﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / Hijackthis Log / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Thu, 21 Aug 2008 21:28:05 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>You're welcome:)</description><pubDate>Thu, 27 Mar 2008 05:18:43 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>Thank you very much for everything! It is much appreciated! I will make sure my husband has a link somewhere on his E-Sports website linking back to this place for technical assistance for our gamers. Thanks a million!</description><pubDate>Wed, 26 Mar 2008 22:35:04 GMT</pubDate><dc:creator>Cheragain</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>Your log is clean:),please do the following:&lt;br&gt;&lt;br&gt;Please download [b]OTMoveIt[/b] by [b]OldTimer[/b]:&lt;br&gt;[url]http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe[/url]&lt;br&gt;Save it to your desktop.&lt;br&gt;Please double-click OTMoveIt.exe to run it.&lt;br&gt;Click on the 'Cleanup' button [IMG]http://img.photobucket.com/albums/v624/29wood/Clipboard01cleanup.gif[/IMG]&lt;br&gt;When you do this a text file named cleanup.txt will be downloaded from the internet. &lt;br&gt;If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so. &lt;br&gt;When the 'Confirm' box appears click 'Yes'.&lt;br&gt;[b]Restart your pc when prompted.[/b]&lt;br&gt;&lt;br&gt;You should take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:&lt;br&gt;&lt;br&gt;[b][color="blue"]Simple and easy ways to keep your computer safe and secure on the Internet[/color][/b]:&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial82.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]How to prevent Malware[/color][/b]:&lt;br&gt;[url]http://users.telenet.be/bluepatchy/miekiemoes/prevention.html[/url]&lt;br&gt;&lt;br&gt;[B][color="blue"]So how did I get infected in the first place[/color][/B]:&lt;br&gt;[URL]http://forums.spybot.info/showthread.php?t=279[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Malware Cleanup Programs and Preventative Procedures[/color][/B]: &lt;br&gt;[URL]http://russelltexas.com/malware/allclear.htm[/URL]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 1[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 2[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html[/url]</description><pubDate>Wed, 26 Mar 2008 18:13:35 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>Main Text:&lt;br&gt;&lt;br&gt;Deckard's System Scanner v20071014.68&lt;br&gt;Run by OMG HI on 2008-03-26 10:58:32&lt;br&gt;Computer is in Normal Mode.&lt;br&gt;--------------------------------------------------------------------------------&lt;br&gt;&lt;br&gt;-- System Restore --------------------------------------------------------------&lt;br&gt;&lt;br&gt;Successfully created a Deckard's System Scanner Restore Point.&lt;br&gt;&lt;br&gt;&lt;br&gt;-- Last 5 Restore Point(s) --&lt;br&gt;98: 2008-03-26 15:58:42 UTC - RP186 - Deckard's System Scanner Restore Point&lt;br&gt;97: 2008-03-25 21:47:59 UTC - RP185 - ComboFix created restore point&lt;br&gt;96: 2008-03-25 21:43:43 UTC - RP184 - Installed Java(TM) 6 Update 5&lt;br&gt;95: 2008-03-25 21:42:36 UTC - RP183 - Removed Java(TM) 6 Update 5&lt;br&gt;94: 2008-03-25 19:12:21 UTC - RP182 - Installed Java(TM) 6 Update 5&lt;br&gt;&lt;br&gt;&lt;br&gt;-- First Restore Point -- &lt;br&gt;1: 2007-12-27 01:50:06 UTC - RP89 - System Checkpoint&lt;br&gt;&lt;br&gt;&lt;br&gt;Backed up registry hives.&lt;br&gt;Performed disk cleanup.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- HijackThis (run as OMG HI.exe) ----------------------------------------------&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 11:00 AM I love you Shaun!, on 03/26/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16608)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe&lt;br&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;br&gt;C:\PROGRA~1\Grisoft\AVG7\avgcc.exe&lt;br&gt;C:\WINDOWS\CTHELPER.EXE&lt;br&gt;C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe&lt;br&gt;C:\WINDOWS\system32\CTXFIHLP.EXE&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&lt;br&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;br&gt;C:\PROGRA~1\Grisoft\AVG7\avgemc.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\WINDOWS\SYSTEM32\CTXFISPI.EXE&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br&gt;C:\WINDOWS\System32\nvsvc32.exe&lt;br&gt;C:\WINDOWS\system32\PnkBstrA.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br&gt;C:\WINDOWS\system32\wscntfy.exe&lt;br&gt;C:\Documents and Settings\OMG HI\Desktop\dss.exe&lt;br&gt;C:\PROGRA~1\TRENDM~1\HIJACK~1\OMG HI.exe&lt;br&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br&gt;O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup&lt;br&gt;O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install&lt;br&gt;O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit&lt;br&gt;O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP&lt;br&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;br&gt;O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE&lt;br&gt;O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=011508 serial=dr12wes-3007622-euw lang=EN&lt;br&gt;O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')&lt;br&gt;O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab&lt;br&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;br&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1193940609155&lt;br&gt;O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab&lt;br&gt;O16 - DPF: {BBF89515-EDB6-4236-8FBB-B6045290076D} (Image Uploader ShellCombo Control) - http://www.totsites.com/admin/includes/imageuploader2/ImageUploader4.cab&lt;br&gt;O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;br&gt;O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe&lt;br&gt;O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe&lt;br&gt;O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe&lt;br&gt;O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br&gt;O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe&lt;br&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe&lt;br&gt;O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe&lt;br&gt;O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;br&gt;O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;br&gt;O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 7166 bytes&lt;br&gt;&lt;br&gt;-- File Associations -----------------------------------------------------------&lt;br&gt;&lt;br&gt;All associations okay.