Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Recurring popups and volume muting


  • This topic is locked This topic is locked

#1
sepaulsen

sepaulsen

    New Member

  • Member
  • Pip
  • 8 posts
I am having an identical problem and have scanned with multiple products and I am unable to fix the problem.
I have run MBR and am currently running OTL.

MBRCheck, version 1.1.1

© 2010, AD



\\.\C: --> \\.\PhysicalDrive0

\\.\D: --> \\.\PhysicalDrive0

\\.\G: --> \\.\PhysicalDrive1



Size Device Name MBR Status

--------------------------------------------

149 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)!

298 GB \\.\PhysicalDrive1 Error reading raw MBR!





Found non-standard or infected MBR.

Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Options:

[1] Dump the MBR of a physical disk to file.

[2] Restore the MBR of a physical disk with a standard boot code.

[3] Exit.



Enter your choice: Enter the physical disk number to dump (0-99, -1 to exit):
  • 0

Advertisements


#2
sepaulsen

sepaulsen

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
OTL logfile created on: 7/20/2010 2:20:25 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\sepaulsen\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 43.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 15.01 Gb Total Space | 2.41 Gb Free Space | 16.06% Space Free | Partition Type: NTFS
Drive D: | 129.03 Gb Total Space | 3.76 Gb Free Space | 2.91% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 298.09 Gb Total Space | 7.03 Gb Free Space | 2.36% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VALUED-B4B48255
Current User Name: sepaulsen
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/07/20 14:17:00 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sepaulsen\My Documents\Downloads\OTL.exe
PRC - [2010/07/20 11:49:12 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/07/20 11:49:11 | 000,620,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/07/20 11:49:09 | 000,515,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/07/20 11:48:55 | 004,093,792 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgui.exe
PRC - [2010/07/20 11:48:42 | 002,065,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/07/20 11:48:38 | 000,723,296 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/07/20 11:47:57 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/07/20 11:47:43 | 000,755,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgscanx.exe
PRC - [2010/06/28 21:27:23 | 000,945,720 | ---- | M] (Google Inc.) -- C:\Documents and Settings\sepaulsen\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2010/04/29 15:39:32 | 001,090,952 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2009/08/05 22:53:26 | 001,590,616 | ---- | M] (Research In Motion Limited) -- C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
PRC - [2009/04/21 23:02:24 | 001,079,296 | ---- | M] (ADDPCs) -- C:\Documents and Settings\sepaulsen\Local Settings\Temp\Rar$EX00.125\tempCleaner.exe
PRC - [2009/03/02 16:50:16 | 000,376,832 | ---- | M] (Research In Motion Limited) -- C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/21 22:17:09 | 000,455,344 | ---- | M] () -- C:\Program Files\Lexmark 5300 Series\lxdkmon.exe
PRC - [2007/06/14 03:15:34 | 000,598,960 | ---- | M] ( ) -- C:\WINDOWS\system32\lxdkcoms.exe
PRC - [2007/06/01 03:06:09 | 000,020,480 | ---- | M] () -- C:\Program Files\Lexmark 5300 Series\lxdkamon.exe
PRC - [2006/01/02 17:41:22 | 000,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2002/08/20 13:29:26 | 000,040,960 | ---- | M] (Easy Systems Japan Ltd.) -- C:\WINDOWS\system32\ezSP_Px.exe


========== Modules (SafeList) ==========

MOD - [2010/07/20 14:17:00 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\sepaulsen\My Documents\Downloads\OTL.exe
MOD - [2008/04/13 19:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe -- (RoxLiveShare9)
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/07/20 11:47:57 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/04/19 10:25:38 | 000,430,152 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2008/10/28 17:42:30 | 000,156,968 | ---- | M] (Seagate Technology LLC) [On_Demand | Stopped] -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -- (FreeAgentGoNext Service)
SRV - [2007/06/14 03:15:34 | 000,598,960 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\System32\lxdkcoms.exe -- (lxdk_device)
SRV - [2007/06/14 03:15:24 | 000,099,248 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdkserv.exe -- (lxdkCATSCustConnectService)
SRV - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2005/10/14 03:53:50 | 000,087,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2003/10/21 00:00:56 | 001,286,144 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe -- (VAIOMediaPlatform-VideoServer-AppServer)
SRV - [2003/10/21 00:00:40 | 000,712,704 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe -- (VAIOMediaPlatform-VideoServer-UPnP) VAIO Media Video Server (UPnP)
SRV - [2003/10/21 00:00:40 | 000,712,704 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe -- (VAIOMediaPlatform-PhotoServer-UPnP) VAIO Media Photo Server (UPnP)
SRV - [2003/10/21 00:00:40 | 000,712,704 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe -- (VAIOMediaPlatform-MusicServer-UPnP) VAIO Media Music Server (UPnP)
SRV - [2003/10/21 00:00:38 | 000,057,344 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe -- (VAIOMediaPlatform-VideoServer-HTTP) VAIO Media Video Server (HTTP)
SRV - [2003/10/21 00:00:38 | 000,057,344 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe -- (VAIOMediaPlatform-PhotoServer-HTTP) VAIO Media Photo Server (HTTP)
SRV - [2003/10/21 00:00:38 | 000,057,344 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe -- (VAIOMediaPlatform-MusicServer-HTTP) VAIO Media Music Server (HTTP)
SRV - [2003/10/21 00:00:14 | 000,925,696 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe -- (VAIOMediaPlatform-PhotoServer-AppServer)
SRV - [2003/10/21 00:00:08 | 000,503,897 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe -- (VAIOMediaPlatform-MusicServer-AppServer)
SRV - [2003/07/28 20:31:14 | 000,065,536 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe -- (SPTISRV)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\TMPassthru.sys -- (TMPassthruMP)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Internet Explorer\SABProcEnum.sys -- (SABProcEnum)
DRV - File not found [File_System | Boot | Stopped] -- C:\WINDOWS\System32\DRIVERS\Lbd.sys -- (Lbd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\SEPAUL~1\LOCALS~1\Temp\pftCC.tmp\amifldrv.sys -- (GENERICDRV)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/07/20 11:52:15 | 000,243,024 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/07/20 11:52:02 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/07/20 11:51:59 | 000,029,584 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2010/06/09 16:47:41 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/06/09 16:47:41 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2010/06/09 16:47:41 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2009/04/30 22:55:58 | 002,687,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2008/04/13 13:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/02/26 10:33:17 | 000,008,413 | ---- | M] (RealNetworks, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\mcstrm.sys -- (MCSTRM)
DRV - [2008/02/19 23:26:07 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2007/12/11 10:52:12 | 000,026,784 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2007/12/04 18:10:30 | 000,016,640 | R--- | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PalmUSBD.sys -- (PalmUSBD)
DRV - [2007/11/02 14:36:10 | 000,018,176 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motccgp.sys -- (motccgp)
DRV - [2007/06/18 14:18:26 | 000,023,680 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motport.sys -- (motport)
DRV - [2007/06/18 14:18:26 | 000,023,680 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motmodem.sys -- (motmodem)
DRV - [2007/01/23 20:03:44 | 000,007,680 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motccgpfl.sys -- (motccgpfl)
DRV - [2006/05/03 11:50:42 | 001,540,608 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/07/22 15:50:16 | 001,268,234 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2003/10/30 14:20:54 | 000,766,848 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\smrt.sys -- (smrt)
DRV - [2003/08/18 20:56:00 | 001,343,803 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2001/08/17 07:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)
DRV - [2000/12/05 19:18:02 | 000,003,952 | R--- | M] (Sony Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\DMICall.sys -- (DMICall)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

