A78C7D2720}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aaaaaaaaaaaaaaaaaaaaaaaaa!!!\main.exe |
      "{5DB5475E-D335-41D9-8BF9-1E07F4EC1B8E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink - trailer 2\smp.exe |
      "{5F5E1AD1-BE2C-479E-94D7-CCD9353F7919}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\dystopia\hl2.exe |
      "{61DB4801-248D-4E49-91ED-0FB2E0693AC2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
      "{66F82E8F-4572-4EB8-8B0F-F84F4328BAA9}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
      "{6E40B9B6-46B0-4A4B-8195-49DD45DBB3A8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |
      "{76A72B70-1A38-4B51-9232-3DAB776D320C}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
      "{77630917-ECD1-45CC-AF0E-E8BE23B9853C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\baboinvasion\baboinvasion.exe |
      "{78C9FC06-995A-45EC-A967-98956CEF0FC6}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
      "{8C69D763-A548-4AC8-9DC4-9F596AE875B9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\team fortress classic\hl.exe |
      "{8D62E36B-8484-442D-9503-6268D9026FA6}" = protocol=6 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
      "{8DE68202-825B-4B7A-9BEC-0F7D444AA772}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
      "{8E2A60C1-60FF-4C1F-9360-C2C464FEEBB3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\beathazard.exe |
      "{926D5C75-FC9D-498D-B2EC-0408B378D874}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
      "{931FBF39-5A91-4C5B-96B1-72265A05DF87}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
      "{958A8D13-7BC6-452A-8E59-9F50BE570E46}" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
      "{98436EBB-D1BC-43B8-9F02-FC313DBCE9BC}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
      "{9E4A9367-CE34-4A30-88D5-44C98AFE7688}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
      "{A19A52AC-9064-4591-9A46-A61C389397A2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
      "{A3E8E719-DA55-4566-BCFB-B8321A98BE37}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforeverlauncher.exe |
      "{A65EEDB5-F3A3-4314-9764-2071E3990F47}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |
      "{ABBE524F-7734-41CA-B4DA-3A41CFBF9E1D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
      "{AC842892-489E-4250-8EBF-5AC66FE5129A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\homefront - dev diary 2\smp.exe |
      "{B5E08404-3D01-4916-B135-D0AA5DF7798A}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
      "{B90FEBB9-1B77-4D8B-82F3-FB764056A4E9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chime\chime.exe |
      "{C213BB9C-CE96-4ACF-9AC5-47FEA6A32BB9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\opposing force\hl.exe |
      "{C7687563-8A86-444F-8879-08927B804850}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2 co-op trailer\smp.exe |
      "{C7D6E09D-603D-457B-9695-A8882E0D40EB}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
      "{C8CBFE82-EAAB-4E37-A63F-1BADC5C892E5}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
      "{CC25590E-4CDA-40EA-86DC-C86D13645AC4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex human revolution gameplay trailer\smp.exe |
      "{CD3AAC29-BBB2-42E4-A83B-3D50FCEAD667}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the undergarden\theundergarden.exe |
      "{CED8F4FA-6F92-4C05-B8DA-9B0DEED2105E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\aaaaaaaaaaaaaaaaaaaaaaaaa!!!\main.exe |
      "{CFAC9CDE-46F1-4F46-815B-ABEABA775D89}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
      "{D12C157E-867D-45CA-AF68-ACCFD4ACF635}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2 co-op trailer\smp.exe |
      "{D20D14FD-76C9-4252-8657-72D146988ACB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex human revolution gameplay trailer\smp.exe |
      "{D687E107-CA25-4BA6-8633-250D6E4057E6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\team fortress classic\hl.exe |
      "{D74B2760-4C19-4A6B-B849-5B4293278F01}" = protocol=17 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
      "{D86638C8-8D73-466D-9A77-EEE2C269ABBD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trackmania nations forever\tmforever.exe |
      "{DF8447FD-8647-4E16-B256-C676978C3A4D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\space marine\smp.exe |
      "{E084DB2E-4260-4058-9FA2-AC2468DF5288}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
      "{EA407E1B-0F22-46E6-8D6F-751B67885AE2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\beathazard.exe |
      "{ED1EDFC1-5589-4C39-BC16-497DA4BB7CC0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe |
      "{ED713FCA-C4BD-44D4-B91E-8978A9032A9C}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
      "{F175BBFD-525B-4CD3-886A-7C3DEE580F90}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
      "{F3965923-7B3C-49E1-9765-7E2394AE7CF3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\baboinvasion\baboinvasion.exe |
      "{F98FA0B6-8BD6-48C9-B83B-AA8A3E7CD2C4}" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
      "{FC7C2600-35E5-4D5F-A1DE-0C2BF40C0774}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\half-life\hl.exe |
      "{FCAEE5F4-B76C-4480-A7E5-D461D6DAA834}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rhythm zone demo\rhythmzone_demo.exe |
      "TCP Query User{2FF9510C-00F7-4346-AA51-C55E99B7ECFD}C:\program files (x86)\steam\steamapps\gdamatov77\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\team fortress 2\hl2.exe |
      "TCP Query User{E684A9AC-00C8-42E0-8B2D-89BB24DA53B5}C:\program files (x86)\steam\steamapps\gdamatov77\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\team fortress 2\hl2.exe |
      "UDP Query User{476A1768-73F2-4CA7-A8B9-049089789B7F}C:\program files (x86)\steam\steamapps\gdamatov77\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\team fortress 2\hl2.exe |
      "UDP Query User{8D6D9313-E7D6-4EED-A305-BCF36C9A4BB3}C:\program files (x86)\steam\steamapps\gdamatov77\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\gdamatov77\team fortress 2\hl2.exe |

      ========== HKEY_LOCAL_MACHINE Uninstall List ==========

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "{0C682623-8F66-46A8-B9B3-93FE1E66A001}" = iTunes
      "{1686C4D1-B1FD-42E8-B7A8-FB4C4DBA5BA8}" = ASUS Power4Gear Hybrid
      "{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
      "{20140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010 (Beta)
      "{20387B45-18A4-4D48-ABD9-A23D2CBE42B3}" = Dolby Control Center
      "{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour
      "{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
      "{48B0F24F-B828-4B1A-A22E-C65454B32A7A}" = Windows Live Family Safety
      "{56F26668-13DA-497A-883F-61434A10CBAB}" = MobileMe Control Panel
      "{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
      "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
      "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
      "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
      "{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
      "{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
      "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
      "{963BFE7E-C350-4346-B43C-B02358306A45}" = Apple Mobile Device Support
      "{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
      "{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
      "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
      "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
      "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
      "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
      "NVIDIA Drivers" = NVIDIA Drivers
      "USB 2.0 UVC 1.3M WebCam" = USB 2.0 UVC 1.3M WebCam

