Author Topic: OS question, and Download error.  (Read 1316 times)

Offline jony

  • Full Member
  • ***
  • Posts: 188
  • Karma: +0/-0
    • View Profile
    • http://forgehub.com
OS question, and Download error.
« on: February 28, 2011, 06:17:38 PM »
Ok so when ever i go to download any type of Software, I get this error telling me that my windows installer is not working right.


Ive tried almost everything to fix this. My question is, if i upgrade from XP ( yes i still use xp...) to 7, will this problem go away or is it going to tell me once again that my windows installer can not install an OS upgrade?


( also i dont know much about computers ) >.<
« Last Edit: February 28, 2011, 06:18:07 PM by jony »

:(


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
OS question, and Download error.
« Reply #1 on: February 28, 2011, 06:29:46 PM »
Let's take a closer look please
Download [color="#FF0000"]OTL.exe[/color][/url] by OldTimer to your Desktop.
  • Close all windows and double click on OTL.exe to run it
  • Click Run Scan and let the program run uninterrupted.
  • It will produce two logs for you, one will pop up - OTL.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline jony

  • Full Member
  • ***
  • Posts: 188
  • Karma: +0/-0
    • View Profile
    • http://forgehub.com
OS question, and Download error.
« Reply #2 on: February 28, 2011, 06:47:09 PM »
OTL logfile created on: 2/28/2011 3:42:20 PM - Run 1
OTL by OldTimer - Version 3.2.22.2    Folder = C:\Documents and Settings\Jonathon\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 166.90 Gb Free Space | 35.84% Space Free | Partition Type: NTFS
 
Computer Name: JONATHONB | User Name: Jonathon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011/02/28 15:42:17 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
PRC - [2010/12/28 01:15:04 | 000,396,152 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2010/08/05 07:46:02 | 000,583,640 | ---- | M] (PC Tools) -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
PRC - [2010/06/08 07:09:33 | 000,681,312 | ---- | M] (MyNetUniverse Inc.) -- C:\Program Files\MyShoppingGenie\mnumsg.exe
PRC - [2010/01/15 04:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/11/23 15:53:58 | 004,781,352 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\WTouch\WTouchUser.exe
PRC - [2009/11/23 15:53:58 | 000,113,448 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\WTouch\WTouchService.exe
PRC - [2009/11/23 15:53:56 | 004,497,704 | ---- | M] (Wacom Technology, Corp.) -- C:\WINDOWS\system32\Pen_Tablet.exe
PRC - [2009/02/02 08:46:42 | 000,115,560 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2009/02/02 08:46:42 | 000,108,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2009/02/02 08:46:40 | 001,795,400 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
PRC - [2009/02/02 08:46:40 | 001,443,144 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
PRC - [2009/02/02 08:46:38 | 002,440,120 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
PRC - [2009/01/08 05:44:06 | 000,070,936 | ---- | M] (Octoshape ApS) -- C:\Documents and Settings\Jonathon\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
PRC - [2008/11/09 12:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/13 20:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/11/15 09:09:56 | 000,059,920 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\SetPoint\LBTWiz.exe
PRC - [2007/11/15 09:09:42 | 000,121,360 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2011/02/28 15:42:17 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
MOD - [2008/04/13 20:42:52 | 001,054,208 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [Auto | Stopped] --  -- (Viewpoint Manager Service)
SRV - File not found [Auto | Stopped] --  -- (ResultBrowse Service)
SRV - File not found [Auto | Stopped] --  -- (QuestBrowse Service)
SRV - [2010/08/05 07:46:02 | 000,583,640 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2010/04/24 22:04:55 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/15 10:50:36 | 001,142,224 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2010/03/11 10:09:22 | 000,366,840 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/01/25 10:00:54 | 000,067,360 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2010/01/22 08:56:24 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Stopped] -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2010/01/15 04:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/11/23 15:53:58 | 000,113,448 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\WTouch\WTouchService.exe -- (WTouchService)
SRV - [2009/11/23 15:53:56 | 004,497,704 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\WINDOWS\system32\Pen_Tablet.exe -- (TabletServicePen)
SRV - [2009/08/30 11:17:30 | 003,407,412 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2009/02/02 08:46:42 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2009/02/02 08:46:42 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2009/02/02 08:46:40 | 001,795,400 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService)
SRV - [2009/02/02 08:46:40 | 000,320,840 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC)
SRV - [2009/02/02 08:46:38 | 002,440,120 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2008/11/09 12:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2007/11/15 09:09:42 | 000,121,360 | ---- | M] (Logitech, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2007/08/11 20:05:27 | 003,093,872 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011/01/21 20:40:40 | 000,031,616 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vrtaucbl.sys -- (EuMusDesignVirtualAudioCableWdm) Virtual Audio Cable (WDM)
DRV - [2010/12/17 01:00:00 | 001,360,760 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110227.003\NAVEX15.SYS -- (NAVEX15)
DRV - [2010/12/17 01:00:00 | 000,086,008 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110227.003\NAVENG.SYS -- (NAVENG)
DRV - [2010/09/10 22:32:20 | 000,167,936 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WpsHelper.sys -- (WpsHelper)
DRV - [2010/05/27 00:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010/05/27 00:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/03/29 09:06:14 | 000,218,592 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2009/08/27 14:06:32 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV - [2009/06/29 21:42:00 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2009/05/20 10:54:06 | 000,013,736 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacomvhid.sys -- (wacomvhid)
DRV - [2009/03/28 11:01:08 | 000,123,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2009/03/27 13:23:12 | 000,023,064 | ---- | M] (Screaming Bee LLC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ScreamingBAudio.sys -- (SCREAMINGBDRIVER)
DRV - [2009/02/02 08:46:44 | 000,042,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\WPSDRVnt.sys -- (WPS)
DRV - [2009/02/02 08:46:42 | 000,319,664 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2009/02/02 08:46:42 | 000,279,600 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)
DRV - [2009/02/02 08:46:42 | 000,043,824 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2009/02/02 08:46:40 | 000,092,488 | ---- | M] (Symantec Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys -- (SysPlant)
DRV - [2009/02/02 08:46:40 | 000,049,536 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Teefer2.sys -- (Teefer2)
DRV - [2009/02/02 08:46:36 | 000,191,536 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2009/02/02 08:46:36 | 000,027,696 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2009/02/02 08:46:34 | 000,420,400 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2009/02/02 08:46:34 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon)
DRV - [2008/07/03 01:03:14 | 004,745,216 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/02/20 13:47:36 | 000,162,824 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\FTT3.sys -- (FTT3)
DRV - [2008/01/03 06:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007/10/11 17:40:12 | 000,009,096 | R--- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\amdide.sys -- (amdide)
DRV - [2007/09/21 02:10:54 | 000,078,992 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2007/09/21 02:10:46 | 000,036,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2007/09/21 02:10:40 | 000,035,088 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007/09/21 02:10:26 | 000,063,120 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L8042mou.Sys -- (L8042mou)
DRV - [2007/09/21 02:10:20 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2007/04/16 16:46:34 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2007/02/16 10:12:36 | 000,011,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacommousefilter.sys -- (wacommousefilter)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} -  File not found
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2786678
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} -  File not found
IE - HKCU\..\URLSearchHook: {73f3dd36-3464-4aa4-a815-de51290fb05e} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaultthis.engineName: "Conduit Engine Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Conduit Engine Customized Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=&SearchSource=13"
FF - prefs.js..extensions.enabledItems: [email protected]:3.5.1.110
FF - prefs.js..extensions.enabledItems: [email protected]:4.0.21.0
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0
FF - prefs.js..extensions.enabledItems: [email protected]:4.5
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.071301000019
FF - prefs.js..extensions.enabledItems: {2224E955-00E9-4613-A844-CE69FCCAAE91}:3.6.0.4470
FF - prefs.js..extensions.enabledItems: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}:2.1.0
FF - prefs.js..extensions.enabledItems: {0CDC78A2-05A1-47F9-8810-A36BA7576D00}:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.14908
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1
FF - prefs.js..extensions.enabledItems: {D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}:1.0
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=BABTDF&PC=BBLN&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{2224E955-00E9-4613-A844-CE69FCCAAE91}: C:\Program Files\Internet Saving Optimizer\3.6.0.4470\FF [2009/08/03 11:49:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/06/17 14:21:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\MSN Toolbar\Platform\4.0.0417.0\Firefox [2010/10/09 16:00:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/10/09 16:01:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/26 21:37:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/27 13:36:00 | 000,000,000 | ---D | M]
 
[2009/04/30 14:29:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Extensions
[2011/02/27 22:00:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions
[2010/04/07 15:42:15 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010/05/11 18:14:21 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/28 01:15:04 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2009/07/16 23:33:11 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
[2010/12/28 01:15:06 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
[2009/06/04 14:21:28 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
[2010/03/04 16:01:07 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
[2010/02/04 16:45:40 | 000,002,254 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\askcom.xml
[2010/10/28 12:43:34 | 000,001,840 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\bing.xml
[2010/12/28 01:15:06 | 000,000,913 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\conduit.xml
[2010/04/11 20:36:02 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\winamp-search.xml
[2011/02/27 22:00:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/10/20 20:18:39 | 000,000,000 | ---D | M] (ResultBrowse) -- C:\Program Files\Mozilla Firefox\extensions\{0CDC78A2-05A1-47F9-8810-A36BA7576D00}
[2011/01/29 10:35:20 | 000,000,000 | ---D | M] (QuestBrowse) -- C:\Program Files\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}
[2011/02/27 20:11:14 | 000,000,000 | ---D | M] (The Browser Highlighter) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2010/12/27 23:33:13 | 000,000,000 | ---D | M] (Gamevance TextLinks) -- C:\DOCUMENTS AND SETTINGS\JONATHON\APPLICATION DATA\MOZILLA\EXTENSIONS\{EC8030F7-C20A-464F-9B0E-13A3A9E97384}\[email protected]
[2010/06/17 14:21:58 | 000,000,000 | ---D | M] (HP Smart Web Printing) -- C:\PROGRAM FILES\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON3
[2009/08/03 11:49:28 | 000,000,000 | ---D | M] ("NP Helper Class") -- C:\PROGRAM FILES\INTERNET SAVING OPTIMIZER\3.6.0.4470\FF
[2010/10/20 20:15:49 | 000,000,000 | ---D | M] (PriceGong) -- C:\PROGRAM FILES\PRICEGONG\2.1.0\FF
[2010/12/09 02:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
 