========== FireFox ==========

FF - prefs.js..browser.search.defaultEngine: "Yahoo"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo....fr=ytff-tyc&p="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-tyc"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-tyc"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.4
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:7
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.23
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.825
FF - prefs.js..extensions.enabledItems: avg@igeared:4.504.019.002
FF - prefs.js..keyword.URL: "http://us.yhs.search...2-tb-web_us&p="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/07/20 11:47:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/07/20 11:50:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/04 09:52:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/29 22:36:51 | 000,000,000 | ---D | M]

[2009/05/17 12:44:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\sepaulsen\Application Data\Mozilla\Extensions
[2009/05/17 12:44:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\sepaulsen\Application Data\Mozilla\Extensions\[email protected]
[2010/07/20 13:31:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\sepaulsen\Application Data\Mozilla\Firefox\Profiles\zomqp1qe.default\extensions
[2010/05/12 23:00:16 | 000,000,000 | ---D | M] (FlashGot) -- C:\Documents and Settings\sepaulsen\Application Data\Mozilla\Firefox\Profiles\zomqp1qe.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}(2)
[2010/07/12 23:44:09 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\sepaulsen\Application Data\Mozilla\Firefox\Profiles\zomqp1qe.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/07/13 19:45:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\sepaulsen\Application Data\Mozilla\Firefox\Profiles\zomqp1qe.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/03/18 18:57:29 | 000,001,844 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Application Data\Mozilla\Firefox\Profiles\zomqp1qe.default\searchplugins\bing-ff.xml
[2010/07/20 13:30:39 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/07/16 03:46:54 | 000,412,044 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-domains-registrations.com
O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 14241 more lines...
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe (Easy Systems Japan Ltd.)
O4 - HKLM..\Run: [lxdkamon] C:\Program Files\Lexmark 5300 Series\lxdkamon.exe ()
O4 - HKLM..\Run: [lxdkmon.exe] C:\Program Files\Lexmark 5300 Series\lxdkmon.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VAIO Recovery] C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [{0CEE364C-F753-49d0-8B5E-003A6C17DD93}] C:\Documents and Settings\sepaulsen\Application Data\c0ki38z3\msrss.exe ()
O4 - HKCU..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE (ATI Technologies Inc.)
O4 - HKCU..\Run: [RIMDeviceManager] C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe (Research In Motion Limited)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoMovingBands = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCloseDragDropBands = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarsOnTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: emscharts.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: listen.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: scifi.com ([video] http in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...tes/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB (VaioInfo.CMClass)
O16 - DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} http://www.shockwave...eb.1.0.0.21.cab (CPlayFirstFashionDasControl Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://tky09.celarte...ntrol_en_US.cab (DjVuCtl Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} http://www.shockwave...Web.1.0.0.9.cab (CPlayFirstCookingDasControl Object)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.t...ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} https://www.idphnet....t/LocalExec.CAB (LocalExec Control)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.syma...bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} http://www-cdn.freer...ller.cab?v=1055 (SonyOnlineInstallerX)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace....ploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {588031A3-94BF-4CDD-86D0-939F6F93910F} https://fixit.suppor...FixItClient.CAB (FixItClient Class)
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} http://www.shockwave...h2.1.0.0.67.cab (CPlayFirstDinerDash2Control Object)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1203472651468 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.syma...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/.../GrooveAX27.cab (Groove Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.c...loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {99FE5072-78AA-4FEE-89BA-69A5FA55343F} http://download.micr...44/igdtoolx.cab (IGDTester Class)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace....ceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} http://www.linksysfi...ll/gtdownls.cab (LinkSys Content Update)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadbl...ivex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} https://ediagnostics....com/serval.cab (Lexmark eDiagnostics Class)
O16 - DPF: {CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} Reg Error: Key error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 97.64.183.164 97.64.179.250
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/12/01 20:36:01 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/02/24 19:56:20 | 000,000,059 | ---- | M] () - G:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{6b7417c8-282e-11df-8e5a-000ea6523580}\Shell\AutoRun\command - "" = H:\slacker.synclauncher.exe -- File not found
O33 - MountPoints2\{6b7417c8-282e-11df-8e5a-000ea6523580}\Shell\slacker\command - "" = H:\slacker.synclauncher.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/07/20 14:28:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sepaulsen\Desktop\New Folder (2)
[2010/07/20 14:09:12 | 000,000,000 | ---D | C] -- C:\ERDNT
[2010/07/20 14:09:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/07/20 14:08:22 | 000,000,000 | ---D | C] -- C:\!FixIEDef
[2010/07/20 13:31:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sepaulsen\Local Settings\Application Data\AVG Security Toolbar
[2010/07/20 13:05:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/07/20 11:52:21 | 000,012,536 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2010/07/20 11:52:13 | 000,243,024 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/07/20 11:52:01 | 000,216,400 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/07/20 11:51:57 | 000,029,584 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/07/20 11:50:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2010/07/20 11:50:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/07/20 11:43:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/07/20 11:27:36 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Defender
[2010/07/20 11:21:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sepaulsen\Application Data\c0ki38z3
[2010/07/19 03:09:59 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/07/19 03:03:15 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/07/17 14:47:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sepaulsen\Local Settings\Application Data\Sunbelt Software
[2010/07/17 14:05:17 | 000,000,000 | ---D | C] -- C:\Program Files\SpywareGuard
[2010/07/16 16:11:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sepaulsen\Desktop\regcleaner
[2010/07/16 06:29:29 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/16 04:00:47 | 000,161,296 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2010/07/14 22:47:15 | 000,578,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2010/07/14 22:45:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2010/07/14 22:44:36 | 000,000,000 | ---D | C] -- C:\SDFix
[2010/07/14 22:13:09 | 000,000,000 | ---D | C] -- C:\VundoFix Backups
[2010/07/14 22:11:10 | 000,000,000 | ---D | C] -- C:\Program Files\ToniArts
[2010/07/14 21:54:20 | 000,017,544 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\RkPavproc1.sys
[2010/07/14 21:50:23 | 000,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2010/07/13 21:28:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/07/13 19:46:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sepaulsen\Application Data\QuickScan
[2010/07/13 19:10:41 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2010/07/13 16:03:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/11 02:12:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/07/05 12:34:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Yahoo!
[2010/07/04 10:13:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/27 18:01:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sepaulsen\Local Settings\Application Data\SCE
[2010/06/27 17:59:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\sepaulsen\Application Data\Sony Online Entertainment
[2009/03/11 19:53:52 | 000,434,176 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdkhcp.dll
[2007/05/17 09:11:04 | 000,647,168 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdkpmui.dll
[2007/05/17 09:07:59 | 001,200,128 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdkserv.dll
[2007/05/17 09:03:03 | 000,356,352 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdkinpa.dll
[2007/05/17 09:02:58 | 000,565,248 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdklmpm.dll
[2007/05/17 09:02:41 | 000,364,544 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdkcomm.dll
[2007/05/17 09:01:21 | 000,663,552 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdkhbn3.dll
[2007/05/17 09:00:42 | 000,950,272 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdkusb1.dll
[2007/05/17 09:00:29 | 000,860,160 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdkcomc.dll
[2007/05/17 08:59:11 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdkprox.dll
[2007/05/17 08:57:01 | 000,339,968 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdkiesc.dll