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
      "{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
      "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
      "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
      "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
      "{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
      "{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
      "{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
      "{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
      "{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
      "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
      "{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
      "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
      "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
      "{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
      "{1C8521E5-5A7B-4A4E-A9CD-AD53116EAEE0}" = ASUS Data Security Manager
      "{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
      "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
      "{20140062-0062-0409-0000-0000000FF1CE}" = Microsoft Office Home and Business 2010 (Beta) - English
      "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
      "{2208D65A-1BF9-485E-A308-1BA6CADCDC1D}" = Windows Live Movie Maker Beta
      "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
      "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
      "{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 18
      "{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
      "{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2
      "{40580068-9B10-40B5-9548-536CE88AB23C}" = ITECIR
      "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
      "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
      "{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
      "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
      "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
      "{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.55.03
      "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
      "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
      "{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
      "{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
      "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
      "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
      "{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
      "{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
      "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
      "{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
      "{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey
      "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112596253}" = Galapago
      "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118892567}" = Monopoly City
      "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
      "{83F73CB1-7705-49D1-9852-84D839CA2A45}" = Wireless Console 2
      "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
      "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
      "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
      "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
      "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
      "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
      "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
      "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
      "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
      "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
      "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
      "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
      "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
      "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
      "{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
      "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
      "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
      "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
      "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
      "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
      "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
      "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
      "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
      "{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
      "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
      "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
      "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
      "{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
      "{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
      "{AE0259D4-7A01-4E47-BBAF-2604D03DF07C}" = LoJack Factory Installer
      "{BEB3AD23-250E-4BD2-BBC9-27D4BB42DE07}" = COMODO System - Cleaner
      "{C0E5147E-C9F3-4360-9ED0-2E875F11766C}" = Respondus LockDown Browser
      "{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
      "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
      "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
      "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
      "{D1E5870E-E3E5-4475-98A6-ADD614524ADF}" = ATK Media
      "{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service
      "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
      "{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
      "{DC905847-D537-427F-BF91-47CC7ACCDE58}" = ASUS FancyStart
      "{DE10AB76-4756-4913-BE25-55D1C1051F9A}" = WinFlash
      "{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
      "{DEA314C4-0929-4250-BC92-98E4C105F28D}" = NVIDIA PhysX
      "{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
      "{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
      "{E8CC51B4-F039-4A13-8C23-57661C5A90AC}" = Express Gate
      "{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
      "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
      "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
      "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
      "{F204E2B3-225D-419D-A5DE-3F97E8ADDD1B}" = Geek Squad 24 Hour Computer Support
      "{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
      "{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
      "{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
      "{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
      "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
      "1Club.FM Toolbar" = 1Club.FM Toolbar
      "Adobe AIR" = Adobe AIR
      "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
      "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
      "Akamai" = Akamai NetSession Interface
      "APB North America" = APB North America
      "Asus_Camera_ScreenSaver" = Asus_Camera_ScreenSaver
      "AVCPhotoStudio_Wrapper" = myPhotoMovie (remove only)
      "chc.4875E02D9FB21EE389F73B8D1702B320485 DF8CE.1" = Adobe Community Help
      "com.adobe.amp.4875E02D9FB21EE389F73B8D1 702B320485DF8CE.1" = Adobe Media Player
      "conduitEngine" = Conduit Engine
      "Diablo II" = Diablo II
      "DivX Setup.divx.com" = DivX Setup
      "EADM" = EA Download Manager
      "Fraps" = Fraps
      "Google Desktop" = Google Desktop
      "HLSW_is1" = HLSW v1.3.3.7b
      "HOMESTUDENTR" = Microsoft Office Home and Student 2007
      "IL Download Manager" = IL Download Manager
      "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
      "InstallShield_{AE0259D4-7A01-4E47-BBAF-2604D03DF07C}" = LoJack Factory Installer
      "jZip" = jZip
      "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
      "mIRC" = mIRC
      "Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
      "NetSight" = Nielsen
      "Office14.Click2Run" = Microsoft Office Click-to-Run 2010 (Beta)
      "OpenAL" = OpenAL
      "Picasa2" = Picasa 2
      "PoiZone" = PoiZone
      "PunkBusterSvc" = PunkBuster Services
      "RealPlayer 12.0" = RealPlayer
      "Sakura" = Sakura
      "Sawer" = Sawer
      "Smart-Shopper" = SmartShopper
      "SoftwareUpdUtility" = Download Updater (AOL LLC)
      "Steam App 11020" = TrackMania Nations Forever
      "Steam App 130" = Half-Life: Blue Shift
      "Steam App 15520" = AaAaAA!!! - A Reckless Disregard for Gravity
      "Steam App 17580" = Dystopia
      "Steam App 18700" = And Yet It Moves
      "Steam App 20" = Team Fortress Classic
      "Steam App 20820" = Shatter
      "Steam App 211" = Source SDK
      "Steam App 220" = Half-Life 2
      "Steam App 22600" = Worms Reloaded
      "Steam App 23120" = Droplitz
      "Steam App 25700" = Madballs in...Babo: Invasion
      "Steam App 310" = Team Fortress 2 Dedicated Server
      "Steam App 31280" = Poker Night at the Inventory
      "Steam App 31410" = Zombie Driver
      "Steam App 320" = Half-Life 2: Deathmatch
      "Steam App 340" = Half-Life 2: Lost Coast
      "Steam App 380" = Half-Life 2: Episode One
      "Steam App 38910" = Rhythm Zone - Demo
      "Steam App 410" = Portal: The First Slice
      "Steam App 420" = Half-Life 2: Episode Two
      "Steam App 42710" = Call of Duty: Black Ops - Multiplayer
      "Steam App 440" = Team Fortress 2
      "Steam App 46000" = Bob Came in Pieces
      "Steam App 49400" = Magic: The Gathering - Duels of the Planeswalkers
      "Steam App 49600" = Beat Hazard
      "Steam App 50" = Half-Life: Opposing Force
      "Steam App 500" = Left 4 Dead
      "Steam App 520" = Team Fortress 2 Beta
      "Steam App 550" = Left 4 Dead 2
      "Steam App 57200" = Puzzle Dimension
      "Steam App 62100" = Chime
      "Steam App 630" = Alien Swarm
      "Steam App 65400" = Archon:Classic
      "Steam App 70" = Half-Life
      "Steam App 70300" = VVVVVV
      "Steam App 9985" = The Undergarden Demo
      "The Weather Channel Desktop 6" = The Weather Channel Desktop 6
      "Toxic Biohazard" = Toxic Biohazard
      "TuneUpMedia" = TuneUp Companion 1.9.0
      "Veoh Web Player Beta" = Veoh Web Player
      "VTFEdit_is1" = VTFEdit 1.2.5
      "Vuze_Remote Toolbar" = Vuze Remote Toolbar
      "WinGimp-2.0_is1" = GIMP 2.6.8
      "WinLiveSuite_Wave3" = Windows Live Essentials
      "Worms2 Demo" = Worms2 Demo
      "xchat" = XChat 2 (remove only)

      ========== HKEY_CURRENT_USER Uninstall List ==========

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "Google Chrome" = Google Chrome
      "Move Media Player" = Move Media Player
      "UnityWebPlayer" = Unity Web Player

      ========== Last 10 Event Log Errors ==========

      [ Application Events ]
      Error - 12/16/2010 9:53:53 PM | Computer Name = Administrator | Source = Bonjour Service | ID = 100
      Description = Task Scheduling Error: m->NextScheduledSPRetry 42963

      Error - 12/17/2010 2:50:44 AM | Computer Name = Administrator | Source = System Restore | ID = 8193
      Description =

      Error - 12/17/2010 3:15:26 AM | Computer Name = Administrator | Source = Application Error | ID = 1000
      Description = Faulting application ZombieDriver.exe, version 0.0.0.0, time stamp
      0x4cff745a, faulting module steam.dll_unloaded, version 0.0.0.0, time stamp 0x4d015133,
      exception code 0xc0000005, fault offset 0x301ea112, process id 0x1480, application
      start time 0x01cb9db8a80d5360.