&lt;br&gt;&lt;br&gt;&lt;br&gt;-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------&lt;br&gt;&lt;br&gt;S3 ENTECH - c:\windows\system32\drivers\entech.sys &lt;Not Verified; EnTech Taiwan; PowerStrip&gt;&lt;br&gt;S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys &lt;Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------&lt;br&gt;&lt;br&gt;S4 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" &lt;Not Verified; Apple, Inc.; Apple Mobile Device Service&gt;&lt;br&gt;S4 Eveetor - &lt;br&gt;&lt;br&gt;&lt;br&gt;-- Device Manager: Disabled ----------------------------------------------------&lt;br&gt;&lt;br&gt;Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}&lt;br&gt;Description: Universal Serial Bus (USB) Controller&lt;br&gt;Device ID: PCI\VEN_8086&amp;DEV_24DD&amp;SUBSYS_42468086&amp;REV_02\3&amp;267A616A&amp;0&amp;EF&lt;br&gt;Manufacturer: &lt;br&gt;Name: Universal Serial Bus (USB) Controller&lt;br&gt;PNP Device ID: PCI\VEN_8086&amp;DEV_24DD&amp;SUBSYS_42468086&amp;REV_02\3&amp;267A616A&amp;0&amp;EF&lt;br&gt;Service: &lt;br&gt;&lt;br&gt;Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}&lt;br&gt;Description: Multimedia Audio Controller&lt;br&gt;Device ID: PCI\VEN_8086&amp;DEV_24D5&amp;SUBSYS_E0018086&amp;REV_02\3&amp;267A616A&amp;0&amp;FD&lt;br&gt;Manufacturer: &lt;br&gt;Name: Multimedia Audio Controller&lt;br&gt;PNP Device ID: PCI\VEN_8086&amp;DEV_24D5&amp;SUBSYS_E0018086&amp;REV_02\3&amp;267A616A&amp;0&amp;FD&lt;br&gt;Service: &lt;br&gt;&lt;br&gt;&lt;br&gt;-- Scheduled Tasks -------------------------------------------------------------&lt;br&gt;&lt;br&gt;2008-03-25 13:05:35      1512 --a------ C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job&lt;br&gt;&lt;br&gt;&lt;br&gt;-- Files created between 2008-02-26 and 2008-03-26 -----------------------------&lt;br&gt;&lt;br&gt;2008-03-25 20:23:36         0 d-------- C:\fsaua.data&lt;br&gt;2008-03-25 18:19:02         0 dr-h----- C:\Documents and Settings\OMG HI\Recent&lt;br&gt;2008-03-25 17:45:53      3592 --a------ C:\Start_.cmd&lt;br&gt;2008-03-25 17:45:05         0 d-------- C:\327882R2FWJFW&lt;br&gt;2008-03-25 16:47:20     68096 --a------ C:\WINDOWS\system32\zip.exe&lt;br&gt;2008-03-25 16:47:20     98816 --a------ C:\WINDOWS\system32\sed.exe&lt;br&gt;2008-03-25 16:47:20     80412 --a------ C:\WINDOWS\system32\grep.exe&lt;br&gt;2008-03-25 16:47:20     73728 --a------ C:\WINDOWS\system32\fdsv.exe &lt;Not Verified; Smallfrogs Studio; &gt;&lt;br&gt;2008-03-25 16:46:20         0 d-------- C:\Program Files\CCleaner&lt;br&gt;2008-03-25 16:45:14         0 d-------- C:\Program Files\Trend Micro&lt;br&gt;2008-03-25 16:43:44         0 d-------- C:\Program Files\Common Files\Java&lt;br&gt;2008-03-25 16:24:15         0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun&lt;br&gt;2008-03-25 15:14:53         0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia&lt;br&gt;2008-03-25 15:12:36         0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla&lt;br&gt;2008-03-25 15:11:49         0 d--h----- C:\Documents and Settings\Administrator\Templates&lt;br&gt;2008-03-25 15:11:49         0 dr------- C:\Documents and Settings\Administrator\Start Menu&lt;br&gt;2008-03-25 15:11:49         0 dr-h----- C:\Documents and Settings\Administrator\SendTo&lt;br&gt;2008-03-25 15:11:49         0 d--h----- C:\Documents and Settings\Administrator\Recent&lt;br&gt;2008-03-25 15:11:49         0 d--h----- C:\Documents and Settings\Administrator\PrintHood&lt;br&gt;2008-03-25 15:11:49    786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT&lt;br&gt;2008-03-25 15:11:49         0 d--h----- C:\Documents and Settings\Administrator\NetHood&lt;br&gt;2008-03-25 15:11:49         0 d-------- C:\Documents and Settings\Administrator\My Documents&lt;br&gt;2008-03-25 15:11:49         0 d--h----- C:\Documents and Settings\Administrator\Local Settings&lt;br&gt;2008-03-25 15:11:49         0 d-------- C:\Documents and Settings\Administrator\Favorites&lt;br&gt;2008-03-25 15:11:49         0 d-------- C:\Documents and Settings\Administrator\Desktop&lt;br&gt;2008-03-25 15:11:49         0 d--hs---- C:\Documents and Settings\Administrator\Cookies&lt;br&gt;2008-03-25 15:11:49         0 dr-h----- C:\Documents and Settings\Administrator\Application Data&lt;br&gt;2008-03-25 15:11:49         0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft&lt;br&gt;2008-03-25 14:03:22         0 d-------- C:\Documents and Settings\OMG HI\Application Data\GetRightToGo&lt;br&gt;2008-03-25 13:38:35         0 d-------- C:\Documents and Settings\OMG HI\.SunDownloadManager&lt;br&gt;2008-03-25 13:06:15         0 d-------- C:\Program Files\Spyware Doctor&lt;br&gt;2008-03-25 13:06:15         0 d-------- C:\Documents and Settings\OMG HI\Application Data\PC Tools&lt;br&gt;2008-03-25 13:05:41         0 d-------- C:\Documents and Settings\LocalService\Application Data\Webroot&lt;br&gt;2008-03-25 13:05:16         0 d-------- C:\Program Files\Webroot&lt;br&gt;2008-03-25 13:05:16         0 d-------- C:\Documents and Settings\OMG HI\Application Data\Webroot&lt;br&gt;2008-03-25 13:05:16         0 d-------- C:\Documents and Settings\All Users\Application Data\Webroot&lt;br&gt;2008-03-25 13:02:09         0 d-------- C:\Documents and Settings\OMG HI\Application Data\Malwarebytes&lt;br&gt;2008-03-25 13:02:02         0 d-------- C:\Program Files\Malwarebytes' Anti-Malware&lt;br&gt;2008-03-25 13:02:02         0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes&lt;br&gt;2008-03-25 12:54:23       164 --a------ C:\install.dat&lt;br&gt;2008-03-25 12:46:05         0 d-------- C:\Program Files\Advanced Spyware Remover&lt;br&gt;2008-03-14 19:25:56         0 d-------- C:\Program Files\Lavasoft&lt;br&gt;2008-03-14 19:25:56         0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft&lt;br&gt;2008-03-14 19:20:00         0 d--h----- C:\WINDOWS\PIF&lt;br&gt;2008-03-11 10:39:08     41984 -----n--- C:\WINDOWS\Ctregrun.exe &lt;Not Verified; Creative Technology Ltd; Creative On-line Registration System&gt;&lt;br&gt;2008-03-11 10:38:28         0 d-------- C:\Program Files\Audible&lt;br&gt;2008-03-11 10:34:02     25088 -----n--- C:\WINDOWS\system32\CTSVCCTL.EXE &lt;Not Verified; Creative Technology Ltd; Creative Service Control&gt;&lt;br&gt;2008-03-11 10:34:02     44032 -----n--- C:\WINDOWS\system32\CTSVCCDA.EXE &lt;Not Verified; Creative Technology Ltd; Creative Service for CDROM Access&gt;&lt;br&gt;2008-03-11 10:33:45         0 d-------- C:\Program Files\Common Files\Creative&lt;br&gt;2008-03-11 10:33:44         0 d--h----- C:\Program Files\Creative Installation Information&lt;br&gt;2008-03-06 21:31:43     22300 --ah----- C:\WINDOWS\system32\mlfcache.dat&lt;br&gt;2008-03-02 20:19:39    216064 --a------ C:\WINDOWS\iun3405.exe &lt;Not Verified; Indigo Rose Corporation; Indigo Rose Corporation unin32&gt;&lt;br&gt;2008-03-02 20:19:37         0 d-------- C:\Program Files\The Princeton Review&lt;br&gt;2008-02-29 22:33:53         0 d-------- C:\Program Files\Mozilla Thunderbird&lt;br&gt;&lt;br&gt;&lt;br&gt;-- Find3M Report ---------------------------------------------------------------&lt;br&gt;&lt;br&gt;2008-03-26 00:33:33         0 d-------- C:\Documents and Settings\OMG HI\Application Data\Xfire&lt;br&gt;2008-03-25 23:49:41         0 d-------- C:\Program Files\Steam&lt;br&gt;2008-03-25 23:45:05         0 d-------- C:\Program Files\Xfire&lt;br&gt;2008-03-25 20:24:34         0 d-------- C:\Documents and Settings\OMG HI\Application Data\Skype&lt;br&gt;2008-03-25 20:17:43         0 d-------- C:\Documents and Settings\OMG HI\Application Data\AVG7&lt;br&gt;2008-03-25 18:27:52         0 d-------- C:\Documents and Settings\OMG HI\Application Data\skypePM&lt;br&gt;2008-03-25 16:44:31         0 d-------- C:\Program Files\Java&lt;br&gt;2008-03-25 16:43:44         0 d-------- C:\Program Files\Common