========== Files - Modified Within 30 Days ==========

[2010/07/20 14:22:14 | 000,000,100 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\Recurring popups and volume muting.url
[2010/07/20 14:02:53 | 000,000,071 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\Troubleshooting Windows XP, Tweaks and Fixes for Windows XP.url
[2010/07/20 13:35:22 | 000,000,256 | ---- | M] () -- C:\Documents and Settings\sepaulsen\pool.bin
[2010/07/20 13:34:41 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/20 13:34:38 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/20 13:32:17 | 020,447,232 | ---- | M] () -- C:\Documents and Settings\sepaulsen\ntuser.dat
[2010/07/20 13:32:17 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\sepaulsen\ntuser.ini
[2010/07/20 11:52:25 | 000,001,507 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/07/20 11:52:24 | 000,012,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2010/07/20 11:52:15 | 000,243,024 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/07/20 11:52:02 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/07/20 11:51:59 | 000,029,584 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/07/20 11:51:57 | 062,233,142 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/07/20 11:51:57 | 000,113,461 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/07/20 11:25:16 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/20 11:21:54 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Application Data\dsktop.dat
[2010/07/20 05:25:23 | 000,024,131 | ---- | M] () -- C:\Documents and Settings\sepaulsen\My Documents\NASAR_SARTECHTM_II_MINIMUM_PERSONAL_EQUIPMENT_LIST_11_2004.pdf
[2010/07/19 03:42:53 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/18 18:05:30 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/07/18 18:02:17 | 000,039,104 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/18 17:49:02 | 000,187,408 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/18 12:20:01 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\sepaulsen\defogger_reenable
[2010/07/17 16:39:27 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/07/17 02:11:44 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk
[2010/07/16 21:36:49 | 000,000,697 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/07/16 16:21:30 | 000,032,425 | ---- | M] () -- C:\Documents and Settings\sepaulsen\My Documents\2739_001-1.pdf
[2010/07/16 04:00:47 | 000,161,296 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2010/07/16 03:46:54 | 000,412,044 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2010/07/16 03:25:41 | 000,284,915 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\gmer.zip
[2010/07/16 03:03:37 | 000,000,071 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\Blue Line Gear - Sherpa.URL
[2010/07/15 09:19:28 | 000,000,376 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2010/07/15 00:02:53 | 005,154,304 | ---- | M] () -- C:\Documents and Settings\sepaulsen\My Documents\WindowsDefender.msi
[2010/07/14 23:04:03 | 000,000,686 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20100716-034654.backup
[2010/07/14 22:47:15 | 000,578,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\user32.dll
[2010/07/14 21:44:14 | 000,000,075 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\AndyManchesta - Anti-Virus.URL
[2010/07/14 07:23:04 | 000,000,089 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\HJT Log random pop-ups - dslreports.com.URL
[2010/07/13 21:27:34 | 000,028,547 | ---- | M] () -- C:\Documents and Settings\All Users\lxdk
[2010/07/13 21:27:08 | 000,010,199 | ---- | M] () -- C:\Documents and Settings\sepaulsen\My Documents\CLUTCH_CABLE_ADJUSTMENT.pdf
[2010/07/13 18:57:10 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/07/12 01:49:03 | 000,084,480 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/11 20:03:19 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Local Settings\Application Data\housecall.guid.cache
[2010/07/10 19:33:00 | 000,097,168 | ---- | M] () -- C:\Documents and Settings\sepaulsen\My Documents\0709102236.jpg
[2010/07/10 15:30:53 | 001,536,569 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\mcmanual.pdf
[2010/07/05 13:34:18 | 000,000,076 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\Ruben Calo Custom Knives - Tutorials.URL
[2010/07/05 13:34:09 | 000,000,081 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\Ariel Salaverria Custom Knives - Damascus and Mokume EDC Tools Gallery - Page 5.URL
[2010/07/04 21:30:45 | 000,000,084 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\Todd Foster Saps.URL
[2010/07/03 17:28:06 | 000,002,316 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\Google Chrome.lnk
[2010/07/03 17:28:06 | 000,002,294 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/06/29 22:36:52 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[2010/06/26 21:24:51 | 000,000,087 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\Bacon Recipes Royal Bacon Society - The Ultimate Bacon Resource.URL
[2010/06/26 17:03:17 | 000,065,205 | ---- | M] () -- C:\Documents and Settings\sepaulsen\My Documents\Kumihimoinstructions.pdf
[2010/06/23 19:16:24 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/06/23 19:16:24 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/06/23 16:22:31 | 000,000,106 | ---- | M] () -- C:\Documents and Settings\sepaulsen\Desktop\National Weather Service - RIDGE2 Radar Display.URL
[2010/06/23 05:32:30 | 094,224,315 | ---- | M] () -- C:\Documents and Settings\sepaulsen\My Documents\fema577.pdf
[2010/06/23 04:20:46 | 000,472,850 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/23 04:20:45 | 000,567,576 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/23 04:20:45 | 000,084,052 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