O1 HOSTS File: ([2007/08/10 22:58:33 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: 127.0.0.1  mpa.one.microsoft.com
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (PriceGongBHO Class) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.1.0\PriceGongIE.dll (PriceGong)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} -  File not found
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Recording Engineer Helper Toolbar) - {73f3dd36-3464-4aa4-a815-de51290fb05e} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O2 - BHO: (System Search Dispatcher) - {CDBFB47B-58A8-4111-BF95-06178DCE326D} -  File not found
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Recording Engineer Helper Toolbar) - {73f3dd36-3464-4aa4-a815-de51290fb05e} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} -  File not found
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Recording Engineer Helper Toolbar) - {73F3DD36-3464-4AA4-A815-DE51290FB05E} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Recording Engineer Helper Toolbar) - {73F3DD36-3464-4AA4-A815-DE51290FB05E} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Bluetooth Connection Assistant]  File not found
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [fsm]  File not found
O4 - HKCU..\Run: [mnumsg.exe] C:\Program Files\MyShoppingGenie\mnumsg.exe (MyNetUniverse Inc.)
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Documents and Settings\Jonathon\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKCU..\Run: [RayV] C:\Program Files\RayV\RayV\RayV.exe (RayV)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Jonathon\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jonathon\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/08 16:27:48 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{2e4fe6e8-b3a6-11de-a4f1-00218514b984}\Shell\AutoRun\command - "" = E:\system\viewer\FlipVideoforPC.exe
O33 - MountPoints2\{2e4fe6e8-b3a6-11de-a4f1-00218514b984}\Shell\Flip Video for PC\command - "" = E:\system\viewer\FlipVideoforPC.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011/02/28 15:41:41 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
[2011/02/28 15:11:48 | 008,669,472 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Jonathon\Desktop\Windows7UpgradeAdvisorSetup.exe
[2011/02/27 13:53:34 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAudio2_6.dll
[2011/02/27 13:53:34 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\XAPOFX1_4.dll
[2011/02/27 13:53:33 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine3_6.dll
[2011/02/27 13:53:33 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\X3DAudio1_7.dll
[2011/02/18 10:27:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jonathon\Desktop\Prat-3.0-3.4.15
[2011/02/13 20:52:52 | 008,582,536 | ---- | C] (Mozilla) -- C:\Documents and Settings\Jonathon\Desktop\Firefox Setup 3.6.13.exe
[2011/02/12 16:53:39 | 004,584,688 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Jonathon\Desktop\WindowsServer2003-KB898715-x64-enu.exe
[2011/02/12 16:53:22 | 005,960,944 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Jonathon\Desktop\WindowsServer2003-KB898715-ia64-enu.exe
[2011/02/12 16:51:20 | 002,585,872 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Jonathon\Desktop\WindowsInstaller-KB893803-v2-x86.exe
[2011/02/07 16:41:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jonathon\Desktop\Logs
[2010/12/31 21:24:24 | 000,883,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files\JavaSetup6u23.exe
[2010/12/31 21:05:48 | 000,883,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files\jre-6u23-windows-i586-iftw-k.exe
[2010/12/12 21:21:08 | 006,274,424 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Silverlight.exe
[2010/12/03 16:08:27 | 002,728,440 | ---- | C] (Microsoft Corporation) -- C:\Program Files\vcsetup.exe
[2010/12/03 15:40:19 | 003,324,232 | ---- | C] (Microsoft Corporation) -- C:\Program Files\vc_web.exe
[2004/01/12 00:00:00 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msvcr71.dll
[6 C:\Documents and Settings\Jonathon\My Documents\*.tmp files -> C:\Documents and Settings\Jonathon\My Documents\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011/02/28 15:42:17 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
[2011/02/28 15:11:57 | 008,669,472 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Jonathon\Desktop\Windows7UpgradeAdvisorSetup.exe
[2011/02/28 15:09:00 | 000,000,890 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/28 15:09:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/28 15:01:00 | 000,000,240 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/02/28 11:56:03 | 000,000,458 | ---- | M] () -- C:\WINDOWS\tasks\RMSmartUpdate.job
[2011/02/28 07:47:05 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/28 07:45:12 | 000,200,819 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011/02/28 07:44:11 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/27 22:30:29 | 000,096,968 | ---- | M] () -- C:\Documents and Settings\Jonathon\Desktop\WauQuickStart.exe
[2011/02/27 19:01:39 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\RMSchedule.job
[2011/02/27 17:41:51 | 000,000,476 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Jonathon.job
[2011/02/27 14:19:28 | 002,585,872 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Jonathon\Desktop\WindowsInstaller-KB893803-v2-x86.exe
[2011/02/27 13:57:16 | 000,000,223 | RHS- | M] () -- C:\boot.ini
[2011/02/27 13:40:23 | 000,000,215 | ---- | M] () -- C:\Documents and Settings\Jonathon\Desktop\Magicka.url
[2011/02/26 14:17:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/02/18 10:27:45 | 001,402,518 | ---- | M] () -- C:\Documents and Settings\Jonathon\Desktop\Prat-3.0-3.4.15.zip
[2011/02/14 22:08:43 | 000,013,486 | ---- | M] () -- C:\WINDOWS\System32\Pen_Tablet.dat
[2011/02/13 20:54:55 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/13 20:54:55 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/13 20:53:42 | 008,582,536 | ---- | M] (Mozilla) -- C:\Documents and Settings\Jonathon\Desktop\Firefox Setup 3.6.13.exe
[2011/02/12 16:53:43 | 004,584,688 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Jonathon\Desktop\WindowsServer2003-KB898715-x64-enu.exe
[2011/02/12 16:53:27 | 005,960,944 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Jonathon\Desktop\WindowsServer2003-KB898715-ia64-enu.exe
[2011/02/12 08:09:12 | 000,456,304 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/02/12 08:09:12 | 000,075,210 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/02/04 20:24:20 | 000,883,488 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\Jonathon\Desktop\jre-6u23-windows-i586-iftw-k.exe
[6 C:\Documents and Settings\Jonathon\My Documents\*.tmp files -> C:\Documents and Settings\Jonathon\My Documents\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011/02/27 22:29:55 | 000,096,968 | ---- | C] () -- C:\Documents and Settings\Jonathon\Desktop\WauQuickStart.exe
[2011/02/27 13:40:23 | 000,000,215 | ---- | C] () -- C:\Documents and Settings\Jonathon\Desktop\Magicka.url
[2011/02/18 10:27:43 | 001,402,518 | ---- | C] () -- C:\Documents and Settings\Jonathon\Desktop\Prat-3.0-3.4.15.zip
[2011/02/13 20:54:55 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/01/29 10:33:01 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/01/29 10:33:01 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/01/21 20:40:53 | 000,031,616 | ---- | C] () -- C:\WINDOWS\System32\drivers\vrtaucbl.sys
[2010/12/31 23:08:16 | 000,835,440 | ---- | C] () -- C:\Program Files\pbsvc.exe
[2010/12/31 22:53:25 | 002,434,856 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_bc2.exe
[2010/12/27 23:34:47 | 005,430,783 | ---- | C] () -- C:\Program Files\WMV r506 32bit DEVWORK.rar
[2010/12/24 00:00:04 | 001,661,959 | ---- | C] () -- C:\Program Files\wowmodelview0.5.07.zip
[2010/12/10 21:13:05 | 001,985,823 | ---- | C] () -- C:\Program Files\AtlasLoot-v6.01.01.zip
[2010/12/07 18:29:56 | 000,001,456 | ---- | C] () -- C:\Documents and Settings\Jonathon\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs
[2010/12/04 14:55:53 | 000,022,222 | ---- | C] () -- C:\Program Files\souper3.zip
[2010/12/04 11:39:28 | 000,980,215 | ---- | C] () -- C:\Program Files\msvcdll-90.zip
[2010/12/04 11:36:56 | 007,683,072 | ---- | C] () -- C:\Program Files\WMV_Installer_v0701_r500_Win64.msi
[2010/12/04 11:33:47 | 000,000,000 | ---- | C] () -- C:\Program Files\wowmodelview-0.5.06beta.zip
[2010/12/03 16:37:20 | 005,928,476 | ---- | C] () -- C:\Program Files\WMV_Binary_v0701_r490_Win32_DevWork.zip
[2010/12/03 16:25:15 | 003,728,716 | ---- | C] () -- C:\Program Files\WoWModelViewer_0.6.0.3_Win32_Release.zip
[2010/12/03 16:10:54 | 005,167,176 | ---- | C] () -- C:\Program Files\WoW-2.4.0.8089-to-2.4.1.8125-enUS-patch.exe
[2010/12/03 15:36:37 | 007,091,330 | ---- | C] () -- C:\Program Files\WoWModelViewer_0.6.0.1_Win32_Debug.zip
[2010/10/10 00:56:26 | 000,037,336 | ---- | C] () -- C:\WINDOWS\System32\CleanMFT32.exe
[2010/08/16 08:54:25 | 000,013,486 | ---- | C] () -- C:\WINDOWS\System32\Pen_Tablet.dat
[2010/08/03 15:54:23 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Jonathon\Application Data\Adobe PNG Format CS5 Prefs
[2010/06/17 19:29:26 | 000,193,751 | ---- | C] () -- C:\WINDOWS\hpoins41.dat.temp
[2010/06/17 19:29:26 | 000,001,253 | ---- | C] () -- C:\WINDOWS\hpomdl41.dat.temp
[2010/06/17 14:13:10 | 000,193,751 | ---- | C] () -- C:\WINDOWS\hpoins41.dat
[2010/06/17 14:13:10 | 000,001,253 | ---- | C] () -- C:\WINDOWS\hpomdl41.dat
[2010/05/16 06:44:30 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
[2009/10/10 20:51:36 | 000,058,004 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/10/08 16:28:11 | 000,017,920 | ---- | C] () -- C:\Documents and Settings\Jonathon\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/10 15:48:01 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/04/30 14:29:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/04/27 20:49:35 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/04/27 20:05:16 | 000,000,760 | ---- | C] () -- C:\Documents and Settings\Jonathon\Application Data\setup_ldm.iss
[2009/03/12 20:02:45 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/03/12 20:00:08 | 003,767,296 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/12 13:55:32 | 000,138,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/12 13:55:32 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Jonathon\Application Data\PnkBstrK.sys
[2009/03/12 13:55:13 | 000,835,440 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2009/03/12 13:55:13 | 000,270,904 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2009/03/12 13:55:13 | 000,075,136 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2009/03/12 13:32:45 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2009/03/12 13:18:21 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/03/12 13:14:03 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/01/13 14:22:56 | 002,163,200 | ---- | C] () -- C:\Program Files\WoWModelViewer.exe
[2009/01/12 12:19:56 | 000,288,056 | ---- | C] () -- C:\Program Files\logo.bmp
[2008/11/03 01:27:22 | 000,245,760 | ---- | C] () -- C:\Program Files\glew32.dll
[2008/10/06 21:33:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/10/06 21:33:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2008/10/06 21:33:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/10/06 21:33:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2008/10/06 21:33:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/10/06 21:33:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/10/06 21:33:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2008/10/06 21:33:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2008/10/06 21:33:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/06/05 08:58:26 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/13 20:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2006/12/30 22:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001/08/23 03:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 03:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 03:00:00 | 000,456,304 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 03:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 03:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 03:00:00 | 000,075,210 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 03:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 03:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 03:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 03:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24051EFF
@Alternate Data Stream - 495 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63238B95
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >







OTL Extras logfile created on: 2/28/2011 3:42:20 PM - Run 1
OTL by OldTimer - Version 3.2.22.2    Folder = C:\Documents and Settings\Jonathon\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 166.90 Gb Free Space | 35.84% Space Free | Partition Type: NTFS
 
Computer Name: JONATHONB | User Name: Jonathon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"427:TCP" = 427:TCP:LocalSubNet:Enabled:SLP_Port(427)_TCP
"427:UDP" = 427:UDP:LocalSubNet:Enabled:SLP_Port(427)_UDP
"56718:TCP" = 56718:TCP:*:Enabled:Pando Media Booster
"56718:UDP" = 56718:UDP:*:Enabled:Pando Media Booster
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
"6112:TCP" = 6112:TCP:*:Enabled:blizzard Downloader
"427:TCP" = 427:TCP:LocalSubNet:Enabled:SLP_Port(427)_TCP
"427:UDP" = 427:UDP:LocalSubNet:Enabled:SLP_Port(427)_UDP
"56718:TCP" = 56718:TCP:*:Enabled:Pando Media Booster
"56718:UDP" = 56718:UDP:*:Enabled:Pando Media Booster
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"D:\setup\hpznui01.exe" = D:\setup\hpznui01.exe:*:Enabled:hpznui01.exe
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe -- ()
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe -- (Hewlett-Packard)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe -- (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe -- (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe -- (Hewlett-Packard Co.)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe" = C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe:*:Enabled:SMC Service -- (Symantec Corporation)
"C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE" = C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE:*:Enabled:SNAC Service -- (Symantec Corporation)
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = C:\Program Files\Common Files\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email -- (Symantec Corporation)
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe -- (Flagship Industries, Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager
"C:\Program Files\World of Warcraft Public Test\WoW-0.2.0-enUS-downloader.exe" = C:\Program Files\World of Warcraft Public Test\WoW-0.2.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe" = C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader
"C:\Program Files\World of Warcraft Public Test\WoW-0.2.0.10147-to-0.2.0.10170-enUS-downloader.exe" = C:\Program Files\World of Warcraft Public Test\WoW-0.2.0.10147-to-0.2.0.10170-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft Public Test\WoW-0.2.0.10170-to-0.2.0.10179-enUS-downloader.exe" = C:\Program Files\World of Warcraft Public Test\WoW-0.2.0.10170-to-0.2.0.10179-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft Public Test\Launcher.exe" = C:\Program Files\World of Warcraft Public Test\Launcher.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft Public Test\WoW-0.2.0.10179-to-0.2.0.10192-enUS-downloader.exe" = C:\Program Files\World of Warcraft Public Test\WoW-0.2.0.10179-to-0.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\Steam\steamapps\kazooy\team fortress 2\hl2.exe" = C:\Program Files\Steam\steamapps\kazooy\team fortress 2\hl2.exe:*:Enabled:hl2 -- ()
"C:\Program Files\World of Warcraft Public Test\WoW-0.2.2.10257-enUS-ptr-downloader.exe" = C:\Program Files\World of Warcraft Public Test\WoW-0.2.2.10257-enUS-ptr-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\RayV\RayV\RayV.exe" = C:\Program Files\RayV\RayV\RayV.exe:*:Enabled:RayV -- (RayV)
"C:\Program Files\RayV\RayV\RayV.dll" = C:\Program Files\RayV\RayV\RayV.dll:*:Enabled:RayV -- (RayV)
"C:\Program Files\World of Warcraft Public Test\WoW-0.2.2.10357-to-0.2.2.10371-enUS-ptr-downloader.exe" = C:\Program Files\World of Warcraft Public Test\WoW-0.2.2.10357-to-0.2.2.10371-enUS-ptr-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe:*:Enabled:Blizzard Downloader -- (Blizzard Entertainment)
"C:\Program Files\World of Warcraft Public Test\WoW-0.2.2.10371-to-0.2.2.10392-enUS-ptr-downloader.exe" = C:\Program Files\World of Warcraft Public Test\WoW-0.2.2.10371-to-0.2.2.10392-enUS-ptr-downloader.exe:*:Enabled:Blizzard Downlo

:(


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
OS question, and Download error.
« Reply #3 on: February 28, 2011, 08:09:58 PM »
Quote
Ok so when ever i go to download any type of Software, I get this error telling me that my windows installer is not working right.