      Error - 12/17/2010 3:15:30 AM | Computer Name = Administrator | Source = Application Error | ID = 1000
      Description = Faulting application ZombieDriver.exe, version 0.0.0.0, time stamp
      0x4cff745a, faulting module steam.dll_unloaded, version 0.0.0.0, time stamp 0x4d015133,
      exception code 0xc0000005, fault offset 0x3015c394, process id 0x1480, application
      start time 0x01cb9db8a80d5360.

      Error - 12/18/2010 12:17:05 AM | Computer Name = Administrator | Source = CVHSVC | ID = 100
      Description = Information only. (Patch task for {20140062-0062-0409-0000-0000000FF1CE}):
      DownloadLatest Failed: HTTP status 404: The requested URL does not exist on the
      server.

      Error - 12/18/2010 9:37:09 PM | Computer Name = Administrator | Source = Application Error | ID = 1000
      Description = Faulting application hl2.exe, version 0.0.0.0, time stamp 0x4d094ebe,
      faulting module engine.dll, version 0.0.0.0, time stamp 0x4d0aee00, exception code
      0xc0000005, fault offset 0x0006abda, process id 0x12e0, application start time 0x01cb9f0c7154adf0.

      Error - 12/19/2010 8:26:36 AM | Computer Name = Administrator | Source = CVHSVC | ID = 100
      Description = Information only. (Patch task for {20140062-0062-0409-0000-0000000FF1CE}):
      DownloadLatest Failed: HTTP status 404: The requested URL does not exist on the
      server.

      Error - 12/19/2010 1:15:12 PM | Computer Name = Administrator | Source = Application Error | ID = 1000
      Description = Faulting application hl2.exe, version 0.0.0.0, time stamp 0x4d094ebe,
      faulting module filesystem_steam.dll_unloaded, version 0.0.0.0, time stamp 0x4d0a5da7,
      exception code 0xc0000005, fault offset 0x02f0d499, process id 0x500, application
      start time 0x01cb9f9230568810.

      Error - 12/20/2010 2:23:05 AM | Computer Name = Administrator | Source = Application Error | ID = 1000
      Description = Faulting application chrome.exe, version 0.0.0.0, time stamp 0x4cffee6d,
      faulting module kernel32.dll, version 6.0.6001.18215, time stamp 0x4995344f, exception
      code 0xc0000005, fault offset 0x00010e38, process id 0xd14, application start time
      0x01cb9d4f54730db8.

      Error - 12/21/2010 12:45:42 AM | Computer Name = Administrator | Source = CVHSVC | ID = 100
      Description = Information only. (Patch task for {20140062-0062-0409-0000-0000000FF1CE}):
      DownloadLatest Failed: HTTP status 404: The requested URL does not exist on the
      server.

      [ System Events ]
      Error - 12/30/2010 3:18:27 PM | Computer Name = Administrator | Source = Service Control Manager | ID = 7034
      Description =

      Error - 12/31/2010 1:58:40 PM | Computer Name = Administrator | Source = Service Control Manager | ID = 7034
      Description =

      Error - 1/2/2011 1:42:53 AM | Computer Name = Administrator | Source = HTTP | ID = 15016
      Description =

      Error - 1/2/2011 1:43:19 AM | Computer Name = Administrator | Source = Service Control Manager | ID = 7026
      Description =

      Error - 1/2/2011 2:45:55 AM | Computer Name = Administrator | Source = DCOM | ID = 10005
      Description =

      Error - 1/2/2011 2:46:03 AM | Computer Name = Administrator | Source = DCOM | ID = 10005
      Description =

      Error - 1/2/2011 2:46:22 AM | Computer Name = Administrator | Source = DCOM | ID = 10005
      Description =

      Error - 1/2/2011 2:47:00 AM | Computer Name = Administrator | Source = Service Control Manager | ID = 7001
      Description =

      Error - 1/2/2011 2:47:00 AM | Computer Name = Administrator | Source = Service Control Manager | ID = 7001
      Description =

      Error - 1/2/2011 2:47:00 AM | Computer Name = Administrator | Source = Service Control Manager | ID = 7026
      Description =


      < End of report >
      I also ran Malwarebytes in Safe mode, here is the notepad log after removing the infected items.


      Malwarebytes' Anti-Malware 1.50.1.1100
      www.malwarebytes.org

      Database version: 5441

      Windows 6.0.6001 Service Pack 1 (Safe Mode)
      Internet Explorer 8.0.6001.18999

      1/2/2011 2:28:10 AM
      mbam-log-2011-01-02 (02-28-10).txt

      Scan type: Quick scan
      Objects scanned: 154785
      Time elapsed: 1 minute(s), 31 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 37
      Registry Values Infected: 1
      Registry Data Items Infected: 1
      Folders Infected: 7
      Files Infected: 18

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_CLASSES_ROOT\CLSID\{4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\TypeLib\{305C6CB1-9D31-4489-881D-5A8E2DC3FE14} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{E79B1445-DFEA-4BEF-A786-E0C0F33C863B} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.Smrt-ShprCtrl.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.Smrt-ShprCtrl (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{4CF088BD-BE95-40A5-BE9B-677F8683EDEA} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.IEButtonA.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.IEButtonA (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{6FAC4823-815E-4361-836E-46D65ED2550B} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.IEButton.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.IEButton (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{8BCB5337-EC01-4E38-840C-A964F174255B} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.HbInfoBand.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.HbInfoBand (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{8BCB5337-EC01-4E38-840C-A964F174255B} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8BCB5337-EC01-4E38-840C-A964F174255B} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{911F251E-34FD-465E-B6CE-DF00FF49A6BE} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.HbAx.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.HbAx (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{FE4F1649-8909-49C0-87BA-24D65120DB46} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.IEButtonB.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Smart-Shopper.IEButtonB (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{022C671F-6CBA-4A03-A8F9-3B3A361B235A} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{8AD815FC-607B-419F-8B70-D345A507A54E} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{90F62EF7-58D1-4E8E-BB3E-CFB10BA9E47B} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CC3D8FE-F0E0-4DD1-A69A-8C56BCC7BEBF} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3CC3D8FE-F0E0-4DD1-A69A-8C56BCC7BEBF} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CC3D8FE-F0E0-4DD1-A69A-8C56BCC7BEC0} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3CC3D8FE-F0E0-4DD1-A69A-8C56BCC7BEC0} (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Smart-Shopper (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\AVSolution (Trojan.Agent) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\AVSuitE (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Smart-Shopper (Adware.SmartShopper) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart-Shopper (Adware.SmartShopper) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cvfvixmq (Trojan.Dropper) -> Value: cvfvixmq -> Quarantined and deleted successfully.