========== Files Created - No Company Name ==========

[2010/07/20 14:22:14 | 000,000,100 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\Recurring popups and volume muting.url
[2010/07/20 14:02:53 | 000,000,071 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\Troubleshooting Windows XP, Tweaks and Fixes for Windows XP.url
[2010/07/20 11:52:25 | 000,001,507 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/07/20 11:51:57 | 000,113,461 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/07/20 11:50:52 | 062,233,142 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/07/20 11:21:54 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Application Data\dsktop.dat
[2010/07/20 05:25:23 | 000,024,131 | ---- | C] () -- C:\Documents and Settings\sepaulsen\My Documents\NASAR_SARTECHTM_II_MINIMUM_PERSONAL_EQUIPMENT_LIST_11_2004.pdf
[2010/07/18 12:20:01 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\sepaulsen\defogger_reenable
[2010/07/18 12:07:16 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\gmer.exe
[2010/07/17 14:56:22 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/07/16 16:21:30 | 000,032,425 | ---- | C] () -- C:\Documents and Settings\sepaulsen\My Documents\2739_001-1.pdf
[2010/07/16 03:25:49 | 000,284,915 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\gmer.zip
[2010/07/16 03:03:37 | 000,000,071 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\Blue Line Gear - Sherpa.URL
[2010/07/15 00:02:53 | 005,154,304 | ---- | C] () -- C:\Documents and Settings\sepaulsen\My Documents\WindowsDefender.msi
[2010/07/14 21:44:14 | 000,000,075 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\AndyManchesta - Anti-Virus.URL
[2010/07/14 07:23:04 | 000,000,089 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\HJT Log random pop-ups - dslreports.com.URL
[2010/07/13 21:27:08 | 000,010,199 | ---- | C] () -- C:\Documents and Settings\sepaulsen\My Documents\CLUTCH_CABLE_ADJUSTMENT.pdf
[2010/07/11 20:03:19 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Local Settings\Application Data\housecall.guid.cache
[2010/07/10 19:33:00 | 000,097,168 | ---- | C] () -- C:\Documents and Settings\sepaulsen\My Documents\0709102236.jpg
[2010/07/10 15:30:53 | 001,536,569 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\mcmanual.pdf
[2010/07/05 13:34:18 | 000,000,076 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\Ruben Calo Custom Knives - Tutorials.URL
[2010/07/05 13:34:09 | 000,000,081 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\Ariel Salaverria Custom Knives - Damascus and Mokume EDC Tools Gallery - Page 5.URL
[2010/07/04 21:30:45 | 000,000,084 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\Todd Foster Saps.URL
[2010/06/27 11:45:36 | 000,000,010 | ---- | C] () -- C:\Documents and Settings\sepaulsen\savepassw.txt
[2010/06/27 11:45:16 | 000,083,968 | ---- | C] () -- C:\WINDOWS\UnGins.exe
[2010/06/27 04:11:29 | 004,894,233 | ---- | C] () -- C:\Documents and Settings\sepaulsen\My Documents\ron edwards - how to make whips - 1998.djvu
[2010/06/26 21:24:51 | 000,000,087 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\Bacon Recipes Royal Bacon Society - The Ultimate Bacon Resource.URL
[2010/06/26 17:03:17 | 000,065,205 | ---- | C] () -- C:\Documents and Settings\sepaulsen\My Documents\Kumihimoinstructions.pdf
[2010/06/23 19:16:24 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/06/23 16:22:31 | 000,000,106 | ---- | C] () -- C:\Documents and Settings\sepaulsen\Desktop\National Weather Service - RIDGE2 Radar Display.URL
[2010/06/23 05:32:16 | 094,224,315 | ---- | C] () -- C:\Documents and Settings\sepaulsen\My Documents\fema577.pdf
[2010/03/15 18:42:20 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2009/06/23 22:57:15 | 000,000,040 | ---- | C] () -- C:\WINDOWS\nero.INI
[2009/05/25 04:04:38 | 000,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/05/25 04:04:38 | 000,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/05/25 04:04:37 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009/05/25 04:04:36 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/05/25 04:04:36 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/05/22 19:18:37 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\LXDKPMON.DLL
[2009/05/22 19:18:37 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXDKFXPU.DLL
[2009/05/22 19:18:17 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\lxdkoem.dll
[2009/04/30 22:39:36 | 000,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/03/18 22:49:48 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2009/03/18 22:47:55 | 000,000,891 | ---- | C] () -- C:\WINDOWS\disney.ini
[2009/03/11 19:53:56 | 000,000,060 | ---- | C] () -- C:\WINDOWS\System32\lxdkrwrd.ini
[2009/03/11 19:53:53 | 000,348,160 | ---- | C] () -- C:\WINDOWS\System32\lxdkinst.dll
[2009/02/17 13:54:24 | 000,000,048 | ---- | C] () -- C:\WINDOWS\FileNamesinQueue.ini
[2008/10/28 19:50:03 | 000,000,006 | ---- | C] () -- C:\WINDOWS\System32\mkghj.dll
[2008/09/30 21:02:58 | 000,001,784 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2008/09/09 19:52:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ATIMMC.INI
[2008/05/21 19:13:47 | 000,004,770 | ---- | C] () -- C:\WINDOWS\DNAPrinters.ini
[2008/02/20 20:46:14 | 000,005,728 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008/02/20 18:19:09 | 000,348,160 | R--- | C] () -- C:\WINDOWS\System32\lxdkcoin.dll
[2008/02/19 21:13:05 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/02/19 21:10:29 | 000,001,295 | ---- | C] () -- C:\WINDOWS\System32\Px.ini
[2008/02/19 19:33:36 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2008/02/04 19:23:10 | 000,693,792 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/06/06 03:25:45 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lxdkgrd.dll
[2007/05/22 12:22:21 | 000,692,224 | ---- | C] () -- C:\WINDOWS\System32\lxdkdrs.dll
[2007/05/22 05:10:00 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\lxdkcaps.dll
[2007/02/14 09:35:07 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\lxdkcnv4.dll
[2006/07/31 20:53:18 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxdkvs.dll
[2004/01/28 11:42:06 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[2004/01/28 11:42:06 | 000,013,601 | ---- | C] () -- C:\WINDOWS\System32\vctest.ini
[2003/12/02 15:44:25 | 000,000,890 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2003/12/02 15:41:26 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\Cpuinf32.dll
[2003/12/02 15:40:09 | 000,262,416 | ---- | C] () -- C:\WINDOWS\System32\ASFV2.DLL
[2003/12/02 15:39:35 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\TDI-SonyOMG.dll
[2003/12/02 15:01:22 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/12/01 20:53:24 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/12/01 20:39:54 | 000,000,800 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/12/01 19:28:51 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\e1000msg.dll
[2003/12/01 19:28:51 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2003/12/01 19:28:41 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\cbldrm.dll
[2003/12/01 19:28:40 | 000,000,730 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2002/10/15 17:54:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2002/06/12 15:21:12 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\winchip.dll
[2002/03/21 16:39:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\UNACEV2.DLL

========== Files - Unicode (All) ==========
[2010/06/13 15:12:18 | 009,586,449 | ---- | M] ()(C:\Documents and Settings\sepaulsen\My Documents\The Beginner's Guid? to Braiding.pdf) -- C:\Documents and Settings\sepaulsen\My Documents\The Beginner's Guidу to Braiding.pdf
[2010/06/13 15:12:17 | 009,586,449 | ---- | C] ()(C:\Documents and Settings\sepaulsen\My Documents\The Beginner's Guid? to Braiding.pdf) -- C:\Documents and Settings\sepaulsen\My Documents\The Beginner's Guidу to Braiding.pdf

========== Alternate Data Streams ==========

@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BDF08FAF
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >

OTL Extras logfile created on: 7/20/2010 2:20:25 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\sepaulsen\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 43.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 15.01 Gb Total Space | 2.41 Gb Free Space | 16.06% Space Free | Partition Type: NTFS
Drive D: | 129.03 Gb Total Space | 3.76 Gb Free Space | 2.91% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 298.09 Gb Total Space | 7.03 Gb Free Space | 2.36% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VALUED-B4B48255
Current User Name: sepaulsen
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"57816:TCP" = 57816:TCP:*:Enabled:PandoRest Listening Port