Do you have an EXACT error message please

Also, not that all are bad, I just need to know what you purposely installed, and may or may not need

Out of the following:
Internet Saving Optimizer
System Search Dispatcher
MyShoppingGenie
DTVblizzcon
Recording_Engineer_Helper Toolbar
ResultBrowse 1.0 build 117
Software Informer 1.0 BETA
Viewpoint Media Player
Winwonk OpenTarget
Winamp Toolbar
Yahoo! Toolbar
Google Toolbar for Internet Explorer


Take a look at that list, out of those, which did you purposely install?
I added in the last 3 toolbars, nothing bad, but did you purposely install them?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline jony

  • Full Member
  • ***
  • Posts: 188
  • Karma: +0/-0
    • View Profile
    • http://forgehub.com
OS question, and Download error.
« Reply #4 on: February 28, 2011, 09:12:31 PM »
The Windows Installer Service could not be accessed. This can occur if the Windows Installer is not correctly installed. Contact your support personnel for assistance.


Internet Saving Optimizer  Cant remember
System Search Dispatcher  no idea
MyShoppingGenie Uninstalling right now...
DTVblizzcon For Blizzcon live stream
Recording_Engineer_Helper Toolbar No idea again
ResultBrowse 1.0 build 117 No idea
Software Informer 1.0 BETA  No idea
Viewpoint Media Player No idea
Winwonk OpenTarget No idea
Winamp Toolbar Just came with Winamp
Yahoo! Toolbar No idea
Google Toolbar for Internet Explorer No idea.


Most of these im just going to go ahead and uninstall because they have no use to me.

:(


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
OS question, and Download error.
« Reply #5 on: February 28, 2011, 09:24:27 PM »
Ok, good then, can you first save these instructions to a notepad file on desktop, then can you go ahead, close down ALL Browser windows
Including this one
Uninstall any/All of those from the forementioned

Internet Saving Optimizer Cant remember
System Search Dispatcher no idea
MyShoppingGenie Uninstalling right now...
DTVblizzcon For Blizzcon live stream
Recording_Engineer_Helper Toolbar No idea again
ResultBrowse 1.0 build 117 No idea
Software Informer 1.0 BETA No idea
Viewpoint Media Player No idea
Winwonk OpenTarget No idea
Winamp Toolbar Just came with Winamp
Yahoo! Toolbar No idea
Google Toolbar for Internet Explorer No idea.

Reboot the computer
Back in Windows

Do the following please
Reopen OTL.exe, run a Quick Scan, post the new log that opens, then we'll see if we can fix that error for you

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline jony

  • Full Member
  • ***
  • Posts: 188
  • Karma: +0/-0
    • View Profile
    • http://forgehub.com
OS question, and Download error.
« Reply #6 on: February 28, 2011, 10:39:44 PM »
Also ive noticed that i cant uninstall some programs that use the Windows installer.





-------------------------------------------------------------------------------
OTL logfile created on: 2/28/2011 7:34:49 PM - Run 1
OTL by OldTimer - Version 3.2.22.2    Folder = C:\Documents and Settings\Jonathon\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 78.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 166.14 Gb Free Space | 35.67% Space Free | Partition Type: NTFS

Computer Name: JONATHONB | User Name: Jonathon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

[color="#e56717"]========== Processes (SafeList) ==========[/color]

PRC - [2011/02/28 15:42:17 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
PRC - [2010/12/28 01:15:04 | 000,396,152 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2010/12/05 13:43:48 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2010/08/05 07:46:02 | 000,583,640 | ---- | M] (PC Tools) -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
PRC - [2010/01/15 04:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/11/23 15:53:58 | 004,781,352 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\WTouch\WTouchUser.exe
PRC - [2009/11/23 15:53:58 | 000,113,448 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\WTouch\WTouchService.exe
PRC - [2009/11/23 15:53:56 | 004,497,704 | ---- | M] (Wacom Technology, Corp.) -- C:\WINDOWS\system32\Pen_Tablet.exe
PRC - [2009/02/02 08:46:42 | 000,115,560 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2009/02/02 08:46:42 | 000,108,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2009/02/02 08:46:40 | 001,795,400 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
PRC - [2009/02/02 08:46:40 | 001,443,144 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
PRC - [2009/02/02 08:46:38 | 002,440,120 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
PRC - [2008/11/09 12:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/13 20:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/11/15 09:09:56 | 000,059,920 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\SetPoint\LBTWiz.exe
PRC - [2007/11/15 09:09:42 | 000,121,360 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe


[color="#e56717"]========== Modules (SafeList) ==========[/color]

MOD - [2011/02/28 15:42:17 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
MOD - [2008/04/13 20:42:52 | 001,054,208 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll


[color="#e56717"]========== Win32 Services (SafeList) ==========[/color]

SRV - File not found [Auto | Stopped] --  -- (Viewpoint Manager Service)
SRV - File not found [Auto | Stopped] --  -- (ResultBrowse Service)
SRV - File not found [Auto | Stopped] --  -- (QuestBrowse Service)
SRV - [2010/08/05 07:46:02 | 000,583,640 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2010/04/24 22:04:55 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/15 10:50:36 | 001,142,224 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2010/03/11 10:09:22 | 000,366,840 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/01/25 10:00:54 | 000,067,360 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus®
SRV - [2010/01/22 08:56:24 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Stopped] -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2010/01/15 04:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/11/23 15:53:58 | 000,113,448 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\WTouch\WTouchService.exe -- (WTouchService)
SRV - [2009/11/23 15:53:56 | 004,497,704 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\WINDOWS\system32\Pen_Tablet.exe -- (TabletServicePen)
SRV - [2009/08/30 11:17:30 | 003,407,412 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2009/02/02 08:46:42 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2009/02/02 08:46:42 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2009/02/02 08:46:40 | 001,795,400 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService)
SRV - [2009/02/02 08:46:40 | 000,320,840 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC)
SRV - [2009/02/02 08:46:38 | 002,440,120 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2008/11/09 12:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2007/11/15 09:09:42 | 000,121,360 | ---- | M] (Logitech, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2007/08/11 20:05:27 | 003,093,872 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)


[color="#e56717"]========== Driver Services (SafeList) ==========[/color]

DRV - [2011/01/21 20:40:40 | 000,031,616 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vrtaucbl.sys -- (EuMusDesignVirtualAudioCableWdm) Virtual Audio Cable (WDM)
DRV - [2010/12/17 01:00:00 | 001,360,760 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110228.024\NAVEX15.SYS -- (NAVEX15)
DRV - [2010/12/17 01:00:00 | 000,086,008 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110228.024\NAVENG.SYS -- (NAVENG)
DRV - [2010/09/10 22:32:20 | 000,167,936 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WpsHelper.sys -- (WpsHelper)
DRV - [2010/05/27 00:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010/05/27 00:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/03/29 09:06:14 | 000,218,592 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2009/08/27 14:06:32 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV - [2009/06/29 21:42:00 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2009/05/20 10:54:06 | 000,013,736 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacomvhid.sys -- (wacomvhid)
DRV - [2009/03/28 11:01:08 | 000,123,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2009/03/27 13:23:12 | 000,023,064 | ---- | M] (Screaming Bee LLC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ScreamingBAudio.sys -- (SCREAMINGBDRIVER)
DRV - [2009/02/02 08:46:44 | 000,042,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\WPSDRVnt.sys -- (WPS)
DRV - [2009/02/02 08:46:42 | 000,319,664 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2009/02/02 08:46:42 | 000,279,600 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)
DRV - [2009/02/02 08:46:42 | 000,043,824 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2009/02/02 08:46:40 | 000,092,488 | ---- | M] (Symantec Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys -- (SysPlant)
DRV - [2009/02/02 08:46:40 | 000,049,536 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Teefer2.sys -- (Teefer2)
DRV - [2009/02/02 08:46:36 | 000,191,536 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2009/02/02 08:46:36 | 000,027,696 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2009/02/02 08:46:34 | 000,420,400 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2009/02/02 08:46:34 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon)
DRV - [2008/07/03 01:03:14 | 004,745,216 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/02/20 13:47:36 | 000,162,824 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\FTT3.sys -- (FTT3)
DRV - [2008/01/03 06:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation                         ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007/10/11 17:40:12 | 000,009,096 | R--- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\amdide.sys -- (amdide)
DRV - [2007/09/21 02:10:54 | 000,078,992 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2007/09/21 02:10:46 | 000,036,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2007/09/21 02:10:40 | 000,035,088 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007/09/21 02:10:26 | 000,063,120 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L8042mou.Sys -- (L8042mou)
DRV - [2007/09/21 02:10:20 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2007/04/16 16:46:34 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2007/02/16 10:12:36 | 000,011,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacommousefilter.sys -- (wacommousefilter)


[color="#e56717"]========== Standard Registry (SafeList) ==========[/color]


[color="#e56717"]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} -  File not found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...&ctid=CT2786678
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} -  File not found
IE - HKCU\..\URLSearchHook: {73f3dd36-3464-4aa4-a815-de51290fb05e} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color="#e56717"]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaultthis.engineName: "Conduit Engine Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Conduit Engine Customized Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.condui...SearchSource=13"
FF - prefs.js..extensions.enabledItems: [email protected]:3.5.1.110
FF - prefs.js..extensions.enabledItems: [email protected]:4.0.21.0
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0
FF - prefs.js..extensions.enabledItems: [email protected]:4.5
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.071301000019
FF - prefs.js..extensions.enabledItems: {2224E955-00E9-4613-A844-CE69FCCAAE91}:3.6.0.4470
FF - prefs.js..extensions.enabledItems: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}:2.1.0
FF - prefs.js..extensions.enabledItems: {0CDC78A2-05A1-47F9-8810-A36BA7576D00}:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.14908
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1
FF - prefs.js..extensions.enabledItems: {D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}:1.0
FF - prefs.js..keyword.URL: "http://www.bing.com/...ABTDF&PC=BBLN&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{2224E955-00E9-4613-A844-CE69FCCAAE91}: C:\Program Files\Internet Saving Optimizer\3.6.0.4470\FF [2009/08/03 11:49:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/06/17 14:21:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\MSN Toolbar\Platform\4.0.0417.0\Firefox [2010/10/09 16:00:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/10/09 16:01:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/26 21:37:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/27 13:36:00 | 000,000,000 | ---D | M]

