Hi Blade,
I did the comboFix scan and DDS scan. After, I was able to install Spybot.
Here are the logs as per your request.
ComboFix 10-10-20.01 - wei 10/20/2010 22:54:15.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.2036.1043 [GMT -4:00]
Running from: c:\users\wei\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\wei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi
c:\users\wei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\About.lnk
c:\users\wei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Activate.lnk
c:\users\wei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Antivirus Support.lnk
c:\users\wei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Antivirus.lnk
c:\users\wei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Buy.lnk
c:\users\wei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Scan.lnk
c:\users\wei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Settings.lnk
c:\users\wei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Update.lnk
c:\users\wei\wrar371.exe
c:\windows\PRAGMAclrtepefne
c:\windows\PRAGMAclrtepefne\PRAGMAcfg.ini
c:\windows\PRAGMAclrtepefne\PRAGMAsrcr.dat
.
((((((((((((((((((((((((( Files Created from 2010-09-21 to 2010-10-21 )))))))))))))))))))))))))))))))
.
2010-10-21 02:59 . 2010-10-21 02:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-17 03:31 . 2010-08-12 12:15 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-10-17 03:30 . 2010-10-17 03:30 -------- dc-h--w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-10-17 03:29 . 2010-10-17 03:31 -------- d-----w- c:\programdata\Lavasoft
2010-10-17 03:29 . 2010-10-17 03:29 -------- d-----w- c:\program files\Lavasoft
2010-10-15 01:58 . 2010-10-15 01:58 -------- d-----w- c:\users\wei\AppData\Roaming\Malwarebytes
2010-10-14 02:37 . 2010-10-14 02:37 -------- d-----w- c:\users\Default\AppData\Roaming\Apple Computer
2010-10-14 02:37 . 2010-10-14 02:37 -------- d-----w- c:\users\Default\AppData\Local\Apple Computer
2010-10-13 02:21 . 2010-10-17 00:45 -------- d-----w- c:\users\wei\AppData\Roaming\AnVi
2010-09-29 12:36 . 2010-09-09 22:52 6084944 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{98D241D9-5ED0-4A15-AB61-693EB043D2D5}\mpengine.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-16 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Google Update"="c:\users\wei\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-03-17 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-14 4452352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-25 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-25 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-25 129560]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-14 30192]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
c:\users\wei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-11-2 724992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-09 135664]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-14 30192]
R3 XDva223;XDva223;c:\windows\system32\XDva223.sys [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-08-12 64288]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-08-12 1355416]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder
2010-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-09 03:50]
2010-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-09 03:50]
2010-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1567490740-3558055732-546575408-1001Core.job
- c:\users\wei\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 23:48]
2010-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1567490740-3558055732-546575408-1001UA.job
- c:\users\wei\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 23:48]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://yahoo.com/
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-10-20 23:01:12
ComboFix-quarantined-files.txt 2010-10-21 03:01
Pre-Run: 206,288,179,200 bytes free
Post-Run: 208,044,556,288 bytes free
- - End Of File - - 8B665725FCF0A7C359E07CADC3473636
DDS (Ver_10-10-10.03) - NTFSx86
Run by wei at 23:06:44.25 on Wed 10/20/2010
Internet Explorer: 8.0.6001.18882