Files&lt;br&gt;2008-03-25 13:49:58         0 d-------- C:\Program Files\mIRC1&lt;br&gt;2008-03-25 13:44:55         0 d-------- C:\Program Files\Diino&lt;br&gt;2008-03-25 13:44:24         0 d-------- C:\Program Files\Oberon Media&lt;br&gt;2008-03-25 00:02:56         0 d-------- C:\Documents and Settings\OMG HI\Application Data\NoNameScript&lt;br&gt;2008-03-21 20:12:17         0 d-------- C:\Documents and Settings\OMG HI\Application Data\OpenOffice.org2&lt;br&gt;2008-03-15 13:52:19         0 d-------- C:\Program Files\Winamp&lt;br&gt;2008-03-14 19:25:21         0 d-------- C:\Program Files\Common Files\Wise Installation Wizard&lt;br&gt;2008-03-13 10:37:04         0 d--h----- C:\Program Files\InstallShield Installation Information&lt;br&gt;2008-03-11 20:14:35         0 d-------- C:\Documents and Settings\OMG HI\Application Data\Adobe&lt;br&gt;2008-03-11 10:43:56         0 d-------- C:\Documents and Settings\OMG HI\Application Data\mIRC&lt;br&gt;2008-03-11 10:39:07         0 d-------- C:\Program Files\Creative&lt;br&gt;2008-03-04 20:55:13         0 d-------- C:\Documents and Settings\OMG HI\Application Data\Ventrilo&lt;br&gt;2008-02-29 22:33:17         0 d-------- C:\Program Files\Mozilla Thunderbirdbac&lt;br&gt;2008-02-27 15:16:26         0 d-------- C:\Documents and Settings\OMG HI\Application Data\Identities&lt;br&gt;2008-02-22 14:43:03         0 d-------- C:\Program Files\America's Army&lt;br&gt;2008-02-22 14:42:59         0 d-------- C:\Program Files\America's Army Server Manager&lt;br&gt;2008-02-01 14:50:00         0 d-------- C:\Documents and Settings\OMG HI\Application Data\Apple Computer&lt;br&gt;2008-02-01 14:49:14         0 d-------- C:\Program Files\iTunes&lt;br&gt;2008-02-01 14:48:54         0 d-------- C:\Program Files\iPod&lt;br&gt;2008-02-01 14:47:31         0 d-------- C:\Program Files\QuickTime&lt;br&gt;2008-02-01 14:45:49         0 d-------- C:\Program Files\Apple Software Update&lt;br&gt;2008-02-01 14:45:09         0 d-------- C:\Program Files\Common Files\Apple&lt;br&gt;2008-01-31 23:10:41         0 d-------- C:\Program Files\SmartFTP Client 2.0&lt;br&gt;2008-01-22 19:23:34      3106 --a------ C:\WINDOWS\mozver.dat&lt;br&gt;&lt;br&gt;&lt;br&gt;-- Registry Dump ---------------------------------------------------------------&lt;br&gt;&lt;br&gt;*Note* empty entries &amp; legit default entries are not shown&lt;br&gt;&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"NvCplDaemon"="RUNDLL32.exe" [08/04/2004 02:56 AM I love you Shaun! C:\WINDOWS\system32\rundll32.exe]&lt;br&gt;"nwiz"="nwiz.exe" [09/17/2007 02:07 AM I love you Shaun! C:\WINDOWS\system32\nwiz.exe]&lt;br&gt;"NvMediaCenter"="RUNDLL32.exe" [08/04/2004 02:56 AM I love you Shaun! C:\WINDOWS\system32\rundll32.exe]&lt;br&gt;"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [12/20/2007 04:51 PM I love you Shaun!]&lt;br&gt;"CTHelper"="CTHELPER.EXE" [08/17/2006 12:32 PM I love you Shaun! C:\WINDOWS\CTHELPER.EXE]&lt;br&gt;"CTxfiHlp"="CTXFIHLP.EXE" [08/17/2006 12:32 PM I love you Shaun! C:\WINDOWS\system32\CTXFIHLP.EXE]&lt;br&gt;"CorelDRAW Graphics Suite 11b"="C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe" []&lt;br&gt;"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [07/25/2007 05:02 PM I love you Shaun!]&lt;br&gt;"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM I love you Shaun!]&lt;br&gt;&lt;br&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 02:56 AM I love you Shaun!]&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]&lt;br&gt;"DisableRegistryTools"=0 (0x0)&lt;br&gt;"HideLegacyLogonScripts"=0 (0x0)&lt;br&gt;"HideLogoffScripts"=0 (0x0)&lt;br&gt;"RunLogonScriptSync"=1 (0x1)&lt;br&gt;"RunStartupScriptSync"=1 (0x1)&lt;br&gt;"HideStartupScripts"=0 (0x0)&lt;br&gt;&lt;br&gt;[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]&lt;br&gt;"HideLegacyLogonScripts"=0 (0x0)&lt;br&gt;"HideLogoffScripts"=0 (0x0)&lt;br&gt;"RunLogonScriptSync"=1 (0x1)&lt;br&gt;"RunStartupScriptSync"=1 (0x1)&lt;br&gt;"HideStartupScripts"=0 (0x0)&lt;br&gt;"disableregistrytools"=0 (0x0)&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]&lt;br&gt;@="Service"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]&lt;br&gt;@="Service"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]&lt;br&gt;@="Service"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]&lt;br&gt;@="Service"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]&lt;br&gt;@="Volume shadow copy"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]&lt;br&gt;path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk&lt;br&gt;backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]&lt;br&gt;path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk&lt;br&gt;backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]&lt;br&gt;path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk&lt;br&gt;backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]&lt;br&gt;"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]&lt;br&gt;&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]&lt;br&gt;"c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]&lt;br&gt;"C:\Program Files\Spyware Doctor\pctsTray.exe"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]&lt;br&gt;"C:\Program Files\iTunes\iTunesHelper.exe"&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]&lt;br&gt;"C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]&lt;br&gt;"C:\Program Files\Messenger\msmsgs.exe" /background&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]&lt;br&gt;"C:\Program Files\QuickTime\qttask.exe" -atboottime&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]&lt;br&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]&lt;br&gt;C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe&lt;br&gt;&lt;br&gt;[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]&lt;br&gt;"usnjsvc"=3 (0x3)&lt;br&gt;"Pml Driver HPZ12"=2 (0x2)&lt;br&gt;"iPod Service"=3 (0x3)&lt;br&gt;"Creative Service for CDROM Access"=2 (0x2)&lt;br&gt;"Apple Mobile Device"=2 (0x2)&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- End of Deckard's System Scanner: finished at 2008-03-26 11:00:50 ------------&lt;br&gt;&lt;br&gt;&lt;br&gt;Extra Text:&lt;br&gt;&lt;br&gt;Deckard's System Scanner v20071014.68&lt;br&gt;Extra logfile - please post this as an attachment with your post.&lt;br&gt;--------------------------------------------------------------------------------&lt;br&gt;&lt;br&gt;-- System Information ----------------------------------------------------------&lt;br&gt;&lt;br&gt;Microsoft Windows XP Professional (build 2600) SP 2.0&lt;br&gt;Architecture: X86; Language: English&lt;br&gt;&lt;br&gt;CPU 0: Intel(R) Pentium(R) 4 CPU 3.00GHz&lt;br&gt;CPU 1: Intel(R) Pentium(R) 4 CPU 3.00GHz&lt;br&gt;Percentage of Memory in Use: 34%&lt;br&gt;Physical Memory (total/avail): 1022.73 MiB / 672.01 MiB&lt;br&gt;Pagefile Memory (total/avail): 2464.42 MiB / 2202.48 MiB&lt;br&gt;Virtual Memory (total/avail): 2047.88 MiB / 1927.38 MiB&lt;br&gt;&lt;br&gt;A: is Removable (No Media)&lt;br&gt;C: is Fixed (NTFS) - 127.99 GiB total, 36.55 GiB free. &lt;br&gt;D: is CDROM (Unformatted)&lt;br&gt;E: is CDROM (CDFS)&lt;br&gt;F: is Fixed (NTFS) - 127.99 GiB total, 98.39 GiB free. &lt;br&gt;&lt;br&gt;\\.