[2009/04/30 14:29:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Extensions
[2011/02/27 22:00:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions
[2010/04/07 15:42:15 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010/05/11 18:14:21 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/28 01:15:04 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2009/07/16 23:33:11 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
[2010/12/28 01:15:06 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
[2009/06/04 14:21:28 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
[2010/03/04 16:01:07 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
[2010/02/04 16:45:40 | 000,002,254 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\askcom.xml
[2010/10/28 12:43:34 | 000,001,840 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\bing.xml
[2010/12/28 01:15:06 | 000,000,913 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\conduit.xml
[2010/04/11 20:36:02 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\winamp-search.xml
[2011/02/27 22:00:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/10/20 20:18:39 | 000,000,000 | ---D | M] (ResultBrowse) -- C:\Program Files\Mozilla Firefox\extensions\{0CDC78A2-05A1-47F9-8810-A36BA7576D00}
[2011/01/29 10:35:20 | 000,000,000 | ---D | M] (QuestBrowse) -- C:\Program Files\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}
[2011/02/28 19:10:10 | 000,000,000 | ---D | M] (The Browser Highlighter) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2010/12/27 23:33:13 | 000,000,000 | ---D | M] (Gamevance TextLinks) -- C:\DOCUMENTS AND SETTINGS\JONATHON\APPLICATION DATA\MOZILLA\EXTENSIONS\{EC8030F7-C20A-464F-9B0E-13A3A9E97384}\[email protected]
[2010/06/17 14:21:58 | 000,000,000 | ---D | M] (HP Smart Web Printing) -- C:\PROGRAM FILES\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON3
[2009/08/03 11:49:28 | 000,000,000 | ---D | M] ("NP Helper Class") -- C:\PROGRAM FILES\INTERNET SAVING OPTIMIZER\3.6.0.4470\FF
[2010/10/20 20:15:49 | 000,000,000 | ---D | M] (PriceGong) -- C:\PROGRAM FILES\PRICEGONG\2.1.0\FF
[2010/12/09 02:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2007/08/10 22:58:33 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: 127.0.0.1  mpa.one.microsoft.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (PriceGongBHO Class) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.1.0\PriceGongIE.dll (PriceGong)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} -  File not found
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Recording Engineer Helper Toolbar) - {73f3dd36-3464-4aa4-a815-de51290fb05e} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O2 - BHO: (System Search Dispatcher) - {CDBFB47B-58A8-4111-BF95-06178DCE326D} -  File not found
O3 - HKLM\..\Toolbar: (Recording Engineer Helper Toolbar) - {73f3dd36-3464-4aa4-a815-de51290fb05e} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} -  File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (Recording Engineer Helper Toolbar) - {73F3DD36-3464-4AA4-A815-DE51290FB05E} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Recording Engineer Helper Toolbar) - {73F3DD36-3464-4AA4-A815-DE51290FB05E} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Bluetooth Connection Assistant]  File not found
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [mnumsg.exe]  File not found
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Jonathon\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jonathon\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/08 16:27:48 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{2e4fe6e8-b3a6-11de-a4f1-00218514b984}\Shell\AutoRun\command - "" = E:\system\viewer\FlipVideoforPC.exe
O33 - MountPoints2\{2e4fe6e8-b3a6-11de-a4f1-00218514b984}\Shell\Flip Video for PC\command - "" = E:\system\viewer\FlipVideoforPC.exe
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

[color="#e56717"]========== Files/Folders - Created Within 30 Days ==========[/color]

[2011/02/28 15:41:41 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
[2011/02/18 10:27:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jonathon\Desktop\Prat-3.0-3.4.15
[2011/02/07 16:41:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jonathon\Desktop\Logs
[2010/12/31 21:24:24 | 000,883,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files\JavaSetup6u23.exe
[2010/12/31 21:05:48 | 000,883,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files\jre-6u23-windows-i586-iftw-k.exe
[2010/12/12 21:21:08 | 006,274,424 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Silverlight.exe
[2010/12/03 16:08:27 | 002,728,440 | ---- | C] (Microsoft Corporation) -- C:\Program Files\vcsetup.exe
[2010/12/03 15:40:19 | 003,324,232 | ---- | C] (Microsoft Corporation) -- C:\Program Files\vc_web.exe
[2004/01/12 00:00:00 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msvcr71.dll
[6 C:\Documents and Settings\Jonathon\My Documents\*.tmp files -> C:\Documents and Settings\Jonathon\My Documents\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color="#e56717"]========== Files - Modified Within 30 Days ==========[/color]

[2011/02/28 19:26:07 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/28 19:25:17 | 000,200,819 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011/02/28 19:24:58 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/28 19:24:37 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/28 19:09:00 | 000,000,890 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/28 19:05:21 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\RMSchedule.job
[2011/02/28 19:01:00 | 000,000,240 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/02/28 16:56:05 | 000,000,458 | ---- | M] () -- C:\WINDOWS\tasks\RMSmartUpdate.job
[2011/02/28 15:42:17 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
[2011/02/27 22:30:29 | 000,096,968 | ---- | M] () -- C:\Documents and Settings\Jonathon\Desktop\WauQuickStart.exe
[2011/02/27 17:41:51 | 000,000,476 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Jonathon.job
[2011/02/27 13:57:16 | 000,000,223 | RHS- | M] () -- C:\boot.ini
[2011/02/27 13:40:23 | 000,000,215 | ---- | M] () -- C:\Documents and Settings\Jonathon\Desktop\Magicka.url
[2011/02/26 14:17:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/02/18 10:27:45 | 001,402,518 | ---- | M] () -- C:\Documents and Settings\Jonathon\Desktop\Prat-3.0-3.4.15.zip
[2011/02/14 22:08:43 | 000,013,486 | ---- | M] () -- C:\WINDOWS\System32\Pen_Tablet.dat
[2011/02/13 20:54:55 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/13 20:54:55 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/12 08:09:12 | 000,456,304 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/02/12 08:09:12 | 000,075,210 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[6 C:\Documents and Settings\Jonathon\My Documents\*.tmp files -> C:\Documents and Settings\Jonathon\My Documents\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color="#e56717"]========== Files Created - No Company Name ==========[/color]

[2011/02/27 22:29:55 | 000,096,968 | ---- | C] () -- C:\Documents and Settings\Jonathon\Desktop\WauQuickStart.exe
[2011/02/27 13:40:23 | 000,000,215 | ---- | C] () -- C:\Documents and Settings\Jonathon\Desktop\Magicka.url
[2011/02/18 10:27:43 | 001,402,518 | ---- | C] () -- C:\Documents and Settings\Jonathon\Desktop\Prat-3.0-3.4.15.zip
[2011/02/13 20:54:55 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/01/29 10:33:01 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/01/29 10:33:01 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/01/21 20:40:53 | 000,031,616 | ---- | C] () -- C:\WINDOWS\System32\drivers\vrtaucbl.sys
[2010/12/31 23:08:16 | 000,835,440 | ---- | C] () -- C:\Program Files\pbsvc.exe
[2010/12/31 22:53:25 | 002,434,856 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_bc2.exe
[2010/12/27 23:34:47 | 005,430,783 | ---- | C] () -- C:\Program Files\WMV r506 32bit DEVWORK.rar
[2010/12/24 00:00:04 | 001,661,959 | ---- | C] () -- C:\Program Files\wowmodelview0.5.07.zip
[2010/12/10 21:13:05 | 001,985,823 | ---- | C] () -- C:\Program Files\AtlasLoot-v6.01.01.zip
[2010/12/07 18:29:56 | 000,001,456 | ---- | C] () -- C:\Documents and Settings\Jonathon\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs
[2010/12/04 14:55:53 | 000,022,222 | ---- | C] () -- C:\Program Files\souper3.zip
[2010/12/04 11:39:28 | 000,980,215 | ---- | C] () -- C:\Program Files\msvcdll-90.zip
[2010/12/04 11:36:56 | 007,683,072 | ---- | C] () -- C:\Program Files\WMV_Installer_v0701_r500_Win64.msi
[2010/12/04 11:33:47 | 000,000,000 | ---- | C] () -- C:\Program Files\wowmodelview-0.5.06beta.zip
[2010/12/03 16:37:20 | 005,928,476 | ---- | C] () -- C:\Program Files\WMV_Binary_v0701_r490_Win32_DevWork.zip
[2010/12/03 16:25:15 | 003,728,716 | ---- | C] () -- C:\Program Files\WoWModelViewer_0.6.0.3_Win32_Release.zip
[2010/12/03 16:10:54 | 005,167,176 | ---- | C] () -- C:\Program Files\WoW-2.4.0.8089-to-2.4.1.8125-enUS-patch.exe
[2010/12/03 15:36:37 | 007,091,330 | ---- | C] () -- C:\Program Files\WoWModelViewer_0.6.0.1_Win32_Debug.zip
[2010/10/10 00:56:26 | 000,037,336 | ---- | C] () -- C:\WINDOWS\System32\CleanMFT32.exe
[2010/08/16 08:54:25 | 000,013,486 | ---- | C] () -- C:\WINDOWS\System32\Pen_Tablet.dat
[2010/08/03 15:54:23 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Jonathon\Application Data\Adobe PNG Format CS5 Prefs
[2010/06/17 19:29:26 | 000,193,751 | ---- | C] () -- C:\WINDOWS\hpoins41.dat.temp
[2010/06/17 19:29:26 | 000,001,253 | ---- | C] () -- C:\WINDOWS\hpomdl41.dat.temp
[2010/06/17 14:13:10 | 000,193,751 | ---- | C] () -- C:\WINDOWS\hpoins41.dat
[2010/06/17 14:13:10 | 000,001,253 | ---- | C] () -- C:\WINDOWS\hpomdl41.dat
[2010/05/16 06:44:30 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
[2009/10/10 20:51:36 | 000,058,004 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/10/08 16:28:11 | 000,017,920 | ---- | C] () -- C:\Documents and Settings\Jonathon\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/10 15:48:01 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/04/30 14:29:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/04/27 20:49:35 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/04/27 20:05:16 | 000,000,760 | ---- | C] () -- C:\Documents and Settings\Jonathon\Application Data\setup_ldm.iss
[2009/03/12 20:02:45 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/03/12 20:00:08 | 003,767,296 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/12 13:55:32 | 000,138,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/12 13:55:32 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Jonathon\Application Data\PnkBstrK.sys
[2009/03/12 13:55:13 | 000,835,440 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2009/03/12 13:55:13 | 000,270,904 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2009/03/12 13:55:13 | 000,075,136 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2009/03/12 13:32:45 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2009/03/12 13:18:21 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/03/12 13:14:03 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/01/13 14:22:56 | 002,163,200 | ---- | C] () -- C:\Program Files\WoWModelViewer.exe
[2009/01/12 12:19:56 | 000,288,056 | ---- | C] () -- C:\Program Files\logo.bmp
[2008/11/03 01:27:22 | 000,245,760 | ---- | C] () -- C:\Program Files\glew32.dll
[2008/10/06 21:33:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/10/06 21:33:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2008/10/06 21:33:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/10/06 21:33:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2008/10/06 21:33:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/10/06 21:33:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/10/06 21:33:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2008/10/06 21:33:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2008/10/06 21:33:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/06/05 08:58:26 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/13 20:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2006/12/30 22:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001/08/23 03:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 03:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 03:00:00 | 000,456,304 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 03:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 03:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 03:00:00 | 000,075,210 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 03:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 03:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 03:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 03:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

[color="#e56717"]========== LOP Check ==========[/color]

[2011/01/29 10:32:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
[2011/01/29 10:49:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ClickPotatoLiteSA
[2010/05/10 20:52:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/06/16 11:28:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/06/29 21:46:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/10/09 16:00:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/08/16 10:53:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/02/04 07:04:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\QuestBrwSearch
[2010/06/22 12:38:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/01/05 16:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ResultBrowse
[2010/02/25 17:06:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Screaming Bee
[2011/02/28 19:25:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/16 11:37:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/10/07 18:27:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/10 17:55:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/09/01 15:53:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/01/29 10:32:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\ClickPotatoLite
[2010/10/28 19:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/05/10 20:52:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\DAEMON Tools Lite
[2010/06/29 15:52:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Datel
[2009/10/18 11:57:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\GetRightToGo
[2009/04/27 20:05:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Leadertech
[2010/08/19 18:58:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\MsgCnf
[2010/08/20 08:29:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\MyShoppingGenie
[2010/06/16 11:37:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\NCH Swift Sound
[2011/02/28 19:14:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Octoshape
[2011/02/28 19:26:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\PriceGong
[2010/04/19 16:14:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\RadioBar
[2011/02/28 19:06:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\RayV
[2009/12/07 21:12:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Screaming Bee
[2011/01/29 12:02:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\ShoppingReport2
[2009/05/24 11:16:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\SPORE
[2010/12/05 08:33:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/02/28 19:35:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\uTorrent
[2009/03/28 11:05:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Windows Desktop Search
[2009/06/30 20:00:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Windows Search
[2010/06/16 19:52:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\WTouch
[2011/02/28 19:05:21 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\RMSchedule.job
[2011/02/28 16:56:05 | 000,000,458 | ---- | M] () -- C:\WINDOWS\Tasks\RMSmartUpdate.job
[2011/02/28 19:01:00 | 000,000,240 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