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\support.com\client\bin\tgcmd.exe" = C:\Program Files\support.com\client\bin\tgcmd.exe:*:Enabled:tgcmd Module -- File not found
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\WINDOWS\system32\lxdkcoms.exe" = C:\WINDOWS\system32\lxdkcoms.exe:*:Enabled:5300 Series Server -- ( )
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkpswx.exe:*:Enabled:Printer Status Window Interface -- ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdktime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdktime.exe:*:Enabled:Lexmark Connect Time Executable -- (Lexmark International, Inc.)
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkjswx.exe:*:Enabled:Job Status Window Interface -- ()
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)
"C:\Program Files\Palm\Hotsync.exe" = C:\Program Files\Palm\Hotsync.exe:*:Enabled:HotSync® Manager Application -- (PalmSource, Inc)
"C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe" = C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe:*:Enabled:PandoRest Application Name -- File not found
"C:\Program Files\Lexmark 5300 Series\lxdkmon.exe" = C:\Program Files\Lexmark 5300 Series\lxdkmon.exe:*:Enabled:Printer Device Monitor -- ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkwbgw.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkwbgw.exe:*:Enabled:Lexmark Web Gateway -- ()
"C:\Program Files\Lexmark 5300 Series\frun.exe" = C:\Program Files\Lexmark 5300 Series\frun.exe:*:Enabled:Printing Application -- ()
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java™ Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Documents and Settings\sepaulsen\Local Settings\Temp\7zS30.tmp\SymNRT.exe" = C:\Documents and Settings\sepaulsen\Local Settings\Temp\7zS30.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool -- File not found
"C:\Documents and Settings\sepaulsen\Local Settings\Temp\7zS26.tmp\SymNRT.exe" = C:\Documents and Settings\sepaulsen\Local Settings\Temp\7zS26.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool -- File not found
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Documents and Settings\sepaulsen\Local Settings\Application Data\asam.exe" = C:\Documents and Settings\sepaulsen\Local Settings\Application Data\asam.exe:*:Disabled:enable -- File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0DC00F90-E7E7-4B19-959A-0A53032DA52C}" = Documents To Go
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{159BC71B-93C9-4AE5-9299-DE16A2F296BF}" = Taber's Cyclopedic Medical Dictionary 20th edition
"{1604516D-063C-441A-A0BF-C7944A2C7549}" = Emergency Medicine Manual
"{1CBE3804-20DF-48DA-B048-895C206E80A5}" = Microsoft SQL Server VSS Writer
"{1EB317D8-8945-4FD6-B37F-DF470317C6AB}" = VAIO Media 2.6
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{2E8131B2-8DAF-41E2-B954-18FD5DEF0B54}" = BlackBerry Desktop Software 5.0.1
"{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B24B725-D81F-442D-8CE5-2AF05A4A4CC9}" = Music Visualizer Library 1.4.00
"{3CBA0E30-6F54-47EF-910E-1D4D450AFE45}" = ATI Multimedia Center
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40A594D0-1490-4979-9382-D2B764F949C6}" = BlackBerry® Media Sync
"{4D1D6640-CD43-4AD9-A52F-E48265DB28E0}" = VAIO BrightColor Wallpaper
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5FA1C51C-6E35-42C1-B2EC-DC9FA1E20694}" = OpenMG Secure Module 3.3.01
"{621FCD24-4498-4324-A81E-07D331376EDF}" = PixiePack Codec Pack
"{685BCC47-B8EC-45EC-BBCE-77DF2451502C}" = DVgate Plus
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6990A2BF-D1D2-11D3-81BC-00609789C908}" = Sony Video Shared Library
"{6DE13770-01B7-4366-8DA6-48237793F445}" = VoiceOver Kit
"{7128C69B-8F7E-4336-8698-3FD3CDD955EC}" = VAIO Media Redistribution 2.6
"{7148F0A8-6813-11D6-A77B-00B0D0142010}" = Java 2 Runtime Environment, SE v1.4.2_01
"{71883667-71F2-48A1-AB72-28D518D8AC4A}" = Seagate Manager Installer
"{71D6CE84-B7DC-4166-8E0D-56C1C37BFB5A}" = SonicStage
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A79D11B-FD82-4A5E-834F-20173515DD14}" = VAIO Media Integrated Server 2.6
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD 5 for VAIO
"{93B80FB1-7A23-11D3-B250-00105A1F4184}" =
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A20DF6AC-0300-45E2-8152-7D677E4E8CF5}" = HotFile AutoDownloader
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.3
"{B2D41883-3BFC-4BA0-A2F6-5A2C9836C238}" = ACDSee 9 Photo Manager
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BF251EAF-8697-4E89-BF09-C998F97BBC40}" = Microsoft SQL Server Native Client
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD7D5804-C157-48A6-AEE0-4A40A4B5C054}" = VAIO System Information
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0448678-1203-4158-A58F-B3D0B616BF9E}" = Sony Certificate PCH
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E68B38DE-D7DD-4FB3-A453-3F03A947EA8E}" = VAIO Help and Support