\PHYSICALDRIVE1 - WDC WD1600JB-00FUA0 - 149.05 GiB - 1 partition&lt;br&gt;  \PARTITION0 (bootable) - Installable File System - 127.99 GiB - C:&lt;br&gt;&lt;br&gt;\\.\PHYSICALDRIVE0 - WDC WD1600JB-00REA0 - 149.05 GiB - 1 partition&lt;br&gt;  \PARTITION0 (bootable) - Installable File System - 127.99 GiB - F:&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- Security Center -------------------------------------------------------------&lt;br&gt;&lt;br&gt;AUOptions is scheduled to auto-install.&lt;br&gt;Windows Internal Firewall is disabled.&lt;br&gt;&lt;br&gt;AV: Spy Sweeper with AntiVirus v5.5.7.124 (Webroot Software Inc) [COLOR=RED]Disabled[/COLOR]&lt;br&gt;AV: AVG 7.5.519 v7.5.519 (Grisoft)&lt;br&gt;&lt;br&gt;[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]&lt;br&gt;"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"&lt;br&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"&lt;br&gt;"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"&lt;br&gt;"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"&lt;br&gt;&lt;br&gt;[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]&lt;br&gt;"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"&lt;br&gt;"C:\\Program Files\\Xfire\\xfire.exe"="C:\\Program Files\\Xfire\\xfire.exe:*:Enabled:Xfire"&lt;br&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"&lt;br&gt;"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"&lt;br&gt;"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"&lt;br&gt;"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"&lt;br&gt;"C:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"="C:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe:*:Enabled:Battlefield 2"&lt;br&gt;"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"&lt;br&gt;"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe:*:Enabled:SmartFTP Client 2.0"&lt;br&gt;"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"&lt;br&gt;"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"&lt;br&gt;&lt;br&gt;&lt;br&gt;-- Environment Variables -------------------------------------------------------&lt;br&gt;&lt;br&gt;ALLUSERSPROFILE=C:\Documents and Settings\All Users&lt;br&gt;APPDATA=C:\Documents and Settings\OMG HI\Application Data&lt;br&gt;CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip&lt;br&gt;CLIENTNAME=Console&lt;br&gt;CommonProgramFiles=C:\Program Files\Common Files&lt;br&gt;COMPUTERNAME=BOB&lt;br&gt;ComSpec=C:\WINDOWS\system32\cmd.exe&lt;br&gt;FP_NO_HOST_CHECK=NO&lt;br&gt;HOMEDRIVE=C:&lt;br&gt;HOMEPATH=\Documents and Settings\OMG HI&lt;br&gt;LOGONSERVER=\\BOB&lt;br&gt;NUMBER_OF_PROCESSORS=2&lt;br&gt;OS=Windows_NT&lt;br&gt;Path=C:\Program Files\Mozilla Firefox;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\QuickTime\QTSystem&lt;br&gt;PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH&lt;br&gt;PROCESSOR_ARCHITECTURE=x86&lt;br&gt;PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel&lt;br&gt;PROCESSOR_LEVEL=15&lt;br&gt;PROCESSOR_REVISION=0209&lt;br&gt;ProgramFiles=C:\Program Files&lt;br&gt;PROMPT=$P$G&lt;br&gt;QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip&lt;br&gt;SESSIONNAME=Console&lt;br&gt;SystemDrive=C:&lt;br&gt;SystemRoot=C:\WINDOWS&lt;br&gt;TEMP=C:\DOCUME~1\OMGHI~1\LOCALS~1\Temp&lt;br&gt;TMP=C:\DOCUME~1\OMGHI~1\LOCALS~1\Temp&lt;br&gt;USERDOMAIN=BOB&lt;br&gt;USERNAME=OMG HI&lt;br&gt;USERPROFILE=C:\Documents and Settings\OMG HI&lt;br&gt;windir=C:\WINDOWS&lt;br&gt;&lt;br&gt;&lt;br&gt;-- User Profiles ---------------------------------------------------------------&lt;br&gt;&lt;br&gt;OMG HI [I](admin)[/I]&lt;br&gt;Administrator [I](new local, admin)[/I]&lt;br&gt;&lt;br&gt;&lt;br&gt;-- Add/Remove Programs ---------------------------------------------------------&lt;br&gt;&lt;br&gt; --&gt; "C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x0009&lt;br&gt; --&gt; "C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x0009&lt;br&gt; --&gt; "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe" /remove /l0x0009&lt;br&gt; --&gt; "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MTP_U\Setup.exe" /remove /l0x0009&lt;br&gt; --&gt; "C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /l0x0009&lt;br&gt; --&gt; "C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x0009&lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E96A7F-AFE3-4171-87B1-583E376319E8}\setup.exe" -l0x9 &lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{19822917-61F6-4221-B1D0-1C3B8A06BE60}\setup.exe" -l0x9 &lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{19822917-61F6-4221-B1D0-1C3B8A06BE60}\setup.exe" -l0x9  /remove&lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9 &lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9 &lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 &lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9  /remove&lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7C9F6AF4-E9D9-47FE-BE4B-E637C2FCB410}\setup.exe" -l0x9 &lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7C9F6AF4-E9D9-47FE-BE4B-E637C2FCB410}\setup.exe" -l0x9  /remove&lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe" -l0x9 &lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe" -l0x9  /remove&lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A0B5225-B59B-4D72-B3FE-71AAA693A8E2}\setup.exe" -l0x9 &lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A0B5225-B59B-4D72-B3FE-71AAA693A8E2}\setup.exe" -l0x9  /remove&lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A9BB081B-C020-4D02-A763-D32204D2563D}\setup.exe" -l0x9 &lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A9BB081B-C020-4D02-A763-D32204D2563D}\setup.exe" -l0x9  /remove&lt;br&gt; --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C029DB0E-C59F-417A-90F8-88FD5B2C4AE7}\setup.exe" -l0x9 &lt;br&gt; --&gt; rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf&lt;br&gt;Ad-Aware 2007 --&gt; MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}&lt;br&gt;Adobe Flash Player 9 ActiveX --&gt; C:\WINDOWS\System32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock&lt;br&gt;Adobe Photoshop 7.0 --&gt; C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"&lt;br&gt;Adobe Photoshop CS --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe" -l0x9 &lt;br&gt;Adobe Reader 8.1.1 --&gt; MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81100000003}&lt;br&gt;Advanced Spyware Remover Free Edition --&gt; "C:\Program Files\Advanced Spyware Remover\unins000.exe"&lt;br&gt;AIM 6 --&gt; C:\Program Files\AIM6\uninst.exe&lt;br&gt;America's Army --&gt; MsiExec.exe /I{D873FA4B-C374-4F8A-8D9A-130DB56FAB16}&lt;br&gt;Apple Mobile Device Support --&gt; MsiExec.exe /I{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}&lt;br&gt;Apple Software Update --&gt; MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}&lt;br&gt;AquaMark3 --&gt; C:\PROGRA~1\AQUAMA~1\UNWISE.EXE C:\PROGRA~1\AQUAMA~1\INSTALL.LOG&lt;br&gt;AudibleManager --&gt; C:\Program Files\Audible\Bin\Upgrade.exe /Uninstall&lt;br&gt;AVG 7.5 --&gt; C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL&lt;br&gt;Battlecraft 1942 --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BBD40517-2A65-4683-A164-E1F1E5770BAB}\setup.exe" -l0x9 &lt;br&gt;Battlefield 1942 --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}\setup.exe" -l0x9 &lt;br&gt;Battlefield 1942 Secret Weapons of WWII Demo --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{909354DE-C180-4B00-B61F-9A6D805E5796}\setup.exe" -l0x9 &lt;br&gt;Battlefield 1942: The Road To Rome --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}\setup.exe" -l0x9 &lt;br&gt;Battlefield 2(TM) Demo --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8BECF123-B0EF-4E51-B7F3-923EFE15CC4A}\setup.exe" -l0x9  -removeonly&lt;br&gt;CCleaner (remove only) --&gt; "C:\Program Files\CCleaner\uninst.exe"&lt;br&gt;Counter-Strike: Source --&gt; "C:\Program Files\Steam\steam.exe" steam://uninstall/240&lt;br&gt;Coupon Printer for Windows --&gt; "C:\Program Files\Coupons\uninstall.exe" "/U:C:\Program Files\Coupons\Uninstall\uninstall.xml"&lt;br&gt;Creative Audio Console --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E96A7F-AFE3-4171-87B1-583E376319E8}\setup.exe" -l0x9  /remove&lt;br&gt;Creative MediaSource 5 --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\SETUP.EXE" -l0x9  /remove&lt;br&gt;Creative Removable Disk Manager --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9  /remove&lt;br&gt;Creative System Information --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9  /remove&lt;br&gt;Creative ZEN V Series (R2) --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9862E0CB-4727-4FFC-963A-E22A9E9EC10C}\SETUP.EXE" -l0x9  /remove&lt;br&gt;DVD Decrypter (Remove Only) --&gt; "C:\Program Files\DVD Decrypter\uninstall.exe"&lt;br&gt;Fun Morph 3.0 --&gt; "C:\Program Files\Zeallsoft\Fun Morph\unins000.exe"&lt;br&gt;GMAT Diagnostic --&gt; C:\WINDOWS\iun3405.exe C:\Program Files\The Princeton Review\ACT Diagnostic&lt;br&gt;HijackThis 2.0.2 --&gt; "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall&lt;br&gt;Hoster Player --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{293B2937-8AFE-4431-A569-FBFEFE638758}\hosterplayersetup.exe" -l0x9 &lt;br&gt;HP Extended Capabilities 4.7 --&gt; C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat&lt;br&gt;HP Image Zone 4.7 --&gt; C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat&lt;br&gt;HP PSC &amp; OfficeJet 4.7 --&gt; "C:\Program Files\HP\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup\hpzscr01.exe" -datfile hposcr05.dat&lt;br&gt;HP Software Update --&gt; MsiExec.exe /X{64FC0C98-B035-4530-B15D-3D30610B6DF1}&lt;br&gt;Intel(R) PRO Network Adapters and Drivers --&gt; Prounstl.exe&lt;br&gt;iTunes --&gt; MsiExec.exe /I{B85C4D19-6CEB-48CF-BD98-C887AC8C6F94}&lt;br&gt;Java(TM) 6 Update 5 --&gt; MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}&lt;br&gt;LimeWire PRO 4.9.23 --&gt; "C:\Program Files\LimeWire\uninstall.exe"&lt;br&gt;Logitech QuickCam --&gt; MsiExec.exe /X{364EC092-93CF-4DDC-9D7A-7278452028E0}&lt;br&gt;Logitech® Camera Driver --&gt; "C:\Program Files\Common Files\LogiShrd\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT&lt;br&gt;Malwarebytes' Anti-Malware --&gt; "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"&lt;br&gt;Mozilla Firefox (2.0.0.13) --&gt; C:\Program Files\Mozilla Firefox\uninstall\helper.exe&lt;br&gt;Mozilla Thunderbird (2.0.0.12) --&gt; C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe&lt;br&gt;MVision --&gt; MsiExec.exe /I{35725FBC-A136-4A46-9F29-091759D9BB93}&lt;br&gt;NoNameScript --&gt; C:\Documents and Settings\OMG HI\Application Data\NoNameScript\nnuninstall.exe&lt;br&gt;NVIDIA Drivers --&gt; C:\WINDOWS\System32\nvudisp.exe UninstallGUI&lt;br&gt;OpenOffice.org 2.0 --&gt; MsiExec.exe /I{462B19F5-C371-4C15-A170-797E93DD490C}&lt;br&gt;QuickTime --&gt; MsiExec.exe /I{6EC874C2-F950-4B7E-A5B7-B1066D6B74AA}&lt;br&gt;Skype™ 3.6 --&gt; MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}&lt;br&gt;SmartFTP Client --&gt; MsiExec.exe /I{C169D3BB-9A27-43F5-9979-09A0D65FE95C}&lt;br&gt;SmartFTP Client 2.0 Setup Files (remove only) --&gt; "C:\Program Files\SmartFTP Client 2.0 Setup Files\uninst-sftp.exe"&lt;br&gt;SmartFTP Client 2.5 Setup Files (remove only) --&gt; C:\Program Files\SmartFTP Client 2.5 Setup Files\uninst-sftp.exe&lt;br&gt;Sony USB Driver --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}\Setup.exe" UNINSTALL&lt;br&gt;Spy Sweeper --&gt; "C:\Program Files\Webroot\Spy Sweeper\unins000.exe"&lt;br&gt;Spyware Doctor 5.5 --&gt; C:\Program Files\Spyware Doctor\unins000.exe /LOG&lt;br&gt;Steam --&gt; MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}&lt;br&gt;System Requirements Lab --&gt; C:\Program Files\SystemRequirementsLab\Uninstall.exe&lt;br&gt;TeamSpeak 2 RC2 --&gt; "C:\Program Files\Teamspeak2_RC2\unins000.exe"&lt;br&gt;The Night of Nights Map V2.0 for BF1942 --&gt; C:\Program Files\EA GAMES\Battlefield 1942\TNON_Uninstall.exe&lt;br&gt;Ventrilo Client --&gt; MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}&lt;br&gt;Winamp --&gt; "C:\Program Files\Winamp\UninstWA.exe"&lt;br&gt;Windows Imaging Component --&gt; "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"&lt;br&gt;Windows Live Messenger --&gt; MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}&lt;br&gt;Windows Live Sign-in Assistant --&gt; MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}&lt;br&gt;WinZip 11.1 --&gt; MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}&lt;br&gt;Xfire (remove only) --&gt; "C:\Program Files\Xfire\uninst.exe"&lt;br&gt;ZENcast Organizer --&gt; RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C029DB0E-C59F-417A-90F8-88FD5B2C4AE7}\setup.exe" -l0x9  /remove&lt;br&gt;&lt;br&gt;&lt;br&gt;-- Application Event Log -------------------------------------------------------&lt;br&gt;&lt;br&gt;Event Record #/Type1844 / Warning&lt;br&gt;Event Submitted/Written: 03/25/2008 05:57:29 PM&lt;br&gt;Event ID/Source: 1001 / MsiInstaller&lt;br&gt;Event Description:&lt;br&gt;Detection of product '{364EC092-93CF-4DDC-9D7A-7278452028E0}', feature 'QuickCam' failed during request for component '{62BA7C13-20BB-41F7-A6A4-482632CE53D4}'&lt;br&gt;&lt;br&gt;Event Record #/Type1843 / Warning&lt;br&gt;Event Submitted/Written: 03/25/2008 05:57:29 PM&lt;br&gt;Event ID/Source: 1004 / MsiInstaller&lt;br&gt;Event Description:&lt;br&gt;Detection of product '{364EC092-93CF-4DDC-9D7A-7278452028E0}', feature 'QuickCam', component '{B52C7B4D-F46F-438C-ADF2-05A138C57757}' failed.  The resource 'HKEY_CURRENT_USER\Software\Logitech\QuickCam10\DesktopShortcutKey' does not exist.&lt;br&gt;&lt;br&gt;Event Record #/Type1842 / Warning&lt;br&gt;Event Submitted/Written: 03/25/2008 05:57:29 PM&lt;br&gt;Event ID/Source: 1001 / MsiInstaller&lt;br&gt;Event Description:&lt;br&gt;Detection of product '{364EC092-93CF-4DDC-9D7A-7278452028E0}', feature 'QuickCam' failed during request for component '{62BA7C13-20BB-41F7-A6A4-482632CE53D4}'&lt;br&gt;&lt;br&gt;Event Record #/Type1841 / Warning&lt;br&gt;Event Submitted/Written: 03/25/2008 05:57:29 PM&lt;br&gt;Event ID/Source: 1004 / MsiInstaller&lt;br&gt;Event Description:&lt;br&gt;Detection of product '{364EC092-93CF-4DDC-9D7A-7278452028E0}', feature 'QuickCam', component '{B52C7B4D-F46F-438C-ADF2-05A138C57757}' failed.  The resource 'HKEY_CURRENT_USER\Software\Logitech\QuickCam10\DesktopShortcutKey' does not exist.&lt;br&gt;&lt;br&gt;Event Record #/Type1839 / Warning&lt;br&gt;Event Submitted/Written: 03/25/2008 05:57:22 PM&lt;br&gt;Event ID/Source: 1001 / MsiInstaller&lt;br&gt;Event Description:&lt;br&gt;Detection of product '{364EC092-93CF-4DDC-9D7A-7278452028E0}', feature 'QuickCam' failed during request for component '{C207503F-9631-4AF6-8CD2-D11260DBA3C5}'&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- Security Event Log ----------------------------------------------------------&lt;br&gt;&lt;br&gt;No Errors/Warnings found.&lt;br&gt;&lt;br&gt;&lt;br&gt;-- System Event Log ------------------------------------------------------------&lt;br&gt;&lt;br&gt;Event Record #/Type2186 / Error&lt;br&gt;Event Submitted/Written: 03/25/2008 08:02:52 PM&lt;br&gt;Event ID/Source: 7 / Cdrom&lt;br&gt;Event Description:&lt;br&gt;The device, \Device\CdRom1, has a bad block.&lt;br&gt;&lt;br&gt;Event Record #/Type2177 / Error&lt;br&gt;Event Submitted/Written: 03/25/2008 04:40:18 PM&lt;br&gt;Event ID/Source: 10005 / DCOM&lt;br&gt;Event Description:&lt;br&gt;DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""&lt;br&gt;in order to run the server:&lt;br&gt;{1BE1F766-5536-11D1-B726-00C04FB926AF}&lt;br&gt;&lt;br&gt;Event Record #/Type2176 / Error&lt;br&gt;Event Submitted/Written: 03/25/2008 04:39:45 PM&lt;br&gt;Event ID/Source: 10005 / DCOM&lt;br&gt;Event Description:&lt;br&gt;DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""&lt;br&gt;in order to run the server:&lt;br&gt;{A1F4E726-8CF1-11D1-BF92-0060081ED811}&lt;br&gt;&lt;br&gt;Event Record #/Type2175 / Warning&lt;br&gt;Event Submitted/Written: 03/25/2008 04:31:00 PM&lt;br&gt;Event ID/Source: 4226 / Tcpip&lt;br&gt;Event Description:&lt;br&gt;TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.&lt;br&gt;&lt;br&gt;Event Record #/Type2174 / Error&lt;br&gt;Event Submitted/Written: 03/25/2008 04:24:32 PM&lt;br&gt;Event ID/Source: 10005 / DCOM&lt;br&gt;Event Description:&lt;br&gt;DCOM got error "%%1084" attempting to start the service MSIServer with arguments ""&lt;br&gt;in order to run the server:&lt;br&gt;{000C101C-0000-0000-C000-000000000046}&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- End of Deckard's System Scanner: finished at 2008-03-26 11:00:50 ------------&lt;br&gt;&lt;br&gt;</description><pubDate>Wed, 26 Mar 2008 11:01:57 GMT</pubDate><dc:creator>Cheragain</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>Please download [b][url=http://www.techsupportforum.com/sectools/Deckard/dss.exe]Deckard's System Scanner (DSS)[/url][/b] and save it to your Desktop.&lt;br&gt;* Close all other windows before proceeding.&lt;br&gt;* Double-click on dss.exe and follow the prompts.&lt;br&gt;* When it has finished, DSS will open two Notepads: [b]main.txt[/b] and [b]extra.txt[/b]&lt;br&gt;* Use [b]Save As[/b] to save both Notepad files to your Desktop and [b]post them in your next reply.[/b]</description><pubDate>Wed, 26 Mar 2008 03:49:02 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>It is running much more smoothly thanks to you! I thank you so much for all of your time, patience and help. :)</description><pubDate>Tue, 25 Mar 2008 23:08:32 GMT</pubDate><dc:creator>Cheragain</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>F Secure Log:&lt;br&gt;&lt;br&gt;Scanning Report&lt;br&gt;Tuesday, March 25, 2008 20:25:45 - 22:39:03&lt;br&gt;&lt;br&gt;Computer name: BOB&lt;br&gt;Scanning type: Scan system for malware, rootkits&lt;br&gt;Target: C:\ F:\&lt;br&gt;Result: 3 malware found&lt;br&gt;Client-IRC.Win32.mIRC (spyware)&lt;br&gt;&lt;br&gt;    * System &lt;br&gt;&lt;br&gt;EICAR_Test_File (virus)&lt;br&gt;&lt;br&gt;    * System &lt;br&gt;&lt;br&gt;Tracking Cookie (spyware)&lt;br&gt;&lt;br&gt;    * System &lt;br&gt;&lt;br&gt;Statistics&lt;br&gt;Scanned:&lt;br&gt;&lt;br&gt;    * Files: 75376&lt;br&gt;    * System: 4716&lt;br&gt;    * Not scanned: 44 &lt;br&gt;&lt;br&gt;Actions:&lt;br&gt;&lt;br&gt;    * Disinfected: 0&lt;br&gt;    * Renamed: 0&lt;br&gt;    * Deleted: 0&lt;br&gt;    * None: 3&lt;br&gt;    * Submitted: 0 &lt;br&gt;&lt;br&gt;Files not scanned:&lt;br&gt;&lt;br&gt;    * C:\PAGEFILE.SYS&lt;br&gt;    * C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT&lt;br&gt;    * C:\WINDOWS\SYSTEM32\CONFIG\SAM&lt;br&gt;    * C:\WINDOWS\SYSTEM32\CONFIG\SECURITY&lt;br&gt;    * C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE&lt;br&gt;    * C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\BROWSER.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\CALLCONT.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\CMDEVTGPROV.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\EVTGPROV.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\GDI32.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\H323.TSP&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\H323MSP.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\HELPCTR.EXE&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\IPNATHLP.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\LSASRV.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\MF3216.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\MSASN1.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\MSGINA.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\MST120.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\NETAPI32.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\NMCOM.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\RTCDLL.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB835732$\SCHANNEL.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\CATSRV.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\CATSRVUT.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\CLBCATEX.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\CLBCATQ.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\COLBACT.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\COMADMIN.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\COMREPL.EXE&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\COMSVCS.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\COMUID.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\ES.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\MIGREGDB.EXE&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\MSDTCPRX.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\MSDTCTM.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\MSDTCUIU.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\MTXCLU.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\MTXOCI.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\OLE32.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\RPCRT4.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\RPCSS.DLL&lt;br&gt;    * F:\WINDOWS\$NTUNINSTALLKB828741$\TXFLOG.DLL &lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Hijack This log:&lt;br&gt;&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 10:40, on 03/25/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16608)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br&gt;C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe&lt;br&gt;C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe&lt;br&gt;C:\PROGRA~1\Grisoft\AVG7\avgemc.exe&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br&gt;C:\WINDOWS\System32\nvsvc32.exe&lt;br&gt;C:\WINDOWS\system32\PnkBstrA.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;br&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;br&gt;C:\WINDOWS\CTHELPER.EXE&lt;br&gt;C:\WINDOWS\system32\CTXFIHLP.EXE&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&lt;br&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;C:\WINDOWS\SYSTEM32\CTXFISPI.EXE&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br&gt;C:\WINDOWS\system32\wscntfy.exe&lt;br&gt;C:\Program Files\Mozilla Firefox\firefox.exe&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br&gt;O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup&lt;br&gt;O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install&lt;br&gt;O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit&lt;br&gt;O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP&lt;br&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;br&gt;O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE&lt;br&gt;O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=011508 serial=dr12wes-3007622-euw lang=EN&lt;br&gt;O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;br&gt;O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')&lt;br&gt;O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab&lt;br&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;br&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1193940609155&lt;br&gt;O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab&lt;br&gt;O16 - DPF: {BBF89515-EDB6-4236-8FBB-B6045290076D} (Image Uploader ShellCombo Control) - http://www.totsites.com/admin/includes/imageuploader2/ImageUploader4.cab&lt;br&gt;O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;br&gt;O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe&lt;br&gt;O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe&lt;br&gt;O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe&lt;br&gt;O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br&gt;O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe&lt;br&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe&lt;br&gt;O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe&lt;br&gt;O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;br&gt;O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;br&gt;O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 7337 bytes&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;I still have to reboot, I will let you know how it runs after that. Thank you so very much for everything! Sorry it took so long, it had over 500 gigs to scan through.</description><pubDate>Tue, 25 Mar 2008 22:41:56 GMT</pubDate><dc:creator>Cheragain</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>I apologize for the confusion, I assumed it was a scanner that scanned only for IE conflicts. I am running the scan now. Spysweeper has finished, however it will not remove the found viruses without a subscription.&lt;br&gt;&lt;br&gt;</description><pubDate>Tue, 25 Mar 2008 20:48:49 GMT</pubDate><dc:creator>Cheragain</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>What do you mean you don't use Internet Explorer,if its working ok can you follow the &lt;A class=SmlLinks href="http://support.f-secure.com/enu/home/ols.shtml" target=_blank&gt;&lt;FONT color=blue&gt;&lt;STRONG&gt;F-Secure Online Scanner&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/A&gt; instructions please.&lt;BR&gt;</description><pubDate>Tue, 25 Mar 2008 20:17:45 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>I had run the other programs prior to the last post. I do not use IE, so I did not run that last program. I did, however run Spysweeper and thus far at 75% in I have:&lt;br&gt;&lt;br&gt;&lt;br&gt;Spy Cookie found: about cookie&lt;br&gt;Spy Cookie found: tacoda cookie&lt;br&gt;Spy Cookie found: adbureau cookie&lt;br&gt;Spy Cookie found: yieldmanager cookie&lt;br&gt;Spy Cookie found: bluestreak cookie&lt;br&gt;Spy Cookie found: advertising cookie&lt;br&gt;Spy Cookie found: atlas dmt cookie&lt;br&gt;Spy Cookie found: trafficmp cookie&lt;br&gt;Spy Cookie found: pointroll cookie&lt;br&gt;Spy Cookie found: questionmarket cookie&lt;br&gt;Spy Cookie found: tribalfusion cookie&lt;br&gt;Spy Cookie found: apmebf cookie&lt;br&gt;Spy Cookie found: 2o7.net cookie&lt;br&gt;Spy Cookie found: statcounter cookie&lt;br&gt;Spy Cookie found: atwola cookie&lt;br&gt;Spy Cookie found: mediaplex cookie&lt;br&gt;Spy Cookie found: burstnet cookie&lt;br&gt;Spy Cookie found: realmedia cookie&lt;br&gt;Spy Cookie found: 247realmedia cookie&lt;br&gt;Spy Cookie found: casalemedia cookie&lt;br&gt;Spy Cookie found: tripod cookie&lt;br&gt;Spy Cookie found: bs.serving-sys cookie&lt;br&gt;Spy Cookie found: serving-sys cookie&lt;br&gt;Spy Cookie found: burstbeacon cookie&lt;br&gt;Spy Cookie found: adrevolver cookie&lt;br&gt;Spy Cookie found: zedo cookie&lt;br&gt;Spy Cookie found: specificclick.com cookie&lt;br&gt;Spy Cookie found: websponsors cookie&lt;br&gt;Spy Cookie found: valuead cookie&lt;br&gt;Spy Cookie found: webtrendslive cookie&lt;br&gt;Spy Cookie found: imrworldwide.com cookie&lt;br&gt;Spy Cookie found: go.com cookie&lt;br&gt;Virus found: Troj/Zapchas-CS&lt;br&gt;Virus found: EICAR-AV-Test&lt;br&gt;&lt;br&gt;&lt;br&gt;I will post the end results as soon as I get home from picking up my husband. Thank you so much for your patience!</description><pubDate>Tue, 25 Mar 2008 19:12:46 GMT</pubDate><dc:creator>Cheragain</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>Download and scan with [b]CCleaner[/b]:&lt;br&gt;[url]http://www.ccleaner.com/downloadbuilds.asp[/url]&lt;br&gt;1. Starting with v1.27.260, CCleaner installs the [b]Yahoo Toolbar[/b] as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free Basic or Slim versions instead of the Standard Build.&lt;br&gt;&lt;br&gt;2. Before first use, select Options &gt; Advanced and UNCHECK [b]"Only delete files in Windows Temp folder older than 48 hours"[/b]&lt;br&gt;&lt;br&gt;3. Then select the items you wish to clean up.&lt;br&gt;&lt;br&gt;[b]In the Windows Tab:[/b]&lt;br&gt;* Clean all entries in the "Internet Explorer" section except Cookies.&lt;br&gt;* Clean all the entries in the "Windows Explorer" section.&lt;br&gt;* Clean all entries in the "System" section.&lt;br&gt;* Clean all entries in the "Advanced" section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;[b]In the Applications Tab:[/b]&lt;br&gt;* Clean all except cookies in the Firefox/Mozilla section if you use it.&lt;br&gt;* Clean all in the Opera section if you use it.&lt;br&gt;* Clean Sun Java in the Internet Section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;4. Click the "Run Cleaner" button.&lt;br&gt;5. A pop up box will appear advising this process will permanently delete files from your system.&lt;br&gt;6. Click "OK" and it will scan and clean your system.&lt;br&gt;7. Click "Exit" when done.&lt;br&gt;&lt;br&gt;&lt;br&gt;Please download [b][color="red"]Malwarebytes Anti-Malware[/color][/b]:&lt;br&gt;[url]http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html[/url]&lt;br&gt;[url]http://www.besttechie.net/tools/mbam-setup.exe[/url]&lt;br&gt;&lt;br&gt;Double Click mbam-setup.exe to install the application.&lt;br&gt;(If using Windows Vista,be sure to [b][url=http://windowshelp.microsoft.com/Windows/en-US/Help/fb464905-31d5-4427-89a2-ed5322327fc21033.mspx][color="blue"]"Run As Administrator"[/color][/url][/b]).&lt;br&gt;&lt;br&gt;* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.&lt;br&gt;* If an update is found, it will download and install the latest version.&lt;br&gt;* Once the program has loaded, select "Perform Quick Scan", then click Scan.&lt;br&gt;* The scan may take some time to finish,so please be patient.&lt;br&gt;* When the scan is complete, click OK, then Show Results to view the results.&lt;br&gt;* Make sure that everything is checked, and click Remove Selected.&lt;br&gt;* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)&lt;br&gt;* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.&lt;br&gt;[b]* Copy and paste the entire report into your next reply.[/b]&lt;br&gt;&lt;br&gt;Extra Note:&lt;br&gt;[b][color="green"]If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.[/color][/b]&lt;br&gt;&lt;br&gt;&lt;br&gt;Run [b][url=http://support.f-secure.com/enu/home/ols.shtml][color="blue"]F-Secure Online Scanner[/color][/url][/b].&lt;br&gt;[b]Note:[/b] &lt;br&gt;This scanner is for [b]Internet Explorer[/b] only.&lt;br&gt;* Click on [b]Online Services[/b] and then [b]Online Scanner[/b].&lt;br&gt;* Accept the License Agreement.&lt;br&gt;* Once the ActiveX installs,click [b]Full System Scan[/b].&lt;br&gt;* Once the download completes,the scan will begin automatically.&lt;br&gt;* The scan will take some time to finish,so please be patient.&lt;br&gt;* When the scan completes, click the [b]Automatic cleaning (recommended)[/b] button.&lt;br&gt;* Click the [b]Show Report[/b] button then [b]copy and paste the entire report into your next reply[/b].&lt;br&gt;&lt;br&gt;Also post a new Hijackthis log,let me know how your pc is running now.</description><pubDate>Tue, 25 Mar 2008 18:39:32 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>The combofix froze. I let it sit for hours on end and I had to re-write the time language myself to get it to appear normally. It got stuck on the end screen saying it was writing a report. Here is the new hijackthis log&lt;br&gt;&lt;br&gt;&lt;br&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 06:23, on 03/25/2008&lt;br&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16608)&lt;br&gt;Boot mode: Normal&lt;br&gt;&lt;br&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br&gt;C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe&lt;br&gt;C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe&lt;br&gt;C:\PROGRA~1\Grisoft\AVG7\avgemc.exe&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br&gt;C:\WINDOWS\System32\nvsvc32.exe&lt;br&gt;C:\WINDOWS\system32\PnkBstrA.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;br&gt;C:\WINDOWS\system32\RUNDLL32.EXE&lt;br&gt;C:\PROGRA~1\Grisoft\AVG7\avgcc.exe&lt;br&gt;C:\WINDOWS\CTHELPER.EXE&lt;br&gt;C:\WINDOWS\system32\CTXFIHLP.EXE&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe&lt;br&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;C:\WINDOWS\SYSTEM32\CTXFISPI.EXE&lt;br&gt;C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br&gt;C:\WINDOWS\system32\wscntfy.exe&lt;br&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157&lt;br&gt;O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;br&gt;O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup&lt;br&gt;O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;br&gt;O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit&lt;br&gt;O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP&lt;br&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;br&gt;O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE&lt;br&gt;O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=011508 serial=dr12wes-3007622-euw lang=EN&lt;br&gt;O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"&lt;br&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background&lt;br&gt;O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')&lt;br&gt;O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')&lt;br&gt;O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab&lt;br&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;br&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1193940609155&lt;br&gt;O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab&lt;br&gt;O16 - DPF: {BBF89515-EDB6-4236-8FBB-B6045290076D} (Image Uploader ShellCombo Control) - http://www.totsites.com/admin/includes/imageuploader2/ImageUploader4.cab&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe&lt;br&gt;O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;br&gt;O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe&lt;br&gt;O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe&lt;br&gt;O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe&lt;br&gt;O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe&lt;br&gt;O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe&lt;br&gt;O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe&lt;br&gt;O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe&lt;br&gt;O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe&lt;br&gt;O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe&lt;br&gt;O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe&lt;br&gt;O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe&lt;br&gt;&lt;br&gt;--&lt;br&gt;End of file - 7095 bytes&lt;br&gt;</description><pubDate>Tue, 25 Mar 2008 18:25:04 GMT</pubDate><dc:creator>Cheragain</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>It seems to be much faster. I have to run my son to the store, then I will proceed to downloading everything in safe mode. I will post as soon as I have done so. Thank you!</description><pubDate>Tue, 25 Mar 2008 15:16:38 GMT</pubDate><dc:creator>Cheragain</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>Reboot your computer into [b][url=http://www.pchell.com/support/safemode.shtml][color="RED"]SAFE MODE[/color][/url][/b] using the [b]F8[/b] method. &lt;br&gt;To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. &lt;br&gt;A menu will appear with several options. &lt;br&gt;Use the arrow keys on your keyboard to navigate and select the option to run Windows in "[b]Safe Mode with Networking[/b]".&lt;br&gt;&lt;br&gt;Hows your internet connection now.</description><pubDate>Tue, 25 Mar 2008 14:17:20 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Hijackthis Log</title><link>http://forum.tweaks.com/forum/Topic236770-29-1.aspx</link><description>I thank you so much for your prompt response. I cannot seem to download anything at this point, it took 6 retrys trying to load the reply page, I am getting just about no internet connectivity and it is not my ISP. In trying to download any of these programs all of my downloads freeze on me and cease to go any further than 80% or so. I am really not sure what to do at this point.</description><pubDate>Tue, 25 Mar 2008 14:09:36 GMT</pubDate><dc:creator>Cheragain</dc:creator></item></channel></rss>