      Registry Data Items Infected:
      HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

      Folders Infected:
      c:\program files (x86)\smart-shopper (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\program files (x86)\smart-shopper\Bin (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\program files (x86)\smart-shopper\Bin\2.5.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\program files (x86)\smart-shopper\cs (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\program files (x86)\smart-shopper\cs\antiphishing (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\programdata\microsoft\Windows\start menu\Programs\smartshopper (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\Users\Gabi\AppData\Roaming\whitesmoke (PUP.WhiteSmoke) -> Not selected for removal.

      Files Infected:
      c:\Users\Gabi\AppData\Local\Temp\drqjnfnkx\niftdpklajb.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
      c:\program files (x86)\smart-shopper\Bin\2.5.1\smrt-shpr.dll (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\Users\Gabi\AppData\Local\Temp\0.7518449972590141.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
      c:\Users\Gabi\downloads\registryfix.exe (Rogue.Installer) -> Quarantined and deleted successfully.
      c:\Users\Gabi\downloads\whitesmokenoregstub_d6045_en.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
      c:\Users\Gabi\downloads\xvidsetup.exe (Adware.HotBar) -> Quarantined and deleted successfully.
      c:\Users\Gabi\AppData\Roaming\microsoft\stor.cfg (Malware.Trace) -> Quarantined and deleted successfully.
      c:\program files (x86)\smart-shopper\Uninst.exe (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\program files (x86)\smart-shopper\cs\antiphishing\antiphishing.html (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\program files (x86)\smart-shopper\cs\antiphishing\phishalert.gif (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\program files (x86)\smart-shopper\cs\antiphishing\x.gif (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\program files (x86)\smart-shopper\cs\antiphishing\xActive.gif (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\programdata\microsoft\Windows\start menu\Programs\smartshopper\smartshopper - comapre product prices.lnk (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\programdata\microsoft\Windows\start menu\Programs\smartshopper\smartshopper - compare travel rate.lnk (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\programdata\microsoft\Windows\start menu\Programs\smartshopper\smartshopper help.lnk (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\programdata\microsoft\Windows\start menu\Programs\smartshopper\uninstall smartshopper.lnk (Adware.SmartShopper) -> Quarantined and deleted successfully.
      c:\Users\Gabi\AppData\Roaming\whitesmoke\stat.log (PUP.WhiteSmoke) -> Not selected for removal.
      c:\Users\Gabi\downloads\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
      FIXED. Thank you everyone for your help. I had to be in safe mode in order for it all to work. Malwarebytes did everything perfectly.

      347.

      Solve : Icons and taskbar is missing (winXP)?

      Answer»

      ComboFix 10-12-30.01 - xxx 12/31/2010 9:12.1.2 - x86
      Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2039.1447 [GMT -8:00]
      Running from: c:\documents and settings\xxx\desktop\commy.exe
      Command switches used :: /stepdel
      AV: AVG Internet Security 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
      FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\CFLog
      c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
      c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
      c:\documents and settings\All Users\Application Data\Toolbar4
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong
      c:\documents and settings\xxx\Application Data\Microsoft\Windows Firewall
      c:\documents and settings\xxx\Application Data\PriceGong
      c:\program files\Level Up Games\Crazy Kart\data\config\AnimLayer\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\config\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\2dAnim\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\2dAnim\gamblinghelp\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\2dAnim\login\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\2dAnim\spark\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\2dAnim\treasure\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\anm\557_500_2\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\anm\abkeypad\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\anm\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\anm\ezpodbanner1\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\anm\helper\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\IMAGE\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\IMAGE\FRIENDLIST\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\IMAGE\LISTCTRL\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\IMAGE\LoadingTips\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\IMAGE\ONLINEPLAYERS\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\mov\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\GUI\update\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\Model\animation\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\Model\car\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\Model\car\MODEL\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\Model\Character\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\Model\Character\model\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\Model\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\Model\ItemEffect\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\Model\ItemEffect\Speaker\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\Model\ItemEffect\textures\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\Model\textures\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\sound\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\1_0\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\1_1\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\1_2\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\1_3\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\1_4\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\1_5\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\2_0\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\2_1\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\2_2\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\2_3\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\2_4\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\2_5\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\3_0\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\3_1\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\3_2\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\3_3\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\3_4\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\4_0\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\4_1\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\4_2\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\5_1\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\6_0\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\6_1\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\6_3\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\6_4\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\6_5\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\6_6\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\6_7\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\6_8\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\6_9\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\7_0\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\advertisement\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\Common\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\Common\textures\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\Textures\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\Textures\Style1\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\Textures\Style2\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\Textures\Style3\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\Textures\Style4\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\Textures\Style5\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\data\StageExt\Textures\Style6\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\SD_Log\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\sound\Desktop_.ini
      c:\program files\Level Up Games\Crazy Kart\sys\Desktop_.ini
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\1.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\a.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\b.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\c.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\d.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\e.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\f.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\g.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\h.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\i.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\J.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\k.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\l.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\m.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\mru.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\n.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\o.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\p.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\q.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\r.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\s.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\t.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\u.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\v.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\w.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\x.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\y.xml
      c:\documents and settings\Test Account.XP-54E10D31A13C\Application Data\PriceGong\Data\z.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\1.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\a.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\b.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\c.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\d.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\e.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\f.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\g.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\h.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\i.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\J.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\k.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\l.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\m.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\mru.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\n.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\o.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\p.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\q.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\r.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\s.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\t.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\u.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\v.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\w.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\x.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\y.xml
      c:\documents and settings\xxx\Application Data\PriceGong\Data\z.xml
      C:\HCTE6.tmp
      C:\HCTE7.tmp
      C:\HCTE8.tmp
      C:\HCTE9.tmp
      C:\HCTEA.tmp
      C:\HCTEB.tmp
      C:\HCTEC.tmp
      C:\HCTED.tmp
      C:\Install.exe
      c:\windows\system32\arp.exe
      c:\windows\system32\SCardSvr.exe
      c:\windows\system32\winlogon.bak
      c:\windows\Tasks\At1.job
      c:\windows\Tasks\At10.job
      c:\windows\Tasks\At11.job
      c:\windows\Tasks\At12.job
      c:\windows\Tasks\At13.job
      c:\windows\Tasks\At14.job
      c:\windows\Tasks\At15.job
      c:\windows\Tasks\At16.job
      c:\windows\Tasks\At17.job
      c:\windows\Tasks\At18.job
      c:\windows\Tasks\At19.job
      c:\windows\Tasks\At2.job
      c:\windows\Tasks\At20.job
      c:\windows\Tasks\At21.job
      c:\windows\Tasks\At22.job
      c:\windows\Tasks\At23.job
      c:\windows\Tasks\At24.job
      c:\windows\Tasks\At3.job
      c:\windows\Tasks\At4.job
      c:\windows\Tasks\At5.job
      c:\windows\Tasks\At6.job
      c:\windows\Tasks\At7.job
      c:\windows\Tasks\At8.job
      c:\windows\Tasks\At9.job

      ----- BITS: Possible INFECTED sites -----

      hxxp://globebroadbandclickfix.com.ph
      Infected copy of c:\windows\system32\Drivers\atapi.sys was found and disinfected
      Restored copy from - c:\windows\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

      Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
      Restored copy from - c:\qoobox\Quarantine\C\WINDOWS\system32\winlogon.bak.vir

      .
      ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      -------\Legacy_ILVMONEYDRIVER53
      -------\Service_IlvMoneyDRIVER53


      ((((((((((((((((((((((((( Files Created from 2010-11-28 to 2010-12-31 )))))))))))))))))))))))))))))))
      .