"{E9459BCF-0982-498B-ABA7-26C34323493F}" = Citrix Presentation Server Client - Web Only
"{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}" = ATI Catalyst Control Center
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F445476A-42DE-11D4-80D0-00C04F2750A6}" = Epocrates Essentials
"{FA11D5B5-7D0A-43E8-88C4-960F97B194DE}" = VAIO Survey Standalone
"{FA66D65A-6413-43AF-8F29-B22EFEC29869}" = Diagnosaurus
"{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}" = Palm Desktop by ACCESS
"3DGroove" = 3D Groove Playback Engine
"AC3Filter_is1" = AC3Filter 1.63b
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Agere Systems Soft Modem" = Agere Systems AC'97 Modem
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG9Uninstall" = AVG Free 9.0
"Bass Audio Decoder" = Bass Audio Decoder (remove only)
"BlackBerry_{2E8131B2-8DAF-41E2-B954-18FD5DEF0B54}" = BlackBerry Desktop Software 5.0.1
"CCleaner" = CCleaner
"CD Audio Reader Filter" = CD Audio Reader Filter (remove only)
"DC-Bass Source" = DC-Bass Source 1.1.1
"DCoder Image Source" = DCoder Image Source (remove only)
"Defraggler" = Defraggler
"DirectVobSub" = DirectVobSub (remove only)
"DjVu" = Lizardtech DjVu Control (autoinstall)
"DScaler 5 Mpeg Decoders_is1" = DScaler 5 Mpeg Decoders
"Easy Video Joiner_is1" = Easy Video Joiner 5.21
"Easy Video Splitter_is1" = Easy Video Splitter 1.28
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"Gabest MPEG Splitter" = Gabest MPEG Splitter (remove only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"InstallShield_{3CBA0E30-6F54-47EF-910E-1D4D450AFE45}" = ATI Multimedia Center 9.14
"InstallShield_{71883667-71F2-48A1-AB72-28D518D8AC4A}" = Seagate Manager Installer
"InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"InstallShield_{E68B38DE-D7DD-4FB3-A453-3F03A947EA8E}" = VAIO Help and Support
"InstallShield_{FA11D5B5-7D0A-43E8-88C4-960F97B194DE}" = VAIO Survey Standalone
"IsoBuster_is1" = IsoBuster 1.6
"Ivanko Super Gripper Suite_is1" = Ivanko Super Gripper Suite 2.2.7
"JDownloader" = JDownloader
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.7.5 (Full)
"LimeWire" = LimeWire 5.1.3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Merck Manual" = Merck Manual
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MONOGRAM AMR Splitter/Decoder" = MONOGRAM AMR Splitter/Decoder (remove only)
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Ahead Nero Burning ROM
"NeroVision!UninstallKey" = Ahead NeroVision Express
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"OpenSource DTS/AC3/DD+ Source Filter" = OpenSource DTS/AC3/DD+ Source Filter (remove only)
"OpenSource Flash Video Splitter" = OpenSource Flash Video Splitter (remove only)
"PROSet" = Intel® PRO Network Adapters and Drivers
"QuickSFV" = QuickSFV (Remove only)
"RealPlayer 6.0" = RealPlayer
"Recuva" = Recuva (remove only)
"Rhapsody" = Rhapsody
"SHOUTcast Source" = SHOUTcast Source (remove only)
"TurboCADLEProDeinstKey" = TurboCAD Learning Edition
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"VLC media player" = VLC media player 1.0.1
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"ZoomPlayer" = Zoom Player (remove only)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Reader for Palm OS" = Adobe Reader for Palm OS, 3.05
"Google Chrome" = Google Chrome
"Move Media Player" = Move Media Player
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/19/2010 5:05:17 AM | Computer Name = VALUED-B4B48255 | Source = ESENT | ID = 489
Description = wuauclt (2772) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 7/19/2010 5:05:17 AM | Computer Name = VALUED-B4B48255 | Source = ESENT | ID = 455
Description = wuaueng.dll (2772) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 7/19/2010 5:05:28 AM | Computer Name = VALUED-B4B48255 | Source = ESENT | ID = 489
Description = wuauclt (168) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 7/19/2010 5:05:28 AM | Computer Name = VALUED-B4B48255 | Source = ESENT | ID = 455
Description = wuaueng.dll (168) SUS20ClientDataStore: Error -1032 (0xfffffbf8) occurred
while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 7/19/2010 5:05:38 AM | Computer Name = VALUED-B4B48255 | Source = ESENT | ID = 489
Description = wuauclt (168) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 7/19/2010 5:05:38 AM | Computer Name = VALUED-B4B48255 | Source = ESENT | ID = 455
Description = wuaueng.dll (168) SUS20ClientDataStore: Error -1032 (0xfffffbf8) occurred
while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 7/19/2010 5:05:49 AM | Computer Name = VALUED-B4B48255 | Source = ESENT | ID = 489
Description = wuauclt (2400) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 7/19/2010 5:05:49 AM | Computer Name = VALUED-B4B48255 | Source = ESENT | ID = 455
Description = wuaueng.dll (2400) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