[color="#e56717"]========== Purity Check ==========[/color]



[color="#e56717"]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24051EFF
@Alternate Data Stream - 495 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63238B95
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
« Last Edit: February 28, 2011, 10:40:02 PM by jony »

:(


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
OS question, and Download error.
« Reply #7 on: February 28, 2011, 10:54:25 PM »
Can you let me know

From the following: How many did you uninstall or try and uninstall?
Internet Saving Optimizer
System Search Dispatcher
MyShoppingGenie
DTVblizzcon
Recording_Engineer_Helper Toolbar
ResultBrowse 1.0 build 117
Software Informer 1.0 BETA
Viewpoint Media Player
Winwonk OpenTarget
Winamp Toolbar
Yahoo! Toolbar
Google Toolbar for Internet Explorer


In addition: I didn't include PriceGong in that list, is that something you need/use?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline jony

  • Full Member
  • ***
  • Posts: 188
  • Karma: +0/-0
    • View Profile
    • http://forgehub.com
OS question, and Download error.
« Reply #8 on: February 28, 2011, 11:10:56 PM »
Internet Saving Optimizer
System Search Dispatcher
MyShoppingGenie
DTVblizzcon

Recording_Engineer_Helper Toolbar
ResultBrowse 1.0 build 117
Software Informer 1.0 BETA
Viewpoint Media Player
Winwonk OpenTarget  
- I use this to open the folders of my programs.
Winamp Toolbar
Yahoo! Toolbar
Google Toolbar for Internet Explorer


PriceGong

Just uninstalled all of these.
« Last Edit: February 28, 2011, 11:11:21 PM by jony »

:(


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
OS question, and Download error.
« Reply #9 on: February 28, 2011, 11:46:23 PM »
Double  click on OTL.exe and Run it
  • Under the [color="#0000FF"]Custom Scans/Fixes[/color] box at the bottom, copy/paste in the following in the quote box below. don't include the word Quote please
    Quote
    :OTL
    SRV - File not found [Auto | Stopped] -- -- (Viewpoint Manager Service)
    SRV - File not found [Auto | Stopped] -- -- (ResultBrowse Service)
    SRV - File not found [Auto | Stopped] -- -- (QuestBrowse Service)
    IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - File not found
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...&ctid=CT2786678
    IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - Reg Error: Key error. File not found
    IE - HKCU\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - File not found
    IE - HKCU\..\URLSearchHook: {73f3dd36-3464-4aa4-a815-de51290fb05e} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
    IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - Reg Error: Key error. File not found
    FF - prefs.js..browser.search.defaultengine: "Ask.com"
    FF - prefs.js..browser.search.defaultthis.engineName: "Conduit Engine Customized Web Search"
    FF - prefs.js..browser.search.defaulturl: "http://search.condui...&q={searchTerms}"
    FF - prefs.js..browser.search.order.1: "Ask.com"
    FF - prefs.js..browser.search.selectedEngine: "Conduit Engine Customized Web Search"
    FF - prefs.js..browser.startup.homepage: "http://search.condui...SearchSource=13"
    FF - prefs.js..extensions.enabledItems: [email protected]:3.5.1.110
    FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
    FF - prefs.js..extensions.enabledItems: {2224E955-00E9-4613-A844-CE69FCCAAE91}:3.6.0.4470
    FF - prefs.js..extensions.enabledItems: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}:2.1.0
    FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2
    FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1
    FF - prefs.js..extensions.enabledItems: {D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}:1.0
    FF - HKLM\software\mozilla\Firefox\Extensions\\{2224E955-00E9-4613-A844-CE69FCCAAE91}: C:\Program Files\Internet Saving Optimizer\3.6.0.4470\FF [2009/08/03 11:49:28 | 000,000,000 | ---D | M]
    [2010/12/28 01:15:06 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
    [2010/03/04 16:01:07 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
    [2010/02/04 16:45:40 | 000,002,254 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\askcom.xml
    [2010/12/28 01:15:06 | 000,000,913 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\conduit.xml
    [2010/10/20 20:18:39 | 000,000,000 | ---D | M] (ResultBrowse) -- C:\Program Files\Mozilla Firefox\extensions\{0CDC78A2-05A1-47F9-8810-A36BA7576D00}
    [2011/01/29 10:35:20 | 000,000,000 | ---D | M] (QuestBrowse) -- C:\Program Files\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}
    [2009/08/03 11:49:28 | 000,000,000 | ---D | M] ("NP Helper Class") -- C:\PROGRAM FILES\INTERNET SAVING OPTIMIZER\3.6.0.4470\FF
    [2010/10/20 20:15:49 | 000,000,000 | ---D | M] (PriceGong) -- C:\PROGRAM FILES\PRICEGONG\2.1.0\FF
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (PriceGongBHO Class) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.1.0\PriceGongIE.dll (PriceGong)
    O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - File not found
    O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
    O2 - BHO: (Recording Engineer Helper Toolbar) - {73f3dd36-3464-4aa4-a815-de51290fb05e} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
    O2 - BHO: (System Search Dispatcher) - {CDBFB47B-58A8-4111-BF95-06178DCE326D} - File not found
    O3 - HKLM\..\Toolbar: (Recording Engineer Helper Toolbar) - {73f3dd36-3464-4aa4-a815-de51290fb05e} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - File not found
    O3 - HKCU\..\Toolbar\ShellBrowser: (Recording Engineer Helper Toolbar) - {73F3DD36-3464-4AA4-A815-DE51290FB05E} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Recording Engineer Helper Toolbar) - {73F3DD36-3464-4AA4-A815-DE51290FB05E} - C:\Program Files\Recording_Engineer_Helper\tbRec2.dll (Conduit Ltd.)
    O4 - HKCU..\Run: [mnumsg.exe] File not found
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
    O33 - MountPoints2\{2e4fe6e8-b3a6-11de-a4f1-00218514b984}\Shell\AutoRun\command - "" = E:\system\viewer\FlipVideoforPC.exe
    O33 - MountPoints2\{2e4fe6e8-b3a6-11de-a4f1-00218514b984}\Shell\Flip Video for PC\command - "" = E:\system\viewer\FlipVideoforPC.exe
    [2011/02/28 19:05:21 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\RMSchedule.job
    [2011/02/28 19:01:00 | 000,000,240 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
    [2011/02/28 16:56:05 | 000,000,458 | ---- | M] () -- C:\WINDOWS\tasks\RMSmartUpdate.job
    [2011/01/05 16:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ResultBrowse
    [2010/06/16 11:37:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2010/08/20 08:29:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\MyShoppingGenie
    [2011/02/28 19:26:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\PriceGong
    [2011/01/29 12:02:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\ShoppingReport2
    @Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24051EFF
    @Alternate Data Stream - 495 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
    @Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
    @Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
    @Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:63238B95
    @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
    :Reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "Alcmtr"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "uTorrent"=-
    :Files
    ipconfig /flushdns /c
    :Commands
    [EmptyTemp]
    [EmptyFlash]
    [Reboot]

  • Then click the [color="#FF0000"]Run Fix[/color] button at the top
  • Let the program run unhindered, reboot the PC when it is done

On startup, Allow OTL to run if prompted
A log should open, can you save it to a convenient location, I want to see it later
A copy of this log can also be found in
C:\_OTL\Moved Files folder

Afterwards:
Come back here, download and save to desktop
Dial-A-Fix from the following location
[color="#0000FF"]Click HERE[/color]
After you have it saved to desktop, Extract the folder within to your desktop

Open the Dial-A-Fix folder and double click on DialaFix.exe icon
Don't worry if you get an "Unable to determine your version of IE....." message, and it goes on asking to email them, just ignore it
and click OK
Select the [color="#00FF00"]GREEN[/color] check, this will select all options

Then hit the GO
Verify that your Date/time is correct, click OK to continue
You will eventually get to the point of it Registering >> Explorer/IE/OE/Shell/WMP
and more than likely get about 12 error messages as eg...
"Error 127, blah blah blah"

Again, ignore those error messages by click OK
When Dial-A-Fix is complete, click EXIT

Reboot your computer

Back in Windows
Let's try installing a program
download Malwarebytes' Anti-Malware from Here or Here
Save the installer to desktop
NOTE: The Shareware version is the same installer as the Freeware version

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.    
  • If an update is found, it will download and install the latest version.    
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.    
  • The scan may take some time to finish,so please be patient.    
  • When the scan is complete, click OK, then Show Results to view the results.    
  • Make sure that everything is checked, and click Remove Selected.
        * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)    
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.    
  • Copy&Paste the entire report in your next reply
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

With the log from MBAM, can you include that Fix log from OTL.exe please
« Last Edit: February 28, 2011, 11:48:36 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline jony

  • Full Member
  • ***
  • Posts: 188
  • Karma: +0/-0
    • View Profile
    • http://forgehub.com
OS question, and Download error.
« Reply #10 on: March 01, 2011, 12:16:09 AM »
( almost done with the Malwarebytes scan. )


while thats scanning heres this.

On startup, Allow OTL to run if prompted
A log should open, can you save it to a convenient location, I want to see it later
A copy of this log can also be found in
C:\_OTL\Moved Files folder



All processes killed
========== OTL ==========
Service Viewpoint Manager Service stopped successfully!
Service Viewpoint Manager Service deleted successfully!
Service ResultBrowse Service stopped successfully!
Service ResultBrowse Service deleted successfully!
Service QuestBrowse Service stopped successfully!
Service QuestBrowse Service deleted successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}\ deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{73f3dd36-3464-4aa4-a815-de51290fb05e} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73f3dd36-3464-4aa4-a815-de51290fb05e}\ not found.
File C:\Program Files\Recording_Engineer_Helper\tbRec2.dll not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\ not found.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Conduit Engine Customized Web Search" removed from browser.search.defaultthis.engineName
Prefs.js: "http://search.condui...&q={searchTerms}" removed from browser.search.defaulturl
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: "Conduit Engine Customized Web Search" removed from browser.search.selectedEngine
Prefs.js: "http://search.condui...SearchSource=13" removed from browser.startup.homepage
Prefs.js: [email protected]:3.5.1.110 removed from extensions.enabledItems
Prefs.js: [email protected]:3.2.5.2 removed from extensions.enabledItems
Prefs.js: {2224E955-00E9-4613-A844-CE69FCCAAE91}:3.6.0.4470 removed from extensions.enabledItems
Prefs.js: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}:2.1.0 removed from extensions.enabledItems
Prefs.js: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2 removed from extensions.enabledItems
Prefs.js: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1 removed from extensions.enabledItems
Prefs.js: {D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}:1.0 removed from extensions.enabledItems
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2224E955-00E9-4613-A844-CE69FCCAAE91} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2224E955-00E9-4613-A844-CE69FCCAAE91}\ not found.
C:\Program Files\Internet Saving Optimizer\3.6.0.4470\FF\components folder moved successfully.
C:\Program Files\Internet Saving Optimizer\3.6.0.4470\FF\chrome\content folder moved successfully.
C:\Program Files\Internet Saving Optimizer\3.6.0.4470\FF\chrome folder moved successfully.
C:\Program Files\Internet Saving Optimizer\3.6.0.4470\FF folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\searchplugin folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\META-INF folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\lib folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\DualPackage folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\defaults folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\components folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\chrome folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected] folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\searchplugins folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\logs folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\defaults\preferences folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\defaults folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\chrome\temp\ff-config.Tue-02-Mar-2010-05-33-58-GMT folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\chrome\temp folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\chrome\skin folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\chrome\content folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]\chrome folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected] folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\askcom.xml moved successfully.
C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\conduit.xml moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{0CDC78A2-05A1-47F9-8810-A36BA7576D00}\defaults\preferences folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{0CDC78A2-05A1-47F9-8810-A36BA7576D00}\defaults folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{0CDC78A2-05A1-47F9-8810-A36BA7576D00}\chrome folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{0CDC78A2-05A1-47F9-8810-A36BA7576D00} folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\defaults\preferences folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\defaults folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}\chrome folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0} folder moved successfully.
Folder C:\PROGRAM FILES\INTERNET SAVING OPTIMIZER\3.6.0.4470\FF\ not found.
Folder C:\PROGRAM FILES\PRICEGONG\2.1.0\FF\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1631550F-191D-4826-B069-D9439253D926}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1631550F-191D-4826-B069-D9439253D926}\ not found.
C:\Program Files\PriceGong\2.1.0\PriceGongIE.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully.
C:\Program Files\ConduitEngine\ConduitEngine.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73f3dd36-3464-4aa4-a815-de51290fb05e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73f3dd36-3464-4aa4-a815-de51290fb05e}\ not found.
File C:\Program Files\Recording_Engineer_Helper\tbRec2.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CDBFB47B-58A8-4111-BF95-06178DCE326D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CDBFB47B-58A8-4111-BF95-06178DCE326D}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{73f3dd36-3464-4aa4-a815-de51290fb05e} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73f3dd36-3464-4aa4-a815-de51290fb05e}\ not found.
File C:\Program Files\Recording_Engineer_Helper\tbRec2.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{73F3DD36-3464-4AA4-A815-DE51290FB05E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73F3DD36-3464-4AA4-A815-DE51290FB05E}\ not found.
File C:\Program Files\Recording_Engineer_Helper\tbRec2.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{73F3DD36-3464-4AA4-A815-DE51290FB05E} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73F3DD36-3464-4AA4-A815-DE51290FB05E}\ not found.
File C:\Program Files\Recording_Engineer_Helper\tbRec2.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\mnumsg.exe deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk moved successfully.
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2e4fe6e8-b3a6-11de-a4f1-00218514b984}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2e4fe6e8-b3a6-11de-a4f1-00218514b984}\ not found.
File E:\system\viewer\FlipVideoforPC.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2e4fe6e8-b3a6-11de-a4f1-00218514b984}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2e4fe6e8-b3a6-11de-a4f1-00218514b984}\ not found.
File E:\system\viewer\FlipVideoforPC.exe not found.
C:\WINDOWS\tasks\RMSchedule.job moved successfully.
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job moved successfully.
C:\WINDOWS\tasks\RMSmartUpdate.job moved successfully.
Folder C:\Documents and Settings\All Users\Application Data\ResultBrowse\ not found.
C:\Documents and Settings\All Users\Application Data\Viewpoint folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\MyShoppingGenie folder moved successfully.
Folder C:\Documents and Settings\Jonathon\Application Data\PriceGong\ not found.
C:\Documents and Settings\Jonathon\Application Data\ShoppingReport2\cs\report folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\ShoppingReport2\cs\dwld folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\ShoppingReport2\cs\db folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\ShoppingReport2\cs folder moved successfully.
C:\Documents and Settings\Jonathon\Application Data\ShoppingReport2 folder moved successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:24051EFF deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:63238B95 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8 deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Alcmtr deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Jonathon\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Jonathon\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 41620 bytes
 
User: Jonathon
->Temp folder emptied: 9137717819 bytes
->Temporary Internet Files folder emptied: 71870777 bytes
->FireFox cache emptied: 69237196 bytes
->Google Chrome cache emptied: 6641196 bytes
->Apple Safari cache emptied: 3002368 bytes
->Flash cache emptied: 3507822 bytes
 
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1348591 bytes
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 579642 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2402044 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 106701702 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23943056 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 770095 bytes
RecycleBin emptied: 440473636 bytes
 
Total Files Cleaned = 9,411.00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default User
->Flash cache emptied: 0 bytes
 
User: Jonathon
->Flash cache emptied: 0 bytes
 
User: LocalService
 
User: NetworkService
 
Total Flash Files Cleaned = 0.00 mb
 
 
OTL by OldTimer - Version 3.2.22.2 log created on 02282011_205058

Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\Jonathon\Local Settings\Temp\~DF7EFB.tmp not found!
File\Folder C:\Documents and Settings\Jonathon\Local Settings\Temp\~DFDBB1.tmp not found!
File\Folder C:\Documents and Settings\Jonathon\Local Settings\Temp\~DFDC00.tmp not found!
File\Folder C:\Documents and Settings\Jonathon\Local Settings\Temp\~DFDCF3.tmp not found!
File\Folder C:\Documents and Settings\Jonathon\Local Settings\Temp\~DFDD20.tmp not found!
File\Folder C:\Documents and Settings\Jonathon\Local Settings\Temp\~DFDF8E.tmp not found!
File\Folder C:\Documents and Settings\Jonathon\Local Settings\Temp\~DFE182.tmp not found!
File\Folder C:\Documents and Settings\Jonathon\Local Settings\Temporary Internet Files\Content.Word\~WRS{0DF35EAE-484B-46E5-ABC9-E2BE270538DD}.tmp not found!
C:\Documents and Settings\Jonathon\Local Settings\Temporary Internet Files\Content.IE5\T7Q9VV2W\index[1].php moved successfully.
C:\Documents and Settings\Jonathon\Local Settings\Temporary Internet Files\Content.IE5\T7Q9VV2W\showthread[1].htm moved successfully.

Registry entries deleted on Reboot...



:(


Offline jony

  • Full Member
  • ***
  • Posts: 188
  • Karma: +0/-0
    • View Profile
    • http://forgehub.com
OS question, and Download error.
« Reply #11 on: March 01, 2011, 12:19:03 AM »
Heres the mbam-log.


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5910

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2/28/2011 9:17:14 PM
mbam-log-2011-02-28 (21-17-14).txt

Scan type: Quick scan
Objects scanned: 149817
Time elapsed: 3 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 34
Registry Values Infected: 6
Registry Data Items Infected: 0
Folders Infected: 30
Files Infected: 288

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Typelib\{883DFC00-8A21-411D-956C-73A4E4B7D16F} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{480098C6-F6AD-4C61-9B5C-2BAE228A34D1} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{C28A0312-C403-417B-A425-A915BC0519CD} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{877F3EAB-4462-44DF-8475-6064EAFD7FBF} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{BDEA95CF-F0E6-41E0-BD3D-B00F39A4E939} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BDEA95CF-F0E6-41E0-BD3D-B00F39A4E939} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3} (Adware.Gamevance) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ED403E8-470A-4a8a-85A4-D7688CFE39A3} (Adware.Gamevance) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{258C9770-1713-4021-8D7E-1F184A2BD754} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{258C9770-1713-4021-8D7E-1F184A2BD754} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CDBFB47B-58A8-4111-BF95-06178DCE326D} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CDBFB47B-58A8-4111-BF95-06178DCE326D} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35B8D58C-B0CB-46B0-BA64-05B3804E4E86} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEAC7DC8-E106-4C6A-931E-5A42E7362883} (Adware.GameVance) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB38E21A-0133-419D-92AD-ECDFD5244D6D} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB620C54-E229-4942-87CE-E717109FC8C6} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ExplorerBar.FunExplorer (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ExplorerBar.FunExplorer.1 (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ExplorerBar.FunRedirector (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ExplorerBar.FunRedirector.1 (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Internet Saving Optimizer (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Media Access Startup (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\clickpotatolitesa (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\ShoppingReport2 (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\AppDataLow\gvtl (Adware.GameVance) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Internet Saving Optimizer (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Media Access Startup (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\QuestBrowse (Adware.QuestBrowse) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1FB52AB3-5987-45a2-85E0-F3EC30DDDC29}}_is1 (Adware.DoubleD) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Value: {5617ECA9-488D-4BA2-8562-9710B9AB78D2} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{DB38E21A-0133-419D-92AD-ECDFD5244D6D} (Adware.ShoppingReport2) -> Value: {DB38E21A-0133-419D-92AD-ECDFD5244D6D} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{EB620C54-E229-4942-87CE-E717109FC8C6} (Adware.ShoppingReport2) -> Value: {EB620C54-E229-4942-87CE-E717109FC8C6} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{EB620C54-E229-4942-87CE-E717109FC8C6} (Adware.ShoppingReport2) -> Value: {EB620C54-E229-4942-87CE-E717109FC8C6} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{DB38E21A-0133-419d-92AD-ECDFD5244D6D} (Adware.ShoppingReport2) -> Value: {DB38E21A-0133-419d-92AD-ECDFD5244D6D} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Value: {5617ECA9-488D-4BA2-8562-9710B9AB78D2} -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
c:\documents and settings\all users\application data\2aca5cc3-0f83-453d-a079-1076fe1a8b65 (Adware.Seekmo) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\clickpotatolitesa (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\application data\clickpotatolite (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.659.0 (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.659.0\firefox (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.659.0\firefox\extensions (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.659.0\firefox\extensions\plugins (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\DoubleD\gamingharbor toolbar (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\gamevance (Adware.Gamevance) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.6.0.4470 (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.6.0.4470\Data (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\shoppingreport2 (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
c:\program files\shoppingreport2\Bin (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
c:\program files\shoppingreport2\Bin\2.7.32 (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\clickpotato (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\DoubleD\gamingharbor toolbar (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\DoubleD\gamingharbor toolbar\4.2.2.21960 (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\DoubleD\gamingharbor toolbar\4.2.2.21960\bin (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470 (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[email protected] (Adware.GamesVance) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[email protected]\chrome (Adware.GamesVance) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[email protected]\components (Adware.GamesVance) -> Quarantined and deleted successfully.
c:\program files\questbrwsearch (Adware.QuestBrowse) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\questbrwsearch (Adware.QuestBrowse) -> Quarantined and deleted successfully.

Files Infected:
c:\documents and settings\Jonathon\Desktop\clickpotatoinstaller.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\clickpotatolitesa\clickpotatolitesa.dat (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\clickpotatolitesa\clickpotatolitesaabout.mht (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\clickpotatolitesa\clickpotatolitesaau.dat (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\clickpotatolitesa\clickpotatolitesaeula.mht (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\clickpotatolitesa\clickpotatolitesa_kyf.dat (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.659.0\clickpotatolitesaax.dll (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.659.0\clickpotatolitesabho.dll (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.659.0\clickpotatolitesahook.dll (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.659.0\clickpotatoliteuninstaller.exe (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.659.0\firefox\extensions\chrome.manifest (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.659.0\firefox\extensions\install.rdf (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.659.0\firefox\extensions\plugins\npclntax_clickpotatolitesa.dll (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\program files\gamevance\ars.cfg (Adware.Gamevance) -> Quarantined and deleted successfully.
c:\program files\gamevance\gamevance32.exe (Adware.Gamevance) -> Quarantined and deleted successfully.
c:\program files\gamevance\gamevancelib32.dll (Adware.Gamevance) -> Quarantined and deleted successfully.
c:\program files\gamevance\gvtl.dll (Adware.Gamevance) -> Quarantined and deleted successfully.
c:\program files\gamevance\gvun.exe (Adware.Gamevance) -> Quarantined and deleted successfully.
c:\program files\gamevance\icon.ico (Adware.Gamevance) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.6.0.4470\unins000.dat (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.6.0.4470\unins000.exe (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\internet saving optimizer\3.6.0.4470\Data\config.md (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\program files\shoppingreport2\Uninst.exe (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
c:\program files\shoppingreport2\Bin\2.7.32\shoppingreport.dll (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\clickpotato\About Us.lnk (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\clickpotato\clickpotato customer support.lnk (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\clickpotato\clickpotato uninstall instructions.lnk (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\DoubleD\gamingharbor toolbar\4.2.2.21960\bin\stbup.exe (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\config.md (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\ipdata.md (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-161010.671.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-165549.515.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-165549.937.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-184849.015.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-184851.109.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-194617.593.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-194618.031.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-205628.750.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-205629.218.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-210150.109.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-210150.562.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-224609.328.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-224609.750.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-004923.593.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-102925.140.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-102926.531.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-104335.046.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-104335.578.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-105612.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-105612.765.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-123650.343.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-123650.859.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-123728.312.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-130141.000.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-141922.140.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-141947.812.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-144120.875.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-144755.687.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-154525.656.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-154936.828.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-155135.187.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-155211.000.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-155844.812.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-222356.765.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-222357.968.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-000252.453.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-000252.937.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-021215.000.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-021215.578.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-095259.875.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-095301.796.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-114939.270.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-161010.234.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-004924.031.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090804-144756.093.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-114939.691.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-181140.359.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090807-233346.453.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-161225.234.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-125313.546.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090811-004239.187.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-121130.786.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-115010.437.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090815-175326.109.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-225246.828.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090818-141934.171.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090819-141253.953.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090820-190650.406.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-124816.707.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-124817.129.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-163115.551.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-163115.988.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090805-211846.723.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-005049.988.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-005050.551.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-102800.281.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-102801.671.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-103102.156.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-103102.609.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-161900.718.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-161901.640.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-181139.906.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-191905.359.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-191905.812.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-200747.468.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090806-200747.890.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090807-013301.656.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090807-013302.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090807-114636.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090807-114647.953.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090807-114649.015.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090807-115544.890.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090807-115545.328.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090807-152006.343.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090807-152006.796.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090807-233346.000.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-002821.796.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-002822.234.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-004711.531.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-004711.984.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-012132.875.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-012133.328.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-102937.093.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-102938.000.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-105805.359.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-105805.796.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-115358.812.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-115359.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-134058.515.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-134058.953.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090808-161225.750.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090809-113157.921.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090809-113158.859.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090809-162736.234.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090809-162736.703.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090809-192239.375.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090809-192239.812.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-020231.515.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-020231.953.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-111917.015.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-111918.140.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-112534.125.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-112534.562.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-125313.093.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-134643.937.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-134644.375.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-161616.859.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-161617.375.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-161901.359.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-161901.781.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-180916.968.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-180917.421.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-182021.843.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-182022.312.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-233750.609.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090810-233751.187.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090811-004201.500.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090811-004238.765.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090811-143640.640.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090811-143641.437.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090811-143739.046.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090811-143739.500.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090811-161859.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090811-161859.750.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090811-181436.093.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090811-181436.562.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-014139.609.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-014140.046.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-112218.332.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-112219.270.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-112442.504.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-112442.957.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-121131.207.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-145926.848.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-145927.286.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-153900.707.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-153901.145.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-161336.332.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-161415.411.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-161416.129.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-174723.082.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-174723.582.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-175641.770.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090812-175642.192.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-112818.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-112819.703.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-125040.125.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-141101.812.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-141759.500.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090803-141800.046.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-115010.890.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-134703.703.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-134704.218.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-162135.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-162135.734.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-211554.296.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-211555.000.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-214220.046.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090813-214220.484.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090814-221111.046.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090814-221112.296.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090815-143658.515.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090815-143659.109.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090815-175325.578.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-001357.812.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-001405.656.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-001417.437.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-001418.015.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-003402.171.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-003402.593.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-104004.750.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-104005.765.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-125020.484.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-125021.359.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-151212.453.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-151212.906.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-224346.968.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-224347.750.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-225247.265.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-225441.828.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090816-225442.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090817-002840.625.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090817-110911.718.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090817-110914.015.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090817-144040.593.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090817-144041.265.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090817-191644.500.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090818-120116.468.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090818-120117.765.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090818-140646.453.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090818-140646.875.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090818-141933.734.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090818-164211.343.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090818-164212.109.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090818-165024.765.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090818-165025.234.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090819-005639.531.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090819-005640.000.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090819-102903.453.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090819-102905.546.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090819-103114.390.log (Adware.DoubleD) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathon\local settings\application data\internet saving optimizer\3.6.0.4470\np_20090819-103114.828.log (Adwa

:(


Offline jony

  • Full Member
  • ***
  • Posts: 188
  • Karma: +0/-0
    • View Profile
    • http://forgehub.com
OS question, and Download error.
« Reply #12 on: March 01, 2011, 12:27:17 AM »
You are the [censored]ing man. I can now install things again.


:(


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
OS question, and Download error.
« Reply #13 on: March 01, 2011, 12:34:49 AM »
Can you do one more Quick Scan for me please with OTL.exe and post it's new log
Let me know how everything is now running

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline jony

  • Full Member
  • ***
  • Posts: 188
  • Karma: +0/-0
    • View Profile
    • http://forgehub.com
OS question, and Download error.
« Reply #14 on: March 01, 2011, 12:44:23 AM »
Here you are.

OTL logfile created on: 2/28/2011 9:40:40 PM - Run 2
OTL by OldTimer - Version 3.2.22.2    Folder = C:\Documents and Settings\Jonathon\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 73.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 175.12 Gb Free Space | 37.60% Space Free | Partition Type: NTFS
 
Computer Name: JONATHONB | User Name: Jonathon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2011/02/28 15:42:17 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
PRC - [2010/12/05 13:43:48 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2010/08/05 07:46:02 | 000,583,640 | ---- | M] (PC Tools) -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
PRC - [2009/11/23 15:53:58 | 004,781,352 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\WTouch\WTouchUser.exe
PRC - [2009/11/23 15:53:58 | 000,113,448 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\WTouch\WTouchService.exe
PRC - [2009/11/23 15:53:56 | 004,497,704 | ---- | M] (Wacom Technology, Corp.) -- C:\WINDOWS\system32\Pen_Tablet.exe
PRC - [2009/04/22 20:11:32 | 001,675,776 | ---- | M] (Flagship Industries, Inc.) -- C:\Program Files\Ventrilo\Ventrilo.exe
PRC - [2009/02/02 08:46:42 | 000,115,560 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2009/02/02 08:46:42 | 000,108,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2009/02/02 08:46:40 | 001,795,400 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
PRC - [2009/02/02 08:46:40 | 001,443,144 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
PRC - [2009/02/02 08:46:38 | 002,440,120 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
PRC - [2008/11/09 12:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/13 20:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/11/15 09:09:56 | 000,059,920 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\SetPoint\LBTWiz.exe
PRC - [2007/11/15 09:09:42 | 000,121,360 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2011/02/28 15:42:17 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
MOD - [2008/04/13 20:42:52 | 001,054,208 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2010/08/05 07:46:02 | 000,583,640 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2010/04/24 22:04:55 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/15 10:50:36 | 001,142,224 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2010/03/11 10:09:22 | 000,366,840 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/01/25 10:00:54 | 000,067,360 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2010/01/22 08:56:24 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Stopped] -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2010/01/15 04:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/11/23 15:53:58 | 000,113,448 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\WTouch\WTouchService.exe -- (WTouchService)
SRV - [2009/11/23 15:53:56 | 004,497,704 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\WINDOWS\system32\Pen_Tablet.exe -- (TabletServicePen)
SRV - [2009/08/30 11:17:30 | 003,407,412 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc)
SRV - [2009/02/02 08:46:42 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2009/02/02 08:46:42 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2009/02/02 08:46:40 | 001,795,400 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe -- (SmcService)
SRV - [2009/02/02 08:46:40 | 000,320,840 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE -- (SNAC)
SRV - [2009/02/02 08:46:38 | 002,440,120 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2008/11/09 12:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2007/11/15 09:09:42 | 000,121,360 | ---- | M] (Logitech, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2007/08/11 20:05:27 | 003,093,872 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011/01/21 20:40:40 | 000,031,616 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vrtaucbl.sys -- (EuMusDesignVirtualAudioCableWdm) Virtual Audio Cable (WDM)
DRV - [2010/12/17 01:00:00 | 001,360,760 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110228.024\NAVEX15.SYS -- (NAVEX15)
DRV - [2010/12/17 01:00:00 | 000,086,008 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110228.024\NAVENG.SYS -- (NAVENG)
DRV - [2010/09/10 22:32:20 | 000,167,936 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WpsHelper.sys -- (WpsHelper)
DRV - [2010/05/27 00:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010/05/27 00:00:00 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/03/29 09:06:14 | 000,218,592 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2009/08/27 14:06:32 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV - [2009/06/29 21:42:00 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2009/05/20 10:54:06 | 000,013,736 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacomvhid.sys -- (wacomvhid)
DRV - [2009/03/28 11:01:08 | 000,123,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2009/03/27 13:23:12 | 000,023,064 | ---- | M] (Screaming Bee LLC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ScreamingBAudio.sys -- (SCREAMINGBDRIVER)
DRV - [2009/02/02 08:46:44 | 000,042,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\WPSDRVnt.sys -- (WPS)
DRV - [2009/02/02 08:46:42 | 000,319,664 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2009/02/02 08:46:42 | 000,279,600 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)
DRV - [2009/02/02 08:46:42 | 000,043,824 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2009/02/02 08:46:40 | 000,092,488 | ---- | M] (Symantec Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys -- (SysPlant)
DRV - [2009/02/02 08:46:40 | 000,049,536 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Teefer2.sys -- (Teefer2)
DRV - [2009/02/02 08:46:36 | 000,191,536 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2009/02/02 08:46:36 | 000,027,696 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2009/02/02 08:46:34 | 000,420,400 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2009/02/02 08:46:34 | 000,023,888 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\COH_Mon.sys -- (COH_Mon)
DRV - [2008/07/03 01:03:14 | 004,745,216 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/02/20 13:47:36 | 000,162,824 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\FTT3.sys -- (FTT3)
DRV - [2008/01/03 06:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation                          ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007/10/11 17:40:12 | 000,009,096 | R--- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\amdide.sys -- (amdide)
DRV - [2007/09/21 02:10:54 | 000,078,992 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2007/09/21 02:10:46 | 000,036,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2007/09/21 02:10:40 | 000,035,088 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007/09/21 02:10:26 | 000,063,120 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L8042mou.Sys -- (L8042mou)
DRV - [2007/09/21 02:10:20 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2007/04/16 16:46:34 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2007/02/16 10:12:36 | 000,011,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacommousefilter.sys -- (wacommousefilter)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A4 1A 25 59 CD D7 CB 01  [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=&SearchSource=13"
FF - prefs.js..extensions.enabledItems: ""
FF - prefs.js..extensions.enabledItems: [email protected]:4.0.21.0
FF - prefs.js..extensions.enabledItems: ""
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0
FF - prefs.js..extensions.enabledItems: [email protected]:4.5
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.071301000019
FF - prefs.js..extensions.enabledItems: ""
FF - prefs.js..extensions.enabledItems: {0CDC78A2-05A1-47F9-8810-A36BA7576D00}:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.14908
FF - prefs.js..extensions.enabledItems: ""
FF - prefs.js..extensions.enabledItems: ""
FF - prefs.js..extensions.enabledItems: ""
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=BABTDF&PC=BBLN&q="
 
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/06/17 14:21:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\MSN Toolbar\Platform\4.0.0417.0\Firefox [2010/10/09 16:00:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/10/09 16:01:02 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/26 21:37:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/27 13:36:00 | 000,000,000 | ---D | M]
 
[2009/04/30 14:29:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Extensions
[2011/02/28 20:51:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions
[2010/04/07 15:42:15 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010/05/11 18:14:21 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/12/28 01:15:04 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2009/07/16 23:33:11 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
[2009/06/04 14:21:28 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\[email protected]
[2010/10/28 12:43:34 | 000,001,840 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\bing.xml
[2010/04/11 20:36:02 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\searchplugins\winamp-search.xml
[2011/02/28 20:51:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/02/28 20:11:59 | 000,000,000 | ---D | M] (The Browser Highlighter) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\JONATHON\APPLICATION DATA\MOZILLA\EXTENSIONS\{EC8030F7-C20A-464F-9B0E-13A3A9E97384}\[email protected]
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\JONATHON\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\PFU1LARR.DEFAULT\EXTENSIONS\[email protected]
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\JONATHON\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\PFU1LARR.DEFAULT\EXTENSIONS\[email protected]
[2010/06/17 14:21:58 | 000,000,000 | ---D | M] (HP Smart Web Printing) -- C:\PROGRAM FILES\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON3
File not found (No name found) -- C:\PROGRAM FILES\INTERNET SAVING OPTIMIZER\3.6.0.4470\FF
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{0CDC78A2-05A1-47F9-8810-A36BA7576D00}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}
[2010/12/09 02:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
 
O1 HOSTS File: ([2007/08/10 22:58:33 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: 127.0.0.1  mpa.one.microsoft.com
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Bluetooth Connection Assistant]  File not found
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Jonathon\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jonathon\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/08 16:27:48 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011/02/28 21:25:39 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2011/02/28 21:25:35 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft XNA
[2011/02/28 21:12:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jonathon\Application Data\Malwarebytes
[2011/02/28 21:12:06 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/28 21:12:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/28 21:12:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/28 21:12:02 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/28 21:12:02 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/28 21:11:20 | 007,734,240 | ---- | C] (Malwarebytes Corporation                                   ) -- C:\Documents and Settings\Jonathon\Desktop\mbam-setup.exe
[2011/02/28 21:04:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2011/02/28 21:00:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jonathon\Desktop\Dial-a-fix-v0.60.0.24
[2011/02/28 20:50:58 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/02/28 15:41:41 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
[2011/02/18 10:27:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jonathon\Desktop\Prat-3.0-3.4.15
[2011/02/07 16:41:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jonathon\Desktop\Logs
[2010/12/31 21:24:24 | 000,883,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files\JavaSetup6u23.exe
[2010/12/31 21:05:48 | 000,883,488 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files\jre-6u23-windows-i586-iftw-k.exe
[2010/12/12 21:21:08 | 006,274,424 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Silverlight.exe
[2010/12/03 16:08:27 | 002,728,440 | ---- | C] (Microsoft Corporation) -- C:\Program Files\vcsetup.exe
[2010/12/03 15:40:19 | 003,324,232 | ---- | C] (Microsoft Corporation) -- C:\Program Files\vc_web.exe
[2004/01/12 00:00:00 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Program Files\msvcr71.dll
[6 C:\Documents and Settings\Jonathon\My Documents\*.tmp files -> C:\Documents and Settings\Jonathon\My Documents\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011/02/28 21:23:08 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/02/28 21:22:39 | 000,013,486 | ---- | M] () -- C:\WINDOWS\System32\Pen_Tablet.dat
[2011/02/28 21:22:25 | 000,200,819 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011/02/28 21:21:57 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/02/28 21:12:06 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/28 21:11:29 | 007,734,240 | ---- | M] (Malwarebytes Corporation                                   ) -- C:\Documents and Settings\Jonathon\Desktop\mbam-setup.exe
[2011/02/28 21:04:51 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/02/28 21:04:51 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/02/28 21:00:35 | 000,335,992 | ---- | M] () -- C:\Documents and Settings\Jonathon\Desktop\Dial-a-fix-v0.60.0.24.zip
[2011/02/28 15:42:17 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jonathon\Desktop\OTL.exe
[2011/02/27 22:30:29 | 000,096,968 | ---- | M] () -- C:\Documents and Settings\Jonathon\Desktop\WauQuickStart.exe
[2011/02/27 17:41:51 | 000,000,476 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Jonathon.job
[2011/02/27 13:57:16 | 000,000,223 | RHS- | M] () -- C:\boot.ini
[2011/02/27 13:40:23 | 000,000,215 | ---- | M] () -- C:\Documents and Settings\Jonathon\Desktop\Magicka.url
[2011/02/26 14:17:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/02/18 10:27:45 | 001,402,518 | ---- | M] () -- C:\Documents and Settings\Jonathon\Desktop\Prat-3.0-3.4.15.zip
[2011/02/13 20:54:55 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\Jonathon\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/02/13 20:54:55 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/12 08:09:12 | 000,456,304 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/02/12 08:09:12 | 000,075,210 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[6 C:\Documents and Settings\Jonathon\My Documents\*.tmp files -> C:\Documents and Settings\Jonathon\My Documents\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011/02/28 21:12:06 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/28 21:00:34 | 000,335,992 | ---- | C] () -- C:\Documents and Settings\Jonathon\Desktop\Dial-a-fix-v0.60.0.24.zip
[2011/02/27 22:29:55 | 000,096,968 | ---- | C] () -- C:\Documents and Settings\Jonathon\Desktop\WauQuickStart.exe
[2011/02/27 13:40:23 | 000,000,215 | ---- | C] () -- C:\Documents and Settings\Jonathon\Desktop\Magicka.url
[2011/02/18 10:27:43 | 001,402,518 | ---- | C] () -- C:\Documents and Settings\Jonathon\Desktop\Prat-3.0-3.4.15.zip
[2011/02/13 20:54:55 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/01/29 10:33:01 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/01/29 10:33:01 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/01/21 20:40:53 | 000,031,616 | ---- | C] () -- C:\WINDOWS\System32\drivers\vrtaucbl.sys
[2010/12/31 23:08:16 | 000,835,440 | ---- | C] () -- C:\Program Files\pbsvc.exe
[2010/12/31 22:53:25 | 002,434,856 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_bc2.exe
[2010/12/27 23:34:47 | 005,430,783 | ---- | C] () -- C:\Program Files\WMV r506 32bit DEVWORK.rar
[2010/12/24 00:00:04 | 001,661,959 | ---- | C] () -- C:\Program Files\wowmodelview0.5.07.zip
[2010/12/10 21:13:05 | 001,985,823 | ---- | C] () -- C:\Program Files\AtlasLoot-v6.01.01.zip
[2010/12/07 18:29:56 | 000,001,456 | ---- | C] () -- C:\Documents and Settings\Jonathon\Local Settings\Application Data\Adobe Save for Web 12.0 Prefs
[2010/12/04 14:55:53 | 000,022,222 | ---- | C] () -- C:\Program Files\souper3.zip
[2010/12/04 11:39:28 | 000,980,215 | ---- | C] () -- C:\Program Files\msvcdll-90.zip
[2010/12/04 11:36:56 | 007,683,072 | ---- | C] () -- C:\Program Files\WMV_Installer_v0701_r500_Win64.msi
[2010/12/04 11:33:47 | 000,000,000 | ---- | C] () -- C:\Program Files\wowmodelview-0.5.06beta.zip
[2010/12/03 16:37:20 | 005,928,476 | ---- | C] () -- C:\Program Files\WMV_Binary_v0701_r490_Win32_DevWork.zip
[2010/12/03 16:25:15 | 003,728,716 | ---- | C] () -- C:\Program Files\WoWModelViewer_0.6.0.3_Win32_Release.zip
[2010/12/03 16:10:54 | 005,167,176 | ---- | C] () -- C:\Program Files\WoW-2.4.0.8089-to-2.4.1.8125-enUS-patch.exe
[2010/12/03 15:36:37 | 007,091,330 | ---- | C] () -- C:\Program Files\WoWModelViewer_0.6.0.1_Win32_Debug.zip
[2010/10/10 00:56:26 | 000,037,336 | ---- | C] () -- C:\WINDOWS\System32\CleanMFT32.exe
[2010/08/16 08:54:25 | 000,013,486 | ---- | C] () -- C:\WINDOWS\System32\Pen_Tablet.dat
[2010/08/03 15:54:23 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Jonathon\Application Data\Adobe PNG Format CS5 Prefs
[2010/06/17 19:29:26 | 000,193,751 | ---- | C] () -- C:\WINDOWS\hpoins41.dat.temp
[2010/06/17 19:29:26 | 000,001,253 | ---- | C] () -- C:\WINDOWS\hpomdl41.dat.temp
[2010/06/17 14:13:10 | 000,193,751 | ---- | C] () -- C:\WINDOWS\hpoins41.dat
[2010/06/17 14:13:10 | 000,001,253 | ---- | C] () -- C:\WINDOWS\hpomdl41.dat
[2010/05/16 06:44:30 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
[2009/10/10 20:51:36 | 000,058,004 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/10/08 16:28:11 | 000,017,920 | ---- | C] () -- C:\Documents and Settings\Jonathon\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/10 15:48:01 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/04/30 14:29:50 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/04/27 20:49:35 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/04/27 20:05:16 | 000,000,760 | ---- | C] () -- C:\Documents and Settings\Jonathon\Application Data\setup_ldm.iss
[2009/03/12 20:02:45 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/03/12 20:00:08 | 003,767,296 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/12 13:55:32 | 000,138,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/12 13:55:32 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Jonathon\Application Data\PnkBstrK.sys
[2009/03/12 13:55:13 | 000,835,440 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2009/03/12 13:55:13 | 000,270,904 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2009/03/12 13:55:13 | 000,075,136 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2009/03/12 13:32:45 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2009/03/12 13:18:21 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/03/12 13:14:03 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/01/13 14:22:56 | 002,163,200 | ---- | C] () -- C:\Program Files\WoWModelViewer.exe
[2009/01/12 12:19:56 | 000,288,056 | ---- | C] () -- C:\Program Files\logo.bmp
[2008/11/03 01:27:22 | 000,245,760 | ---- | C] () -- C:\Program Files\glew32.dll
[2008/10/06 21:33:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/10/06 21:33:00 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2008/10/06 21:33:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/10/06 21:33:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2008/10/06 21:33:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/10/06 21:33:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/10/06 21:33:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2008/10/06 21:33:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2008/10/06 21:33:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/06/05 08:58:26 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/13 20:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2006/12/30 22:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001/08/23 03:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 03:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 03:00:00 | 000,456,304 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 03:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 03:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 03:00:00 | 000,075,210 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 03:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 03:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 03:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 03:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
 
========== LOP Check ==========
 
[2010/05/10 20:52:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/06/16 11:28:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/06/29 21:46:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/10/09 16:00:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/08/16 10:53:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/06/22 12:38:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/02/25 17:06:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Screaming Bee
[2011/02/28 21:22:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/07 18:27:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/10 17:55:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/09/01 15:53:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/10/28 19:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/05/10 20:52:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\DAEMON Tools Lite
[2010/06/29 15:52:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Datel
[2009/10/18 11:57:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\GetRightToGo
[2009/04/27 20:05:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Leadertech
[2010/08/19 18:58:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\MsgCnf
[2010/06/16 11:37:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\NCH Swift Sound
[2011/02/28 19:14:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Octoshape
[2010/04/19 16:14:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\RadioBar
[2011/02/28 19:06:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\RayV
[2009/12/07 21:12:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Screaming Bee
[2009/05/24 11:16:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\SPORE
[2010/12/05 08:33:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/02/28 20:44:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\uTorrent
[2009/03/28 11:05:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Windows Desktop Search
[2009/06/30 20:00:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\Windows Search
[2010/06/16 19:52:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jonathon\Application Data\WTouch
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >



:(


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
OS question, and Download error.
« Reply #15 on: March 01, 2011, 12:48:37 AM »
How is everything running on your end now?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline jony

  • Full Member
  • ***
  • Posts: 188
  • Karma: +0/-0
    • View Profile
    • http://forgehub.com
OS question, and Download error.
« Reply #16 on: March 01, 2011, 12:49:24 AM »
[quote name='guestolo' date='28 February 2011 - 11:48 PM' timestamp='1298958517' post='476641']
How is everything running on your end now?
[/quote]


Very smooth

:(


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
OS question, and Download error.
« Reply #17 on: March 01, 2011, 01:03:50 AM »
I see some leftovers
Can you do the following

Double  click on OTL.exe and Run it
  • Under the [color="#0000FF"]Custom Scans/Fixes[/color] box at the bottom, copy/paste in the following in the quote box below. don't include the word Quote please
    Quote
    :OTL
    SRV - [2010/01/15 04:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
    FF - prefs.js..browser.search.defaultengine: ""
    FF - prefs.js..browser.search.defaultthis.engineName: ""
    FF - prefs.js..browser.search.defaulturl: "http://search.condui...&q={searchTerms}"
    FF - prefs.js..browser.search.selectedEngine: ""
    FF - prefs.js..browser.startup.homepage: "http://search.condui...SearchSource=13"
    FF - prefs.js..extensions.enabledItems: ""
    FF - prefs.js..extensions.enabledItems: ""
    FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0
    FF - prefs.js..extensions.enabledItems: ""
    FF - prefs.js..extensions.enabledItems: {0CDC78A2-05A1-47F9-8810-A36BA7576D00}:1.0
    FF - prefs.js..extensions.enabledItems: ""
    FF - prefs.js..extensions.enabledItems: ""
    FF - prefs.js..extensions.enabledItems: ""
    [2010/04/07 15:42:15 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
    [2010/12/28 01:15:04 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\Jonathon\Application Data\Mozilla\Firefox\Profiles\pfu1larr.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\JONATHON\APPLICATION DATA\MOZILLA\EXTENSIONS\{EC8030F7-C20A-464F-9B0E-13A3A9E97384}\[email protected]
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\JONATHON\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\PFU1LARR.DEFAULT\EXTENSIONS\[email protected]
    File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\JONATHON\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\PFU1LARR.DEFAULT\EXTENSIONS\[email protected]
    File not found (No name found) -- C:\PROGRAM FILES\INTERNET SAVING OPTIMIZER\3.6.0.4470\FF
    File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{0CDC78A2-05A1-47F9-8810-A36BA7576D00}
    File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{D9ADB0A8-7BFB-498D-9880-EE78A81CCFA0}
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    :Files
    C:\Program Files\McAfee Security Scan
    :Commands
    [EmptyTemp]
    [EmptyFlash]
    [Reboot]

  • Then click the [color="#FF0000"]Run Fix[/color] button at the top
  • Let the program run unhindered, reboot the PC when it is done

On startup, Allow OTL to run if prompted
A log should open, can you post it please
A copy of this log can also be found in
C:\_OTL\Moved Files folder

In addition, I see reference to PCTools in your logs, related to Spyware Doctor, did you uninstall it at one time?
I'm curious as I don't see it in your Add/Remove Programs
Do you?

Also, Can you do the following
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
« Last Edit: March 01, 2011, 01:04:26 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here