      2010-12-30 06:03 . 2010-12-30 06:03--------d-----w-c:\documents and settings\xxx\Local Settings\Application Data\Conduit
      2010-12-30 05:38 . 2010-12-30 05:38--------d-----w-C:\Level Up Games
      2010-12-28 23:12 . 2010-12-28 23:12--------d-----w-c:\documents and settings\xxx\Maps
      2010-12-27 18:31 . 2010-12-27 18:31388096----a-r-c:\documents and settings\xxx\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
      2010-12-27 18:31 . 2010-12-27 18:31--------d-----w-c:\program files\Trend Micro
      2010-12-27 05:13 . 2010-12-27 05:13--------d-----w-c:\documents and settings\xxx\Application Data\SUPERAntiSpyware.com
      2010-12-27 05:13 . 2010-12-27 05:13--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
      2010-12-27 05:12 . 2010-12-27 05:13--------d-----w-c:\program files\SUPERAntiSpyware
      2010-12-26 18:55 . 2010-12-26 18:55--------d-----w-c:\program files\CCleaner
      2010-12-24 07:52 . 2010-12-24 07:53--------d-----w-c:\documents and settings\xxx\.64pixels
      2010-12-23 21:39 . 2010-12-30 06:04--------d-----w-c:\documents and settings\All Users\Application Data\Yahoo! Companion
      2010-12-23 21:39 . 2010-12-23 21:39--------d-----w-c:\program files\Common Files\DirectX
      2010-12-23 21:38 . 2010-12-23 21:38--------d-----w-c:\program files\SmileyCentral_1vEI
      2010-12-18 02:43 . 2010-12-18 02:43--------d-----w-c:\program files\SmileyCentralIE_1w
      2010-12-18 02:33 . 2010-12-18 02:330----a-w-c:\windows\system32\ConduitEngine.tmp
      2010-12-18 02:18 . 2010-12-23 21:38--------d-----w-c:\documents and settings\Test Account
      2010-12-17 23:22 . 2010-12-23 21:38--------d-----w-c:\program files\VirtualDJ
      2010-12-16 21:13 . 2010-12-18 02:15--------d-----w-c:\documents and settings\Administrator
      2010-12-09 15:07 . 2010-12-09 15:07--------d-----w-c:\windows\system32\wbem\Repository
      2010-12-09 04:50 . 2010-12-09 04:50--------d-sh--w-c:\documents and settings\NetworkService\IETldCache
      2010-12-09 01:58 . 2010-12-09 01:58--------d-----w-c:\program files\X-Play
      2010-12-08 21:02 . 2010-12-09 15:06--------d-----w-c:\program files\uTorrent Turbo Booster

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-11-13 02:53 . 2010-04-18 00:07472808----a-w-c:\windows\system32\deployJava1.dll
      2010-11-13 00:34 . 2010-04-18 00:0773728----a-w-c:\windows\system32\javacpl.cpl
      .

      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
      "{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSof0.dll" [2010-10-18 3908192]

      [HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
      2010-10-18 10:263908192----a-w-c:\program files\Softonic-Eng7\tbSof0.dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      "{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSof0.dll" [2010-10-18 3908192]

      [HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
      "{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}"= "c:\program files\Softonic-Eng7\tbSof0.dll" [2010-10-18 3908192]

      [HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\NBHShellExt]
      @="{8D2223A2-B3C6-4e32-B096-CDD11F628C60}"
      [HKEY_CLASSES_ROOT\CLSID\{8D2223A2-B3C6-4e32-B096-CDD11F628C60}]
      2008-07-10 16:2397064----a-w-c:\program files\Nero\Nero8\InCD\NBHShx.dll

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2010-11-05 6174008]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
      "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
      "SecurDisc"="c:\program files\Nero\Nero8\InCD\NBHGui.exe" [2008-07-10 2049320]
      "RTHDCPL"="RTHDCPL.EXE" [2007-11-22 16858112]
      "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-19 421888]
      "Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
      "NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-07-09 570664]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
      "InCD"="c:\program files\Nero\Nero8\InCD\InCD.exe" [2008-07-10 1083176]
      "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
      "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
      "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
      "globe"="c:\program files\Globe Telecom\Click Fix\bin\sprtcmd.exe" [2009-06-11 204440]
      "AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
      "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]

      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
      2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
      "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
      "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
      "c:\\Program Files\\Level Up Games\\Grand Chase\\main.exe"=
      "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
      "c:\\Program Files\\Level Up Games\\FreeStyle\\FreeStyle.exe"=
      "c:\\Program Files\\Level Up Games\\Rohan Online CBT\\Client\\rohanclient.exe"=
      "c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
      "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
      "c:\\Program Files\\Opera\\opera.exe"=
      "c:\\FarmHelper\\FVBot.exe"=
      "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
      "c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
      "c:\\Documents and Settings\\xxx\\My Documents\\Downloads\\Gang Garrison 2\\Gang Garrison 2.exe"=
      "c:\\Program Files\\FlashGet Network\\FlashGet 3\\FlashGet3.exe"=
      "c:\\WINDOWS\\system32\\PnkBstrA.exe"=
      "c:\\WINDOWS\\system32\\PnkBstrB.exe"=
      "c:\\Program Files\\softnyx\\GunboundWC\\GunBound.gme"=
      "c:\\Documents and Settings\\xxx\\My Documents\\Downloads\\VinServer34\\VinServer34.exe"=
      "c:\\Documents and Settings\\xxx\\My Documents\\Downloaded by flashget\\GGC Beta 2\\GGC.exe"=
      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
      "c:\\Program Files\\iTunes\\iTunes.exe"=
      "c:\\Documents and Settings\\xxx\\My Documents\\Downloads\\MM8BDM-SGC8\\rcon_utility.exe"=
      "c:\\Documents and Settings\\xxx\\My Documents\\Downloads\\MM8BDM-SGC8\\skulltag.exe"=
      "c:\\Program Files\\GameClub\\Philippines\\SpecialForce\\specialforce.exe"=
      "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
      "c:\\Program Files\\uTorrent\\uTorrent.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "58426:TCP"= 58426:TCP:Pando Media Booster
      "58426:UDP"= 58426:UDP:Pando Media Booster
      "57230:TCP"= 57230:TCP:Pando Media Booster
      "57230:UDP"= 57230:UDP:Pando Media Booster
      "56684:TCP"= 56684:TCP:Pando Media Booster
      "56684:UDP"= 56684:UDP:Pando Media Booster
      "1035:TCP"= 1035:TCP:Akamai NetSession Interface
      "5000:UDP"= 5000:UDP:Akamai NetSession Interface

      R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
      R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
      R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [2/28/2006 4:00 AM 14336]
      R2 NeroRegInCDSrv;Nero Registry InCD Service;c:\program files\Nero\Nero8\InCD\NBHRegInCDSrv.exe [7/10/2008 8:23 AM 53032]
      R2 sprtsvc_globe;SupportSoft Sprocket Service (globe);c:\program files\Globe Telecom\Click Fix\bin\sprtsvc.exe [7/17/2009 1:13 PM 206120]
      R2 tgsrvc_globe;SupportSoft Repair Service (globe);c:\program files\Globe Telecom\Click Fix\bin\tgsrvc.exe [8/6/2009 3:16 PM 151192]
      S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/18/2010 11:02 AM 136176]
      S3 7ByteIo;7ByteIo;\??\c:\program files\Hot CPU Tester Pro 4 LE\SysInfo.sys --> c:\program files\Hot CPU Tester Pro 4 LE\SysInfo.sys [?]
      S3 dump_wmimmc;dump_wmimmc;\??\c:\program files\level up games\grand chase\GameGuard\dump_wmimmc.sys --> c:\program files\level up games\grand chase\GameGuard\dump_wmimmc.sys [?]
      S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\xxx\LOCALS~1\Temp\LNK2C.tmp --> c:\docume~1\xxx\LOCALS~1\Temp\LNK2C.tmp [?]
      S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
      S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 12:37 PM 517096]
      S3 XDva285;XDva285;\??\c:\windows\system32\XDva285.sys --> c:\windows\system32\XDva285.sys [?]
      S3 XDva312;XDva312;\??\c:\windows\system32\XDva312.sys --> c:\windows\system32\XDva312.sys [?]
      S3 XDva361;XDva361;\??\c:\windows\system32\XDva361.sys --> c:\windows\system32\XDva361.sys [?]
      S3 XDva367;XDva367;\??\c:\windows\system32\XDva367.sys --> c:\windows\system32\XDva367.sys [?]
      S3 XDva368;XDva368;\??\c:\windows\system32\XDva368.sys --> c:\windows\system32\XDva368.sys [?]
      S3 XDva370;XDva370;\??\c:\windows\system32\XDva370.sys --> c:\windows\system32\XDva370.sys [?]
      S3 XDva372;XDva372;\??\c:\windows\system32\XDva372.sys --> c:\windows\system32\XDva372.sys [?]
      S3 XDva377;XDva377;\??\c:\windows\system32\XDva377.sys --> c:\windows\system32\XDva377.sys [?]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      AkamaiREG_MULTI_SZ Akamai
      .
      Contents of the 'Scheduled Tasks' folder

      2010-12-13 c:\windows\Tasks\AdobeAAMUpdater-1.0-XP-54E10D31A13C-xxx.job
      - c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-10-16 10:44]

      2010-12-29 c:\windows\Tasks\AppleSoftwareUpdate.job
      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

      2010-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
      - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-18 19:01]

      2010-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
      - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-18 19:01]

      2010-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1592454029-839522115-1003Core.job
      - c:\documents and settings\xxx\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 22:12]

      2010-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1592454029-839522115-1003UA.job
      - c:\documents and settings\xxx\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 22:12]

      2010-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1592454029-839522115-1007Core.job
      - c:\documents and settings\Test Account.XP-54E10D31A13C\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-18 01:07]

      2010-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1592454029-839522115-1007UA.job
      - c:\documents and settings\Test Account.XP-54E10D31A13C\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-12-18 01:07]

      2010-12-31 c:\windows\Tasks\User_Feed_Synchronization-{382D449B-C195-41E6-9C0F-C2CCC0C7D31D}.job
      - c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://www.google.com.ph/
      uInternet Settings,ProxyOverride = *.local
      uSearchAssistant = hxxp://www.google.com/ie
      uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
      IE: Download All By FlashGet3 - c:\documents and settings\xxx\Application Data\FlashGetBHO\GetAllUrl.htm
      IE: Download By FlashGet3 - c:\documents and settings\xxx\Application Data\FlashGetBHO\GetUrl.htm
      IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
      Trusted Zone: kuaiche.com\software
      FF - ProfilePath - c:\documents and settings\xxx\Application Data\Mozilla\Firefox\Profiles\mtid3796.default\
      FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
      FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.ph/
      FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4c6b3303&v=6.010.006.004&i=23&tp=ab&iy=&ychte=ph&lng=en-US&q=
      FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
      FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
      FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
      FF - Ext: flashget3 Extension: {DB9127A2-3381-41ec-82B3-1B6ED4C6F29A} - c:\program files\Mozilla Firefox\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}
      FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
      FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
      FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
      FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
      FF - Ext: Java Quick Starter: [emailprotected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
      FF - Ext: FiddlerHook: [emailprotected] - c:\program files\Fiddler2\FiddlerHook
      FF - Ext: Stylish: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8} - %profile%\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
      FF - Ext: Orange Fox: {5b35cb30-16b4-11de-8c30-0800200c9a66} - %profile%\extensions\{5b35cb30-16b4-11de-8c30-0800200c9a66}
      FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
      FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
      FF - Ext: Battlefield Heroes Updater: [emailprotected] - %profile%\extensions\[emailprotected]
      FF - Ext: Firebug: [emailprotected] - %profile%\extensions\[emailprotected]
      FF - Ext: Conduit Engine : [emailprotected] - %profile%\extensions\[emailprotected]
      FF - Ext: Softonic-Eng7 Community Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - %profile%\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
      FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true
      .
      - - - - ORPHANS REMOVED - - - -

      URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
      URLSearchHooks-{84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)
      URLSearchHooks-{346de098-61f9-4b42-89da-6dfba7091bb6} - (no file)
      BHO-{5ed22e89-62fa-47ec-bd8d-374d849d436c} - (no file)
      Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
      WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
      AddRemove-{980A182F-E0A2-4A40-94C1-AE0C1235902E} - c:\program files\Pando Networks\Media Booster\uninst.exe



      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-12-31 09:24
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************

      [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
      "ImagePath"="\??\c:\docume~1\xxx\LOCALS~1\Temp\LNK2C.tmp"

      [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
      "ImagePath"="c:\windows\system32\GameMon.des -service"
      .
      --------------------- LOCKED REGISTRY KEYS ---------------------

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
      "Enabled"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
      @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker4"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------

      - - - - - - - > 'winlogon.exe'(788)
      c:\program files\SUPERAntiSpyware\SASWINLO.DLL
      c:\windows\system32\WININET.dll

      - - - - - - - > 'explorer.exe'(3452)
      c:\windows\system32\WININET.dll
      c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
      c:\program files\Nero\Nero8\InCD\NBHShx.dll
      c:\program files\Nero\Nero8\InCD\NBHStr.dll
      c:\program files\Common Files\Nero\Shared\NL3\AdvrCntr3.dll
      c:\windows\system32\msi.dll
      c:\windows\system32\ieframe.dll
      c:\windows\system32\webcheck.dll
      .
      ------------------------ Other Running Processes ------------------------
      .
      c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      c:\program files\Bonjour\mDNSResponder.exe
      c:\program files\Nero\Nero8\InCD\InCDsrv.exe
      c:\program files\Java\jre6\bin\jqs.exe
      c:\windows\system32\PnkBstrA.exe
      c:\windows\system32\wdfmgr.exe
      c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
      c:\windows\system32\wscntfy.exe
      c:\windows\RTHDCPL.EXE
      c:\program files\iPod\bin\iPodService.exe
      c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
      .
      **************************************************************************
      .
      Completion time: 2010-12-31 09:28:26 - machine was rebooted
      ComboFix-quarantined-files.txt 2010-12-31 17:28

      Pre-Run: 71,741,403,136 bytes free
      Post-Run: 71,748,911,104 bytes free

      WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      UnsupportedDebug="do not select this" /debug
      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

      - - End Of File - - 00FB71455A5BAD310D970830700C0DF4
      Please download the newest version of Adobe Acrobat READER from Adobe.com

      Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
      Go to the Control Panel and enter Add or Remove Programs.
      Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

      Once old versions are gone, please install the newest version.
      **************************************************
      P2P - I see you have P2P software installed on your machine (uTorrent). We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

      Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

      I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
      **********************************************
      GameGuard Service doesn't have a very good reputation in the malware world. I would suggest that you uninstall it.

      Re-running ComboFix to remove infections:

      • Close any open browsers.
      • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Open notepad and copy/paste the text in the quotebox below into it:
        Quote
        KillAll::

        File::
        c:\program files\Google\Update\GoogleUpdate.exe
        c:\docume~1\xxx\LOCALS~1\Temp\LNK2C.tmp
        c:\program files\level up games\grand chase\GameGuard\dump_wmimmc.sys
        c:\windows\system32\XDva285.sys
        c:\windows\system32\XDva312.sys
        c:\windows\system32\XDva361.sys
        c:\windows\system32\XDva367.sys
        c:\windows\system32\XDva368.sys
        c:\windows\system32\XDva370.sys
        c:\windows\system32\XDva372.sys
        c:\windows\system32\XDva377.sys

        DDS::
        Trusted Zone: kuaiche.com\software

        Driver::
        gupdate
        GarenaPEngine
        dump_wmimmc
        XDva285
        XDva312
        XDva361
        XDva367
        XDva368
        XDva370
        XDva372
        XDva377

      • Save this as CFScript.txt, in the same location as ComboFix.exe



      • Referring to the picture above, drag CFScript into ComboFix.exe
      • When finished, it shall produce a log for you at C:\ComboFix.txt
      • Please post the contents of the log in your next reply.
      ******************************************************

      Please download TDSSKiller from here and save it to your Desktop.
      • Doubleclick TDSSKiller.exe to run the tool
      • Click the Start Scan button (If prompted with a "hidden service warning" do go ahead and delete it.)

      • After the scan has finished, click the Close button
      • Click the Report button and copy/paste the contents of it into your next reply
      • Note:It will also create a log in the C:\ directory.
      348.

      Solve : drweb.exe amongst other names?

      Answer»
        Quote from: SuperDave on December 27, 2010, 04:41:38 PM

        • When you have re-booted, please post a fresh HijackThis log into this thread and tell me how your computer is running now
        .

        Still won't let me update Avast. Still getting web page redirects. Most recent redirect was to: hxxp://www.happili.com/vht/innerxy.php?q=Cnn&xy=riva-631
        Quote
        Is this because it is Windows 7?

        Could be. I don't have Win7

        Quote
        Does not allow me to "check" running processes - it is grayed out. Running SCAN now will post update shortly.
        This is the first time I've used this canned speech. It's possibly because of Win7

        Open HijackThis and select Do a system scan only

        Place a check mark next to the following entries: (if there)

        O1 - Hosts: ÿþ127.0.0.1 localhost
        O1 - Hosts: ::1 localhost


        Important: Close all open windows except for HijackThis and then click Fix checked.

        Once completed, exit HijackThis.
        ******************************************
        Ok. Let's try this one.

        Please download Rooter and Save it to your desktop.
        • Double click it to start the tool.
        • Click Scan.
        • Eventually, a Notepad file containing the report will open, also found at C:\Rooter.txt. Post that log in your next reply.
        Quote from: SuperDave on December 28, 2010, 01:44:28 PM
        O1 - Hosts: ÿþ127.0.0.1 localhost
        O1 - Hosts: ::1 localhost


        Important: Close all open windows except for HijackThis and then click Fix checked.



        DoneQuote from: SuperDave on December 28, 2010, 01:44:28 PM
        • Eventually, a Notepad file containing the report will open, also found at C:\Rooter.txt. Post that log in your next reply.
        Rooter.exe (v1.0.2) by Eric_71
        .
        SeDebugPrivilege granted successfully ...
        .
        Windows 7 Home Edition (6.1.7600)
        [32_bits] - Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
        .
        [wscsvc] (Security Center) RUNNING (state:4)
        [MpsSvc] RUNNING (state:4)
        Windows Firewall -&GT; Enabled
        Windows Defender -> Enabled
        User Account Control (UAC) -> Enabled
        .
        Internet Explorer 8.0.7600.16385
        .
        C:\ [Fixed-NTFS] .. ( Total:451 Go - Free:403 Go )
        D:\ [CD_Rom]
        .
        Scan : 15:52.48
        Path : C:\Users\Gerrit deBorst\Desktop\Rooter.exe
        User : Gerrit deBorst ( Administrator -> YES )
        .
        ----------------------\\ Processes
        .
        Locked [System Process] (0)
        Locked System (4)
        ______ ???z??? (264)
        ______ ???z??? (400)
        ______ ???z??? (464)
        ______ ???z??? (480)
        ______ ???z??? (512)
        ______ ???z??? (536)
        ______ ???z??? (544)
        ______ ???z??? (628)
        ______ ???z??? (700)
        ______ ???z??? (788)
        ______ ???z??? (852)
        ______ ???z??? (916)
        ______ ???z??? (964)
        ______ ???z??? (1000)
        ______ ???z??? (312)
        ______ C:\Program Files\Dell\DellDock\DockLogin.exe (1052)
        ______ ???z??? (1128)
        ______ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (1212)
        ______ ???z??? (1312)
        ______ ???z??? (1336)
        ______ ???z??? (1588)
        ______ ???z??? (1620)
        ______ ???z??? (1632)
        ______ C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1764)
        ______ ???z??? (1864)
        ______ C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (1908)
        ______ C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (1964)
        ______ ???z??? (2000)
        ______ C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (2032)
        ______ ???z??? (2852)
        ______ ???z??? (2652)
        ______ C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe (2904)
        ______ ???z??? (3044)
        ______ C:\ProgramData\Macrovision\FLEXnet Connect\11\ISUSPM.exe (2960)
        ______ C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (2676)
        ______ C:\Program Files\Alwil Software\Avast5\AvastUI.exe (2604)
        ______ ???z??? (2252)
        ______ ???z??? (1300)
        ______ C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (3560)
        ______ ???z??? (3732)
        ______ C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_ActiveX.exe (3764)
        Locked audiodg.exe (3840)
        ______ ???z??? (4080)
        ______ ???z??? (1652)
        ______ ???z??? (3196)
        ______ C:\Users\Gerrit deBorst\Desktop\Rooter.exe (2320)
        .
        ----------------------\\ Device\Harddisk0\
        .
        \Device\Harddisk0 [Sectors : 63 x 512 Bytes]
        .
        \Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:41094144)
        \Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:41126400 | Length:15728640000)
        \Device\Harddisk0\Partition3 (Start_Offset:15769766400 | Length:484337047040)
        .
        ----------------------\\ Scheduled Tasks
        .
        C:\Windows\Tasks\SA.DAT
        C:\Windows\Tasks\SCHEDLGU.TXT
        .
        ----------------------\\ Registry
        .
        .
        ----------------------\\ Files & Folders
        .
        ----------------------\\ Scan completed at 15:52.55
        .
        C:\Rooter$\Rooter_1.txt - (28/12/2010 | 15:52.55)
        First off I appreciate you taking the time to help me with this - and I can see from the forum you are working on multiple issues at one. I realize that you don't want me to attempt anything to solve the problem, but time is of the essence as my father is returning to Florida and I need to get this done before he leaves.

        That being the case I have researched the issue and narrowed it down to a bootkit infection specifically rootkit.win32.tdss. I have dowloaded and run Kaspersky TDSSKILLER. This program found the the bootkit infection and removed it.

        A review of internet explorer appears that the redirect is GONE. I loaded about 20 pages without getting redirected.

        Additionaly I have researched the AVAST problem with AVAST and found that by changing the connection in the AVAST settings page for Proxy Server to direct connect this resolves my problem.


        If there is any cleanup you think I should do please let me know.

        If my actions have caused further problem for you - please accept my apologies and close this thread.I'm glad that you were able to get it cleaned. I would like you to run one last scan, if you please.

        I'd like to scan your machine with ESET OnlineScan

        •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
        ESET OnlineScan
        •Click the button.
        •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
        • Click on to download the ESET Smart Installer. Save it to your desktop.
        • Double click on the icon on your desktop.
        •Check
        •Click the button.
        •Accept any security warnings from your browser.
        •Check
        •Push the Start button.
        •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
        •When the scan completes, push
        •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
        •Push the button.
        •Push
        A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Quote from: SuperDave on December 28, 2010, 04:40:53 PM
        save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.


        C:\Users\Gerrit deBorst\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\30d181d3-6c62447emultiple threatsdeleted - quarantined

        C:\Users\Gerrit deBorst\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\5def9a73-63f50e0cmultiple threatsdeleted - quarantined
        Ok. That's looks GOOD. Let's cleanup.

        To remove all of the tools we used and the files and folders they created do the following:
        Double click OTL.exe.
        • Click the CleanUp button.
        • Select Yes when the "Begin cleanup Process?" prompt appears.
        • If you are prompted to Reboot during the cleanup, select Yes.
        • The tool will delete itself once it finishes.
        Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
        *************************************************
        Clean out your temporary internet files and temp files.

        Download TFC by OldTimer to your desktop.

        Double-click TFC.exe to run it.

        Note: If you are running on Vista, right-click on the file and choose Run As Administrator

        TFC will close all programs when run, so make sure you have saved all your work before you begin.

        * Click the Start button to begin the cleaning process.
        * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
        * Please let TFC run uninterrupted until it is finished.

        Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
        ************************************************
        Looking over your log it seems you don't have any evidence of a third party firewall.

        Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

        Remember only install ONE firewall

        1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
        2) Online Armor
        3) Agnitum Outpost
        4) PC Tools Firewall Plus

        If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
        ***************************************************************
        Use the Secunia Software Inspector to check for out of date software.

        •Click Start Now

        •Check the box next to Enable thorough system inspection.

        •Click Start

        •Allow the scan to finish and scroll down to see if any updates are needed.
        •Update anything listed.
        .
        ----------

        Go to Microsoft Windows Update and get all critical updates.

        ----------

        I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

        SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

        Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

        Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
        Safe Surfing!Quote from: SuperDave on December 29, 2010, 12:59:25 PM
        Ok. That's looks good. Let's cleanup.


        Thanks for all your help!!
        349.

        Solve : Explore.exe and services.exe virus - Windows XP...!!!?

        Answer»

        SuperDave -
        My apologies. My intentions were to get assistance ASAP as I posted both threads around the same time.
        On the other forum I only posted logs from the SCANS that you had initially requested. I did not perform any other tasks other than what you requested in this thread other than running ComboFix a second time which I MENTIONED to you earlier.


        I ran the ESET Online scanner which came up with 0 infected files.

        [emailprotected] as DOWNLOADER log:
        all ok
        # version=7
        # OnlineScannerApp.exe=1.0.0.1
        # OnlineScanner.ocx=1.0.0.6419
        # api_version=3.0.2
        # EOSSerial=1d92e26ce77ca64a80a4315df6e3171a
        # end=finished
        # remove_checked=false
        # archives_checked=true
        # unwanted_checked=true
        # unsafe_checked=false
        # antistealth_checked=true
        # utc_time=2010-12-25 12:45:00
        # local_time=2010-12-24 04:45:00 (-0800, PACIFIC Standard Time)
        # country="United States"
        # lang=1033
        # osver=5.1.2600 NT Service Pack 3
        # compatibility_mode=512 16777215 100 0 0 0 0 0
        # compatibility_mode=8199 39157077 100 100 0 15747384 0 0
        # scanned=38450
        # found=0
        # cleaned=0
        # scan_time=3739
        # nod_component=V3 Build:0x30000000
        You really should ADVISE Belahzur that you're finished with the thread on GeekPolice.net.
        Ok. Where are we now? Everything looks good from this end.

        350.

        Solve : Deep rooted fake anti-virus software (I think)?

        Answer»

        Let's see what happens once we clean it all up.

        Clean up System Restore

        Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."

        • SELECT Start > All Programs > Accessories > System tools > System Restore.
        • On the dialogue box that appears select Create a Restore Point
        • Click NEXT
        • Enter a name e.g. Clean
        • Click CREATE
        You now have a clean restore point, to get rid of the bad ones:
        • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
        • In the Drop down box that appears select your main DRIVE e.g. C
        • Click OK
        • The System will do some calculation and the display a dialogue box with TABS
        • Select the More Options Tab.
        • At the bottom will be a system restore box with a CLEANUP button click this
        • Accept the Warning and select OK again, the program will close and you are done
        Run OTC to remove our tools

        To remove all of the tools we used and the files and folders they created, please do the following:
        Please download OTC.exe by OldTimer:
        • Save it to your Desktop.
        • Double click OTC.exe.
        • Click the CleanUp! button.
        • If you are prompted to Reboot during the cleanup, select Yes.
        • The tool will delete itself once it finishes.
        Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

        Purge old temporary files

        Please download TFC by OldTimer to your desktop
        • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
        • It will close all programs when run, so make sure you have saved all your work before you begin.
        • Click the Start
          button to begin the process. Depending on how often you clean temp
          files, execution time should be anywhere from a few seconds to a minute
          or two. Let it run uninterrupted to completion.
        • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
        Security Check

        Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
        • Save it to your Desktop.
        • Double click SecurityCheck.exe and follow the ONSCREEN instructions inside of the black box.
        • A Notepad document should OPEN automatically called checkup.txt; please post the contents of that document.
        Tell me in your next REPLY, if you have completed these tasks:
        • Cleaned System Restore
        • Ran OTC
        • Ran TFC
        • Ran Security Check
        Also, let me know how your computer is running, and don't forget to post the contents of the Security Check log.