Error - 7/19/2010 5:05:59 AM | Computer Name = VALUED-B4B48255 | Source = ESENT | ID = 489
Description = wuauclt (2400) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 7/19/2010 5:05:59 AM | Computer Name = VALUED-B4B48255 | Source = ESENT | ID = 455
Description = wuaueng.dll (2400) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

[ System Events ]
Error - 7/17/2010 5:41:30 PM | Computer Name = VALUED-B4B48255 | Source = DCOM | ID = 10010
Description = The server {DC0C2640-1415-4644-875C-6F4D769839BA} did not register
with DCOM within the required timeout.

Error - 7/18/2010 11:52:43 AM | Computer Name = VALUED-B4B48255 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the cisvc service.

Error - 7/18/2010 12:33:00 PM | Computer Name = VALUED-B4B48255 | Source = W32Time | ID = 39452718
Description = The time service encountered an error and was forced to shut down.
The error was: 0x800706BB

Error - 7/18/2010 12:34:51 PM | Computer Name = VALUED-B4B48255 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdkCATSCustConnectService
service to connect.

Error - 7/18/2010 12:34:51 PM | Computer Name = VALUED-B4B48255 | Source = Service Control Manager | ID = 7000
Description = The lxdkCATSCustConnectService service failed to start due to the
following error: %%1053

Error - 7/18/2010 12:49:15 PM | Computer Name = VALUED-B4B48255 | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 7/18/2010 12:52:42 PM | Computer Name = VALUED-B4B48255 | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 7/18/2010 12:55:12 PM | Computer Name = VALUED-B4B48255 | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 7/18/2010 12:59:28 PM | Computer Name = VALUED-B4B48255 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the lxdkCATSCustConnectService
service to connect.