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.2036.907 [GMT -4:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Windows\explorer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\wei\Desktop\dds.com
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://yahoo.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Google Update] "c:\users\wei\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\users\wei\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~2\GoogleDesktopNetwork3.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-10-16 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-8-12 1355416]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-8 135664]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-10-16 30192]
=============== Created Last 30 ================
2010-10-21 03:01:16 -------- d-sh--w- C:\$RECYCLE.BIN
2010-10-21 02:51:23 98816 ----a-w- c:\windows\sed.exe
2010-10-21 02:51:23 77312 ----a-w- c:\windows\MBR.exe
2010-10-21 02:51:23 256512 ----a-w- c:\windows\PEV.exe
2010-10-21 02:51:23 161792 ----a-w- c:\windows\SWREG.exe
2010-10-21 02:51:19 -------- d-----w- C:\ComboFix
2010-10-17 03:31:15 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-10-17 03:30:16 -------- dc-h--w- c:\progra~2\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-10-17 03:29:50 -------- d-----w- c:\program files\Lavasoft
2010-10-15 01:58:36 -------- d-----w- c:\users\wei\appdata\roaming\Malwarebytes
2010-10-13 02:21:35 -------- d-----w- c:\users\wei\appdata\roaming\AnVi
2010-09-29 12:36:08 6084944 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{98d241d9-5ed0-4a15-ab61-693eb043d2d5}\mpengine.dll
==================== Find3M ====================
============= FINISH: 23:06:56.08 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-10-10.03)
Microsoft® Windows Vista™ Home Basic
Boot Device: \Device\HarddiskVolume3
Install Date: 10/16/2008 3:19:55 PM
System Uptime: 10/20/2010 10:47:12 PM (1 hours ago)
Motherboard: Dell Inc. | | 0CU409
Processor: Intel(R) Core(TM)2 Duo CPU E7200 @ 2.53GHz | Socket 775 | 2534/266mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 223 GiB total, 193.816 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 6.16 GiB free.
E: is CDROM (UDF)
F: is Removable
==== Disabled Device Manager Items =============
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0032
Manufacturer: Microsoft
Name: isatap.{3700D6B9-8C49-4ADA-AB61-17D2A67A8B27}
PNP Device ID: ROOT\*ISATAP\0032
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0037
Manufacturer: Microsoft
Name: isatap.{3700D6B9-8C49-4ADA-AB61-17D2A67A8B27}
PNP Device ID: ROOT\*ISATAP\0037
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0066
Manufacturer: Microsoft
Name: isatap.{3700D6B9-8C49-4ADA-AB61-17D2A67A8B27}
PNP Device ID: ROOT\*ISATAP\0066
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0089
Manufacturer: Microsoft
Name: isatap.{3700D6B9-8C49-4ADA-AB61-17D2A67A8B27}
PNP Device ID: ROOT\*ISATAP\0089
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0108
Manufacturer: Microsoft
Name: isatap.{3700D6B9-8C49-4ADA-AB61-17D2A67A8B27}
PNP Device ID: ROOT\*ISATAP\0108
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0126
Manufacturer: Microsoft
Name: isatap.{3700D6B9-8C49-4ADA-AB61-17D2A67A8B27}
PNP Device ID: ROOT\*ISATAP\0126
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0147
Manufacturer: Microsoft
Name: isatap.{3700D6B9-8C49-4ADA-AB61-17D2A67A8B27}
PNP Device ID: ROOT\*ISATAP\0147
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0151
Manufacturer: Microsoft
Name: isatap.{3700D6B9-8C49-4ADA-AB61-17D2A67A8B27}
PNP Device ID: ROOT\*ISATAP\0151
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0155
Manufacturer: Microsoft
Name: isatap.{3700D6B9-8C49-4ADA-AB61-17D2A67A8B27}
PNP Device ID: ROOT\*ISATAP\0155
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0164
Manufacturer: Microsoft
Name: isatap.{3700D6B9-8C49-4ADA-AB61-17D2A67A8B27}
PNP Device ID: ROOT\*ISATAP\0164
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0181
Manufacturer: Microsoft
Name: isatap.{3700D6B9-8C49-4ADA-AB61-17D2A67A8B27}
PNP Device ID: ROOT\*ISATAP\0181
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0301
Manufacturer: Microsoft
Name: Microsoft ISATAP Adapter #277
PNP Device ID: ROOT\*ISATAP\0301
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0333
Manufacturer: Microsoft
Name: Microsoft ISATAP Adapter #309
PNP Device ID: ROOT\*ISATAP\0333
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0338
Manufacturer: Microsoft
Name: Microsoft ISATAP Adapter #314
PNP Device ID: ROOT\*ISATAP\0338
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0341
Manufacturer: Microsoft
Name: Microsoft ISATAP Adapter #317
PNP Device ID: ROOT\*ISATAP\0341
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0404
Manufacturer: Microsoft
Name: Microsoft ISATAP Adapter #378
PNP Device ID: ROOT\*ISATAP\0404
Service: tunnel
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0420
Manufacturer: Microsoft
Name: Microsoft ISATAP Adapter #392
PNP Device ID: ROOT\*ISATAP\0420
Service: tunnel
==== System Restore Points ===================
RP396: 10/16/2010 11:52:29 PM - Windows Defender Checkpoint
RP397: 10/20/2010 10:51:27 PM - ComboFix created restore point
==== Installed Programs ======================
Acrobat.com
Ad-Aware
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9
Apple Mobile Device Support
Apple Software Update
Bonjour
Browser Address Error Redirector
Business Tools Launcher
Dell Getting Started Guide
Dell Support Center
EDocs
GL Excess v1.2v
Google Chrome
Google Desktop
Google Earth
Google Talk Plugin
Google Toolbar for Internet Explorer
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Intel(R) PRO Network Connections 12.1.11.0
iTunes
Java(TM) 6 Update 7
Microsoft .NET Framework 3.5 SP1
MixMaster
Move Media Player
OpenOffice.org 3.0
Personal Entertainment Launcher
PowerDVD
Product Support Launcher
QuickBooks Premier Edition 2004
QuickTime
Realtek High Definition Audio Driver
Roxio Activation Module
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Express Labeler 3
Roxio Update Manager
Sonic CinePlayer Decoder Pack
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 0.9.4
WinRAR archiver
==== Event Viewer Messages From Past Week ========
10/20/2010 10:54:08 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
10/16/2010 11:31:03 PM, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
10/16/2010 11:22:30 PM, Error: Service Control Manager [7001] - The Windows Image Acquisition (WIA) service depends on the Shell Hardware Detection service which failed to start because of the following error: The operation completed successfully.
10/14/2010 7:35:11 AM, Error: Service Control Manager [7043] - The Windows Update service did not shut down properly after receiving a preshutdown control.
10/13/2010 9:36:36 PM, Error: Microsoft-Windows-Windows Defender [1008] - Windows Defender has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name=Rogue:Win32/FakeCog&threatid=140896 Scan ID: {226F1706-82D9-4278-B1F6-4264FD452134} Scan Type: AntiMalware User: NT AUTHORITY\NETWORK SERVICE Name: Rogue:Win32/FakeCog ID: 140896 Severity ID: 5 Category ID: 8 Path: Action: Remove Error Code: 0x80508022 Error description: To finish removing spyware and other potentially unwanted software, restart the computer.
10/13/2010 9:30:05 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer T-BONE-I7 that believes that it is the master browser for the domain on transport NetBT_Tcpip_{DDCB8C90-9E48-4F51-A864-FA2E441D. The master browser is stopping or an election is being forced.
10/13/2010 8:16:32 AM, Error: NETLOGON [3095] - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration.
10/13/2010 8:16:21 AM, Error: Microsoft-Windows-Kernel-General [5] - {Registry Hive Recovered} Registry hive (file): '\??\C:\Users\wei\AppData\Local\Microsoft\Windows\UsrClass.dat' was corrupted and it has been recovered. Some data might have been lost.
10/13/2010 10:25:23 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Kaspersky Anti-Virus Service service to connect.
10/13/2010 10:25:23 PM, Error: Service Control Manager [7000] - The Kaspersky Anti-Virus Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/13/2010 10:20:59 PM, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {C2BFE331-6739-4270-86C9-493D9A04CD38}. The error: "5" Happened while starting this command: C:\Windows\system32\igfxsrvc.exe -Embedding
==== End Of File ===========================
Thank you very much,
Tim