Error - 7/18/2010 12:59:28 PM | Computer Name = VALUED-B4B48255 | Source = Service Control Manager | ID = 7000
Description = The lxdkCATSCustConnectService service failed to start due to the
following error: %%1053


< End of report >
  • 0

#3
ldtate

ldtate

    Malware Expert

  • Expert
  • 1,874 posts
  • MVP
Please do the following:


  • Run MBRCheck.exe
  • Wait until you see the following line: Enter 'Y' and hit ENTER for more options, or 'N' to exit:
  • Please push the 'Y' key and then press Enter
  • When program ask you Enter your choice: enter (2) and press the Enter key
  • Now the program will ask you "Enter the physical disk number to fix (0-99, -1 to cancel):"
  • Enter 0 and press the Enter key.
  • The program will show Available MBR codes:, followed by a list of operating systems. Please enter 1 for Windows XP, and then press Enter.
  • The program will prompt for confirmation. Type 'YES' and hit Enter.
  • Left click on the title bar (where program name and path is written).
  • From menu chose Edit -> Select All
  • Hit the Enter key on your keyboard to copy selected text.
  • Paste that text into Notepad, save it to your desktop as "MBRCheck results.txt"
  • Restart your PC.
  • Post the text in "MBRCheck results.txt" here, please.

  • 0

#4
sepaulsen

sepaulsen

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
MBRCheck, version 1.1.1
© 2010, AD

\\.\C: --> \\.\PhysicalDrive0
\\.\D: --> \\.\PhysicalDrive0
\\.\G: --> \\.\PhysicalDrive1

Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black I
nternet)!
298 GB \\.\PhysicalDrive1 Error reading raw MBR!


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit: y

Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.

Enter your choice: 2

Enter the physical disk number to fix (0-99, -1 to cancel): 0
Available MBR codes:
[ 0] Default (Windows XP)
[ 1] Windows XP
[ 2] Windows Server 2003
[ 3] Windows Vista
[ 4] Windows 2008
[ 5] Windows 7
[-1] Cancel

Please select the MBR code to write to this drive: 1

Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue: YES
Successfully wrote new MBR code!
Please reboot your computer to complete the fix.


Done! Press ENTER to exit...
  • 0

#5
sepaulsen

sepaulsen

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
I didn't read the instructions well and ran it twice and it was the same both times.
  • 0

#6
ldtate

ldtate

    Malware Expert

  • Expert
  • 1,874 posts
  • MVP
Run MBRCheck.exe

At the prompt, enter Y and hit Enter
At the next prompt (Options), select 2 and hit Enter
At the "Enter the physical drive number to fix" option, select (0 ) and hit Enter
At the "Available MBR codes" prompt, select 1 and hit Enter
The program will prompt for confirmation. Type YES and hit Enter
A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop
Reboot your PC
Post the contents of the log
  • 0

#7
sepaulsen

sepaulsen

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Run MBRCheck.exe

At the prompt, enter Y and hit Enter
At the next prompt (Options), select 2 and hit Enter
At the "Enter the physical drive number to fix" option, select (0 ) and hit Enter
At the "Available MBR codes" prompt, select 1 and hit Enter
The program will prompt for confirmation. Type YES and hit Enter
A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop
Reboot your PC
Post the contents of the log


MBRCheck, version 1.1.1

© 2010, AD



\\.\C: --> \\.\PhysicalDrive0

\\.\D: --> \\.\PhysicalDrive0

\\.\G: --> \\.\PhysicalDrive1



Size Device Name MBR Status

--------------------------------------------

149 GB \\.\PhysicalDrive0 Windows XP MBR code detected

298 GB \\.\PhysicalDrive1 Error reading raw MBR!





Done! Press ENTER to exit...

This is what came up, I never got any of the other options

Attached Files


  • 0

#8
ldtate

ldtate

    Malware Expert

  • Expert
  • 1,874 posts
  • MVP
Great. We removed the MBR infection.

We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
[/list]If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    Posted Image
  • When the scan is complete, click OK, then Show Results to view the results.
  • Posted Image
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
  • 0

#9
sepaulsen

sepaulsen

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
I am running malware now. I have run it several times with negative results. Since the MBR check scan the computer does seem to be running better and I checked task manager and do see any sign that IE is running and the volume hasn't been turned down. I will post the Malware bites scan when it is done.
  • 0

#10
ldtate

ldtate

    Malware Expert

  • Expert
  • 1,874 posts
  • MVP

I am running malware now. I have run it several times with negative results. Since the MBR check scan the computer does seem to be running better and I checked task manager and do see any sign that IE is running and the volume hasn't been turned down. I will post the Malware bites scan when it is done.

I just want to be sure nothing else is bad.
I think you're good to go, but wait until I give you the all clear.
  • 0

#11
sepaulsen

sepaulsen

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Scan type: Quick scan
Objects scanned: 134446
Time elapsed: 8 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

#12
ldtate

ldtate

    Malware Expert

  • Expert
  • 1,874 posts
  • MVP
To be on the safe side, I would also change all my passwords.


Here's my usual all clean post

Log looks good :)


This infection appears to have been cleaned, but as the malware could be configured to run any program a remote attacker requires, it's impossible to be 100% sure that any machine is clean.


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:[list=1]
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.

  • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

Only run one Anti-Virus and Firewall program.


I would suggest you read:
PC Safety and Security--What Do I Need?.
How to Prevent Malware:
  • 0

#13
sepaulsen

sepaulsen

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
I am running AVG 9, I will make explorer more secure but I usually run firefox. I am running windows firewall and have updated everything. The one additional thing I noticed was that there was an additional user account that I did not add that was "password" protected. I deleted the account after the the first MBR scan you had me do. It was for ae something .net. Thanks for the help. I can usually muddle through and find the infection and fix it. But this one defied everything I tried and read.
  • 0

#14
ldtate

ldtate

    Malware Expert

  • Expert
  • 1,874 posts
  • MVP
The MBR infection you had is something new within the last few weeks that we are seeing on the forums.

You're more than welcome.
Glad we were able to help

Peace be with you :)
  • 0

#15
ldtate

ldtate

    Malware Expert

  • Expert
  • 1,874 posts
  • MVP
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP