MyWay.MyWayWebSearch - PUPSC - Can't remove

Hi,
I have tried this and it's still not working - it downloads says run, which I do, and say's to restart computer, however it's not removing it. Don't know if I'm doing something wrong, but I am following the instructions it gives?
Thanks

this is the instruction it gives:

To use the AVG 7.x removal tool please follow these steps:

- Run the "delAVG7.reg" file.
- Confirm adding of the information to the system registry.
- Restart your computer.

This file will remove completely all AVG 7.x registry information.

- After the restart you can delete the installed file(s) from the folder where it is stored (C:\AVGTemp by default).

I get as far as "Confirm adding of the information to the system registry."

Then i restart - but files are still there..?? (sorry if this a fault on my part... really am not too sure about what to do now)
 
Hi,
Just rebooted again it "appears" to have worked (Avg 7.5) icons etc are gone. Still not sure if it's completely gone though..

Also on reboot.. took 5 attempts before system started operating and got the "blue screen of death"... twice..:confused:
 
Hi Peku006,

Pls see below:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:21:25 AM, on 02/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Netgear\WG111v3\WG111v3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [DLCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = D:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\Netgear\WG111v3\WG111v3.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: bet365 Poker - {B1BA4A3F-1C95-497b-9F82-F8DA4A5C89DD} - C:\Microgaming\Poker\bet365MPP\MPPoker.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.bebo.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {33415AC7-AFFA-4D55-B41C-C64C0D07DFCA} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWebManager.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://mppv2flash3.valueactive.com/Bet365/FlashAX.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cryptographic Services (CryptSvc) - Unknown owner - C:\Program Files\Dell Support\bin\MsPMSNSv.exe (file missing)
O23 - Service: dlcf_device - - C:\WINDOWS\system32\dlcfcoms.exe
O23 - Service: Google Desktop Manager 5.9.909.30391 (GoogleDesktopManager-093009-130223) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: AutomatedSurfer (SurferService) - Unknown owner - C:\WINDOWS\system32\srvany.exe

--
End of file - 11835 bytes
 
Hi IT Novice

it seems you don't have any evidence of an anti-virus software.

Anti-virus software are programs that detect cleans and erase harmful virus files on a computer
Web server or network.
Unchecked virus files can unintentionally be forwarded to others including trading partners and thereby spreading infection. Because new viruses regularly emerge anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present and will clean delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors NOW:


It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer then only one of them should be active in memory at a time.

With that done, please post back with a fresh HiJackThis log

Thanks peku006
 
Hi Pek006,
thanks for that.. before i install one of these... are these listed in order of preference? - or are they all equally as good? - I'm just a bit apprehensive about AVG given the hassle trying to remove 7.5?
thanks
 
Hi IT Novice

they are all good programs...........(avira is my favorite :yes:)

peku006
 
Hi IT Novice

they are all good programs...........(avira is my favorite :yes:)

peku006

Hi Again,

Avira it is then!!.. ran a scan with it and it found 48 detections.. some referring to the lets bet and limewire tho.. I will post findings below also.. here is the HJT report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:48:43 PM, on 02/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Netgear\WG111v3\WG111v3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [DLCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = D:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\Netgear\WG111v3\WG111v3.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: bet365 Poker - {B1BA4A3F-1C95-497b-9F82-F8DA4A5C89DD} - C:\Microgaming\Poker\bet365MPP\MPPoker.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.bebo.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {33415AC7-AFFA-4D55-B41C-C64C0D07DFCA} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWebManager.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://mppv2flash3.valueactive.com/Bet365/FlashAX.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cryptographic Services (CryptSvc) - Unknown owner - C:\Program Files\Dell Support\bin\MsPMSNSv.exe (file missing)
O23 - Service: dlcf_device - - C:\WINDOWS\system32\dlcfcoms.exe
O23 - Service: Google Desktop Manager 5.9.909.30391 (GoogleDesktopManager-093009-130223) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: AutomatedSurfer (SurferService) - Unknown owner - C:\WINDOWS\system32\srvany.exe

--
End of file - 12349 bytes

Here is the Log from Avira
Avira AntiVir Personal
Report file date: Monday, November 02, 2009 11:46

Scanning for 1562564 virus strains and unwanted programs.

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 2) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : TOFFEE

Version information:
BUILD.DAT : 9.0.0.407 17961 Bytes 7/29/2009 10:34:00
AVSCAN.EXE : 9.0.3.7 466689 Bytes 7/21/2009 14:36:14
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 11:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 12:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 11:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 13:30:36
ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 6/24/2009 10:21:42
ANTIVIR2.VDF : 7.1.4.253 1779200 Bytes 7/19/2009 23:08:01
ANTIVIR3.VDF : 7.1.5.19 139776 Bytes 7/23/2009 08:36:13
Engineversion : 8.2.0.228
AEVDF.DLL : 8.1.1.1 106868 Bytes 7/28/2009 14:31:50
AESCRIPT.DLL : 8.1.2.18 442746 Bytes 7/23/2009 10:59:39
AESCN.DLL : 8.1.2.4 127348 Bytes 7/23/2009 10:59:39
AERDL.DLL : 8.1.2.4 430452 Bytes 7/23/2009 10:59:39
AEPACK.DLL : 8.1.3.18 401783 Bytes 7/28/2009 14:31:50
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 7/23/2009 10:59:39
AEHEUR.DLL : 8.1.0.143 1864055 Bytes 7/23/2009 10:59:39
AEHELP.DLL : 8.1.5.3 233846 Bytes 7/23/2009 10:59:39
AEGEN.DLL : 8.1.1.50 352629 Bytes 7/23/2009 10:59:39
AEEMU.DLL : 8.1.0.9 393588 Bytes 10/9/2008 15:32:40
AECORE.DLL : 8.1.7.6 184694 Bytes 7/23/2009 10:59:39
AEBB.DLL : 8.1.0.3 53618 Bytes 10/9/2008 15:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 09:47:59
AVPREF.DLL : 9.0.0.1 43777 Bytes 12/5/2008 11:32:15
AVREP.DLL : 8.0.0.3 155905 Bytes 1/20/2009 15:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 11:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 3/24/2009 16:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 11:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 16:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 09:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 11:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 5/15/2009 16:39:58
RCTEXT.DLL : 9.0.37.0 86785 Bytes 4/17/2009 11:19:48

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +GAME,

Start of the scan: Monday, November 02, 2009 11:46

Starting search for hidden objects.
'90701' objects were checked, '0' hidden objects were found.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'wltuser.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'WG111v3.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'QuickDCF2.exe' - '1' Module(s) have been scanned
Scan process 'ezi_hnm2.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'QTTask.exe' - '1' Module(s) have been scanned
Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'Corel Photo Downloader.exe' - '1' Module(s) have been scanned
Scan process 'issch.exe' - '1' Module(s) have been scanned
Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
Scan process 'DLACTRLW.EXE' - '1' Module(s) have been scanned
Scan process 'DMXLauncher.exe' - '1' Module(s) have been scanned
Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned
Scan process 'stsystra.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'ehtray.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'dllhost.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'CALMAIN.exe' - '1' Module(s) have been scanned
Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SeaPort.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'mdm.exe' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'IAANTmon.exe' - '1' Module(s) have been scanned
Scan process 'hnm_svc.exe' - '1' Module(s) have been scanned
Scan process 'ehSched.exe' - '1' Module(s) have been scanned
Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
Scan process 'CTSVCCDA.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
59 processes with 59 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
Master boot sector HD3
[INFO] No virus was found!
Master boot sector HD4
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '74' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3545425-another chance with love.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3555427-she fucking hates me.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3877634-she fucking hates me - greatest hits.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
C:\Documents and Settings\Rebecca\Incomplete\T-3515164-she fucking hates me.wma
[DETECTION] Is the TR/Dldr.WMA.Wim.N.4 Trojan
C:\Documents and Settings\Rebecca\Incomplete\T-3555427-she fucking hates me.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
C:\Documents and Settings\Rebecca\Incomplete\T-3877634-she fucking hates me - greatest hits.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
C:\Documents and Settings\Rebecca\My Documents\My Music\claire and friends 関蹿.wma
[DETECTION] Is the TR/Dldr.WMA.Wima.AA Trojan
C:\Documents and Settings\Rebecca\Shared\Eighties classic.wma
[DETECTION] Is the TR/Dldr.Age.3566386 Trojan
C:\Documents and Settings\Rebecca\Shared\she fucking hates me.mp3
[DETECTION] Is the TR/Brisv.B Trojan
C:\Documents and Settings\Rebecca\Shared\vanessa over the rainbow bob frisell chase.wma
[DETECTION] Is the TR/Dldr.WMA.Wima.AA Trojan
C:\Microgaming\Poker\bet365MPP\local\da\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\de\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\en\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\es\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\fr\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\it\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\no\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\sv\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\zh-cn\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\zh-tw\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\da\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\de\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\en\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\es\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\fr\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\it\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\no\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\sv\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\zh-cn\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\zh-tw\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP533\A0149762.reg
[DETECTION] Is the TR/REG.Koobface.89 Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP535\A0153824.reg
[DETECTION] Is the TR/REG.Koobface.89 Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154882.dll
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154883.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154885.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154886.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154887.exe
[DETECTION] Is the TR/Wippy.19968 Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154888.dll
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154890.exe
[DETECTION] Is the TR/Wippy.19968 Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154895.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154896.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154897.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154898.exe
[DETECTION] Contains recognition pattern of the WORM/Koobface.24576 worm
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154950.exe
[DETECTION] Is the TR/Drop.Softomat.AN Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP537\A0154966.dll
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP579\A0171411.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP579\A0171412.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\WINDOWS\system32\FlashAX\FlashAX.ocx
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
Begin scan in 'D:\' <Backup>

Beginning disinfection:
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3545425-another chance with love.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
[NOTE] The file was moved to '4b53d387.qua'!
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3555427-she fucking hates me.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
[NOTE] The file was moved to '48d5d078.qua'!
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3877634-she fucking hates me - greatest hits.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
[NOTE] The file was moved to '48c27d70.qua'!
C:\Documents and Settings\Rebecca\Incomplete\T-3515164-she fucking hates me.wma
[DETECTION] Is the TR/Dldr.WMA.Wim.N.4 Trojan
[NOTE] The file was moved to '4b21d342.qua'!
C:\Documents and Settings\Rebecca\Incomplete\T-3555427-she fucking hates me.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
[NOTE] The file was moved to '48b26dcb.qua'!
C:\Documents and Settings\Rebecca\Incomplete\T-3877634-she fucking hates me - greatest hits.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
[NOTE] The file was moved to '48b51513.qua'!
C:\Documents and Settings\Rebecca\My Documents\My Music\claire and friends 関蹿.wma
[DETECTION] Is the TR/Dldr.WMA.Wima.AA Trojan
[NOTE] The file was moved to '4b4fd382.qua'!
C:\Documents and Settings\Rebecca\Shared\Eighties classic.wma
[DETECTION] Is the TR/Dldr.Age.3566386 Trojan
[NOTE] The file was moved to '4b55d37f.qua'!
C:\Documents and Settings\Rebecca\Shared\she fucking hates me.mp3
[DETECTION] Is the TR/Brisv.B Trojan
[NOTE] The file was moved to '4b53d37e.qua'!
C:\Documents and Settings\Rebecca\Shared\vanessa over the rainbow bob frisell chase.wma
[DETECTION] Is the TR/Dldr.WMA.Wima.AA Trojan
[NOTE] The file was moved to '4b5cd377.qua'!
C:\Microgaming\Poker\bet365MPP\local\da\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b5bd385.qua'!
C:\Microgaming\Poker\bet365MPP\local\de\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4ebcc63e.qua'!
C:\Microgaming\Poker\bet365MPP\local\en\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b5bd386.qua'!
C:\Microgaming\Poker\bet365MPP\local\es\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b5bd387.qua'!
C:\Microgaming\Poker\bet365MPP\local\fr\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '48cc0e20.qua'!
C:\Microgaming\Poker\bet365MPP\local\it\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e0630f8.qua'!
C:\Microgaming\Poker\bet365MPP\local\no\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e0538b0.qua'!
C:\Microgaming\Poker\bet365MPP\local\sv\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e042088.qua'!
C:\Microgaming\Poker\bet365MPP\local\zh-cn\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e3b2940.qua'!
C:\Microgaming\Poker\bet365MPP\local\zh-tw\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e39d118.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\da\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b53d388.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\de\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e35f239.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\en\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e34faf1.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\es\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e3be2c9.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\fr\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e3aea81.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\it\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e399359.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\no\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e389b11.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\sv\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b53d389.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\zh-cn\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e3e8ba2.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\zh-tw\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e3d8c7a.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP533\A0149762.reg
[DETECTION] Is the TR/REG.Koobface.89 Trojan
[NOTE] The file was moved to '4b1fd349.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP535\A0153824.reg
[DETECTION] Is the TR/REG.Koobface.89 Trojan
[NOTE] The file was moved to '4efad562.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154882.dll
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e7bc16a.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154883.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e450092.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154885.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e7cd912.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154886.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e6fbcca.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154887.exe
[DETECTION] Is the TR/Wippy.19968 Trojan
[NOTE] The file was moved to '4e6ea402.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154888.dll
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e70b4f2.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154890.exe
[DETECTION] Is the TR/Wippy.19968 Trojan
[NOTE] The file was moved to '4e6dac5a.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154895.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e6c5592.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154896.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e6b5dea.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154897.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e6a4522.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154898.exe
[DETECTION] Contains recognition pattern of the WORM/Koobface.24576 worm
[NOTE] The file was moved to '4e694d7a.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154950.exe
[DETECTION] Is the TR/Drop.Softomat.AN Trojan
[NOTE] The file was moved to '4e6876b2.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP537\A0154966.dll
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e677e8a.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP579\A0171411.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e6666c2.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP579\A0171412.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e656e1a.qua'!
C:\WINDOWS\system32\FlashAX\FlashAX.ocx
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b4fd385.qua'!


End of the scan: Monday, November 02, 2009 12:39
Used time: 50:58 Minute(s)

The scan has been done completely.

10689 Scanned directories
362390 Files were scanned
48 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
48 Files were moved to quarantine
0 Files were renamed
2 Files cannot be scanned
362340 Files not concerned
4508 Archives were scanned
2 Warnings
50 Notes
90701 Objects were scanned with rootkit scan
0 Hidden objects were found
 
Hi Again,

Avira it is then!!.. ran a scan with it and it found 48 detections.. some referring to the lets bet and limewire tho.. I will post findings below also.. here is the HJT report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:48:43 PM, on 02/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Netgear\WG111v3\WG111v3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [DLCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = D:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\Netgear\WG111v3\WG111v3.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: bet365 Poker - {B1BA4A3F-1C95-497b-9F82-F8DA4A5C89DD} - C:\Microgaming\Poker\bet365MPP\MPPoker.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.bebo.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {33415AC7-AFFA-4D55-B41C-C64C0D07DFCA} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWebManager.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://mppv2flash3.valueactive.com/Bet365/FlashAX.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cryptographic Services (CryptSvc) - Unknown owner - C:\Program Files\Dell Support\bin\MsPMSNSv.exe (file missing)
O23 - Service: dlcf_device - - C:\WINDOWS\system32\dlcfcoms.exe
O23 - Service: Google Desktop Manager 5.9.909.30391 (GoogleDesktopManager-093009-130223) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: AutomatedSurfer (SurferService) - Unknown owner - C:\WINDOWS\system32\srvany.exe

--
End of file - 12349 bytes

Here is the Log from Avira
Avira AntiVir Personal
Report file date: Monday, November 02, 2009 11:46

Scanning for 1562564 virus strains and unwanted programs.

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 2) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : TOFFEE

Version information:
BUILD.DAT : 9.0.0.407 17961 Bytes 7/29/2009 10:34:00
AVSCAN.EXE : 9.0.3.7 466689 Bytes 7/21/2009 14:36:14
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 11:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 12:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 11:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 13:30:36
ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 6/24/2009 10:21:42
ANTIVIR2.VDF : 7.1.4.253 1779200 Bytes 7/19/2009 23:08:01
ANTIVIR3.VDF : 7.1.5.19 139776 Bytes 7/23/2009 08:36:13
Engineversion : 8.2.0.228
AEVDF.DLL : 8.1.1.1 106868 Bytes 7/28/2009 14:31:50
AESCRIPT.DLL : 8.1.2.18 442746 Bytes 7/23/2009 10:59:39
AESCN.DLL : 8.1.2.4 127348 Bytes 7/23/2009 10:59:39
AERDL.DLL : 8.1.2.4 430452 Bytes 7/23/2009 10:59:39
AEPACK.DLL : 8.1.3.18 401783 Bytes 7/28/2009 14:31:50
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 7/23/2009 10:59:39
AEHEUR.DLL : 8.1.0.143 1864055 Bytes 7/23/2009 10:59:39
AEHELP.DLL : 8.1.5.3 233846 Bytes 7/23/2009 10:59:39
AEGEN.DLL : 8.1.1.50 352629 Bytes 7/23/2009 10:59:39
AEEMU.DLL : 8.1.0.9 393588 Bytes 10/9/2008 15:32:40
AECORE.DLL : 8.1.7.6 184694 Bytes 7/23/2009 10:59:39
AEBB.DLL : 8.1.0.3 53618 Bytes 10/9/2008 15:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 09:47:59
AVPREF.DLL : 9.0.0.1 43777 Bytes 12/5/2008 11:32:15
AVREP.DLL : 8.0.0.3 155905 Bytes 1/20/2009 15:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 11:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 3/24/2009 16:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 11:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 16:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 09:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 11:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 5/15/2009 16:39:58
RCTEXT.DLL : 9.0.37.0 86785 Bytes 4/17/2009 11:19:48

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +GAME,

Start of the scan: Monday, November 02, 2009 11:46

Starting search for hidden objects.
'90701' objects were checked, '0' hidden objects were found.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'wltuser.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'WG111v3.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'QuickDCF2.exe' - '1' Module(s) have been scanned
Scan process 'ezi_hnm2.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'QTTask.exe' - '1' Module(s) have been scanned
Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'Corel Photo Downloader.exe' - '1' Module(s) have been scanned
Scan process 'issch.exe' - '1' Module(s) have been scanned
Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
Scan process 'DLACTRLW.EXE' - '1' Module(s) have been scanned
Scan process 'DMXLauncher.exe' - '1' Module(s) have been scanned
Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned
Scan process 'stsystra.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'ehtray.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'dllhost.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'CALMAIN.exe' - '1' Module(s) have been scanned
Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SeaPort.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'mdm.exe' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'IAANTmon.exe' - '1' Module(s) have been scanned
Scan process 'hnm_svc.exe' - '1' Module(s) have been scanned
Scan process 'ehSched.exe' - '1' Module(s) have been scanned
Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
Scan process 'CTSVCCDA.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
59 processes with 59 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
Master boot sector HD3
[INFO] No virus was found!
Master boot sector HD4
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '74' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3545425-another chance with love.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3555427-she fucking hates me.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3877634-she fucking hates me - greatest hits.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
C:\Documents and Settings\Rebecca\Incomplete\T-3515164-she fucking hates me.wma
[DETECTION] Is the TR/Dldr.WMA.Wim.N.4 Trojan
C:\Documents and Settings\Rebecca\Incomplete\T-3555427-she fucking hates me.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
C:\Documents and Settings\Rebecca\Incomplete\T-3877634-she fucking hates me - greatest hits.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
C:\Documents and Settings\Rebecca\My Documents\My Music\claire and friends 関蹿.wma
[DETECTION] Is the TR/Dldr.WMA.Wima.AA Trojan
C:\Documents and Settings\Rebecca\Shared\Eighties classic.wma
[DETECTION] Is the TR/Dldr.Age.3566386 Trojan
C:\Documents and Settings\Rebecca\Shared\she fucking hates me.mp3
[DETECTION] Is the TR/Brisv.B Trojan
C:\Documents and Settings\Rebecca\Shared\vanessa over the rainbow bob frisell chase.wma
[DETECTION] Is the TR/Dldr.WMA.Wima.AA Trojan
C:\Microgaming\Poker\bet365MPP\local\da\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\de\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\en\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\es\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\fr\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\it\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\no\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\sv\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\zh-cn\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\local\zh-tw\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\da\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\de\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\en\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\es\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\fr\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\it\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\no\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\sv\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\zh-cn\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\zh-tw\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP533\A0149762.reg
[DETECTION] Is the TR/REG.Koobface.89 Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP535\A0153824.reg
[DETECTION] Is the TR/REG.Koobface.89 Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154882.dll
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154883.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154885.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154886.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154887.exe
[DETECTION] Is the TR/Wippy.19968 Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154888.dll
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154890.exe
[DETECTION] Is the TR/Wippy.19968 Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154895.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154896.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154897.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154898.exe
[DETECTION] Contains recognition pattern of the WORM/Koobface.24576 worm
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154950.exe
[DETECTION] Is the TR/Drop.Softomat.AN Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP537\A0154966.dll
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP579\A0171411.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP579\A0171412.exe
[DETECTION] Is the TR/Trash.Gen Trojan
C:\WINDOWS\system32\FlashAX\FlashAX.ocx
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
Begin scan in 'D:\' <Backup>

Beginning disinfection:
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3545425-another chance with love.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
[NOTE] The file was moved to '4b53d387.qua'!
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3555427-she fucking hates me.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
[NOTE] The file was moved to '48d5d078.qua'!
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-3877634-she fucking hates me - greatest hits.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
[NOTE] The file was moved to '48c27d70.qua'!
C:\Documents and Settings\Rebecca\Incomplete\T-3515164-she fucking hates me.wma
[DETECTION] Is the TR/Dldr.WMA.Wim.N.4 Trojan
[NOTE] The file was moved to '4b21d342.qua'!
C:\Documents and Settings\Rebecca\Incomplete\T-3555427-she fucking hates me.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
[NOTE] The file was moved to '48b26dcb.qua'!
C:\Documents and Settings\Rebecca\Incomplete\T-3877634-she fucking hates me - greatest hits.mp3
[DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
[NOTE] The file was moved to '48b51513.qua'!
C:\Documents and Settings\Rebecca\My Documents\My Music\claire and friends 関蹿.wma
[DETECTION] Is the TR/Dldr.WMA.Wima.AA Trojan
[NOTE] The file was moved to '4b4fd382.qua'!
C:\Documents and Settings\Rebecca\Shared\Eighties classic.wma
[DETECTION] Is the TR/Dldr.Age.3566386 Trojan
[NOTE] The file was moved to '4b55d37f.qua'!
C:\Documents and Settings\Rebecca\Shared\she fucking hates me.mp3
[DETECTION] Is the TR/Brisv.B Trojan
[NOTE] The file was moved to '4b53d37e.qua'!
C:\Documents and Settings\Rebecca\Shared\vanessa over the rainbow bob frisell chase.wma
[DETECTION] Is the TR/Dldr.WMA.Wima.AA Trojan
[NOTE] The file was moved to '4b5cd377.qua'!
C:\Microgaming\Poker\bet365MPP\local\da\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b5bd385.qua'!
C:\Microgaming\Poker\bet365MPP\local\de\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4ebcc63e.qua'!
C:\Microgaming\Poker\bet365MPP\local\en\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b5bd386.qua'!
C:\Microgaming\Poker\bet365MPP\local\es\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b5bd387.qua'!
C:\Microgaming\Poker\bet365MPP\local\fr\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '48cc0e20.qua'!
C:\Microgaming\Poker\bet365MPP\local\it\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e0630f8.qua'!
C:\Microgaming\Poker\bet365MPP\local\no\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e0538b0.qua'!
C:\Microgaming\Poker\bet365MPP\local\sv\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e042088.qua'!
C:\Microgaming\Poker\bet365MPP\local\zh-cn\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e3b2940.qua'!
C:\Microgaming\Poker\bet365MPP\local\zh-tw\Common\CommonRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e39d118.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\da\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b53d388.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\de\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e35f239.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\en\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e34faf1.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\es\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e3be2c9.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\fr\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e3aea81.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\it\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e399359.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\no\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e389b11.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\sv\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b53d389.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\zh-cn\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e3e8ba2.qua'!
C:\Microgaming\Poker\bet365MPP\theme\bet365\local\zh-tw\ClientConfig\OperatorRes.dll
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4e3d8c7a.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP533\A0149762.reg
[DETECTION] Is the TR/REG.Koobface.89 Trojan
[NOTE] The file was moved to '4b1fd349.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP535\A0153824.reg
[DETECTION] Is the TR/REG.Koobface.89 Trojan
[NOTE] The file was moved to '4efad562.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154882.dll
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e7bc16a.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154883.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e450092.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154885.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e7cd912.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154886.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e6fbcca.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154887.exe
[DETECTION] Is the TR/Wippy.19968 Trojan
[NOTE] The file was moved to '4e6ea402.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154888.dll
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e70b4f2.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154890.exe
[DETECTION] Is the TR/Wippy.19968 Trojan
[NOTE] The file was moved to '4e6dac5a.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154895.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e6c5592.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154896.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e6b5dea.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154897.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e6a4522.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154898.exe
[DETECTION] Contains recognition pattern of the WORM/Koobface.24576 worm
[NOTE] The file was moved to '4e694d7a.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP536\A0154950.exe
[DETECTION] Is the TR/Drop.Softomat.AN Trojan
[NOTE] The file was moved to '4e6876b2.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP537\A0154966.dll
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e677e8a.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP579\A0171411.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e6666c2.qua'!
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP579\A0171412.exe
[DETECTION] Is the TR/Trash.Gen Trojan
[NOTE] The file was moved to '4e656e1a.qua'!
C:\WINDOWS\system32\FlashAX\FlashAX.ocx
[DETECTION] Contains recognition pattern of the GAME/Casino.Gen game
[NOTE] The file was moved to '4b4fd385.qua'!


End of the scan: Monday, November 02, 2009 12:39
Used time: 50:58 Minute(s)

The scan has been done completely.

10689 Scanned directories
362390 Files were scanned
48 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
48 Files were moved to quarantine
0 Files were renamed
2 Files cannot be scanned
362340 Files not concerned
4508 Archives were scanned
2 Warnings
50 Notes
90701 Objects were scanned with rootkit scan
0 Hidden objects were found

I haven't done anything else with the scan for now..ie deleted or restored quarentined objects.. i will await your instruction..:rolleyes:
 
Hi

limewire :nono:
NOTE: Even if you are using a "safe P2P program", it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

1 - Remove bad HijackThis entries
  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):

    • R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
  • Close all open windows and browsers/email, etc...
  • Click on the "Fix Checked" button
  • When completed, close the application.

2 - Update Java Runtime

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 16.
  • Go to Java Site
  • Click to Download Java SE Runtime Environment (JRE) 6 Update 16
  • In Platform box choose Windows.
  • Check the box to Accept License Agreement and click Continue.
  • Click on Windows Offline Installation, click on the link under it which says "jre-6u16-windows-i586-p.exe" and save the downloaded file to your desktop.
  • Go to Start => Control Panel => Add or Remove Programs
  • Uninstall all old versions of Java (Java 3 Runtime Environment, JRE or JSE)
  • Install the new version by running the newly-downloaded file with the java icon which will be at your desktop, and follow the on-screen instructions.
  • Reboot your computer

3 - Clean temp files

Please download ATF Cleaner by Atribune.

  • Save it to your desktop
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

    If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.

    NOTE: If you would like to keep your saved passwords
    please click No at the prompt.


    If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.

    NOTE: If you would like to keep your saved passwords
    please click No at the prompt.

  • Click Exit on the Main menu to close the program.

For Technical Support double-click the e-mail address located at the bottom of each menu.

4 - Kaspersky Online Scan

You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply along with a fresh HijackThis log.

Thanks peku006
 
Hi

limewire :nono:
NOTE: Even if you are using a "safe P2P program", it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

1 - Remove bad HijackThis entries
  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):

    • R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
  • Close all open windows and browsers/email, etc...
  • Click on the "Fix Checked" button
  • When completed, close the application.

2 - Update Java Runtime

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 16.
  • Go to Java Site
  • Click to Download Java SE Runtime Environment (JRE) 6 Update 16
  • In Platform box choose Windows.
  • Check the box to Accept License Agreement and click Continue.
  • Click on Windows Offline Installation, click on the link under it which says "jre-6u16-windows-i586-p.exe" and save the downloaded file to your desktop.
  • Go to Start => Control Panel => Add or Remove Programs
  • Uninstall all old versions of Java (Java 3 Runtime Environment, JRE or JSE)
  • Install the new version by running the newly-downloaded file with the java icon which will be at your desktop, and follow the on-screen instructions.
  • Reboot your computer

3 - Clean temp files

Please download ATF Cleaner by Atribune.

  • Save it to your desktop
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

    If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.

    NOTE: If you would like to keep your saved passwords
    please click No at the prompt.


    If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.

    NOTE: If you would like to keep your saved passwords
    please click No at the prompt.

  • Click Exit on the Main menu to close the program.

For Technical Support double-click the e-mail address located at the bottom of each menu.

4 - Kaspersky Online Scan

You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply along with a fresh HijackThis log.

Thanks peku006

Hi Peku006,
I thought Limewire was removed since yesterday? - do i need to do something more with this?

Here is the Kaspersky report:

ASPERSKY ONLINE SCANNER 7.0: scan report
Monday, November 2, 2009
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Monday, November 02, 2009 16:08:40
Records in database: 3114865
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
H:\
I:\
J:\

Scan statistics:
Objects scanned: 88994
Threats found: 3
Infected objects found: 3
Suspicious objects found: 0
Scan duration: 01:55:21


File name / Threat / Threats count
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-2563347-she fucking hates me.mp3 Infected: Trojan-Downloader.WMA.Wimad.r 1
C:\Program Files\MSN Messenger\msimg32.dll Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.au 1
C:\Qoobox\Quarantine\C\WINDOWS\yvixrx.tmp.vir Infected: Trojan-PSW.Win32.Kates.j 1

Selected area has been scanned.

here's the HJT report
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:36:25 PM, on 02/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Netgear\WG111v3\WG111v3.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Rebecca\Local Settings\Temp\jkos-Rebecca\binaries\ScanningProcess.exe
C:\Documents and Settings\Rebecca\Local Settings\Temp\jkos-Rebecca\binaries\ScanningProcess.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [DLCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = D:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\Netgear\WG111v3\WG111v3.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: bet365 Poker - {B1BA4A3F-1C95-497b-9F82-F8DA4A5C89DD} - C:\Microgaming\Poker\bet365MPP\MPPoker.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: www.bebo.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {33415AC7-AFFA-4D55-B41C-C64C0D07DFCA} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWebManager.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://mppv2flash3.valueactive.com/Bet365/FlashAX.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cryptographic Services (CryptSvc) - Unknown owner - C:\Program Files\Dell Support\bin\MsPMSNSv.exe (file missing)
O23 - Service: dlcf_device - - C:\WINDOWS\system32\dlcfcoms.exe
O23 - Service: Google Desktop Manager 5.9.909.30391 (GoogleDesktopManager-093009-130223) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: AutomatedSurfer (SurferService) - Unknown owner - C:\WINDOWS\system32\srvany.exe

--
End of file - 12029 bytes

I removed the old version of JAVA and downloaded the newer version as advised - however, the only option it has was "jre-6u16-windows-i586-.exe" and not "jre-6u16-windows-i586-p.exe" - the one available to download didn't have the "p" at the end, does this make a difference?

Also; what do I do with the Threats found on the Kaspersky report?

thanks
 
Hi IT Novice
do i need to do something more with this?
not necessary
I removed the old version of JAVA and downloaded the newer version as advised - however, the only option it has was "jre-6u16-windows-i586-.exe" and not "jre-6u16-windows-i586-p.exe" - the one available to download didn't have the "p" at the end, does this make a difference?
jre-6u16-windows-i586-.exe was right :yes:
Also; what do I do with the Threats found on the Kaspersky report?
you need to remove them now

Please delete these files
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-2563347-she fucking hates me.mp3
C:\Program Files\MSN Messenger\msimg32.dll

How's the computer running now? Any problems?

Thanks peku006
 
Hi IT Novice

not necessary

jre-6u16-windows-i586-.exe was right :yes:

you need to remove them now

Please delete these files
C:\Documents and Settings\Rebecca\Incomplete\Preview-T-2563347-she fucking hates me.mp3
C:\Program Files\MSN Messenger\msimg32.dll

How's the computer running now? Any problems?

Thanks peku006

Hi there,
Do I just press delete from the report to delete them? - also apologies for the rude name on that song..

it's still taking about 5-6 attempts after it's powered on to start up - got the blue screen once today already.
 
Hi IT Novice

Using Windows Explore by right-clicking the start button and left clicking Explore navigate to and find the following files : if found, delete them (some may not be present after previous steps):

Files:

C:\Documents and Settings\Rebecca\Incomplete\Preview-T-2563347-she fucking hates me.mp3
C:\Program Files\MSN Messenger\msimg32.dll

Do you have problems with MyWayWebSearch

Thanks peku006
 
Hi IT Novice

Using Windows Explore by right-clicking the start button and left clicking Explore navigate to and find the following files : if found, delete them (some may not be present after previous steps):

Files:

C:\Documents and Settings\Rebecca\Incomplete\Preview-T-2563347-she fucking hates me.mp3
C:\Program Files\MSN Messenger\msimg32.dll

Do you have problems with MyWayWebSearch

Thanks peku006

Hi,
I have deleted these now.. no problems with MyWayWebSearch - it seem's to be gone.

Only problem now is on the start up of the pc - still taking 5-6 attempts (keeps shutting down)

Thanks
 
Hi IT Novice

VEW - Vino's Event Viewer
Please download VEW.exe... by Vino Rosso. Save it to your desktop.
  1. Double click on VEW.exe to start the program. If you recieve an "Open File" security warning, press Run.
    Vista users, right-click on VEW.exe and select "Run as Administrator." If UAC prompts... accept it.
  2. In the "Select log to query" section check:
    • Application
    • System
  3. In the "Select type to list" section check:
    • Error
    • Information
    • Warning
  4. In the "Number or dates of events" section check either:
    • Number of events... then enter any number from 1 thru 20 in the entry box.
    • Date of events... then enter the From and To dates you want. (Note... date format: dd mm yyyy)
  5. Press the Run button.
    When the process completes, it only takes a few seconds...
  6. Notepad will open with a report file named: VEW.txt... located on %SystemDrive%\VEW.txt ... usually C:\VEW.txt.
  7. Please copy and paste the contents of the VEW.txt file, in your next reply.

Thanks peku006
 
Hi Peku006,
I have ran the Vew as instructed - however - if i put dates e.g. 01 10 2009 - 03 11 2009 - the file size is too big for an attachment and also there are too many characters (871944) so I ran it without dates and put the number to 19 - hope this is enough info:
Vino's Event Viewer v01c run on Windows XP in English
Report run at 03/11/2009 9:49:34 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 03/11/2009 7:17:01 AM
Type: error Category: 0
Event: 3 Source: Microsoft-Windows-SpoolerFilterPipelineSVC
The event description cannot be found.

Log: 'Application' Date/Time: 02/11/2009 11:39:45 AM
Type: error Category: 0
Event: 11 Source: crypt32
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Log: 'Application' Date/Time: 02/11/2009 11:39:44 AM
Type: error Category: 0
Event: 11 Source: crypt32
Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.

Log: 'Application' Date/Time: 02/11/2009 8:19:00 AM
Type: error Category: 1
Event: 32045 Source: Microsoft Fax
Fax Service failed to initialize because it could not initialize the TAPI devices. Verify that the fax modem was installed and configured correctly. Win32 error code: 31. This error code indicates the cause of the error.

Log: 'Application' Date/Time: 02/11/2009 8:19:00 AM
Type: error Category: 0
Event: 28 Source: WinMgmt
WinMgmt could not initialize the core parts. This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

Log: 'Application' Date/Time: 01/11/2009 11:12:05 PM
Type: error Category: 1
Event: 32045 Source: Microsoft Fax
Fax Service failed to initialize because it could not initialize the TAPI devices. Verify that the fax modem was installed and configured correctly. Win32 error code: 31. This error code indicates the cause of the error.

Log: 'Application' Date/Time: 01/11/2009 9:50:47 PM
Type: error Category: 0
Event: 1000 Source: Windows Product Activation
An error occurred while the wizard was checking the current Windows product license. Error Code: 0x80070013

Log: 'Application' Date/Time: 01/11/2009 9:50:47 PM
Type: error Category: 0
Event: 1000 Source: Windows Product Activation
An error occurred while the wizard was checking the current Windows product license. Error Code: 8: 0x80070013

Log: 'Application' Date/Time: 01/11/2009 9:49:40 PM
Type: error Category: 0
Event: 1000 Source: Windows Product Activation
An error occurred while the wizard was checking the current Windows product license. Error Code: 0x80070013

Log: 'Application' Date/Time: 01/11/2009 9:49:40 PM
Type: error Category: 0
Event: 1000 Source: Windows Product Activation
An error occurred while the wizard was checking the current Windows product license. Error Code: 8: 0x80070013

Log: 'Application' Date/Time: 01/11/2009 9:41:55 PM
Type: error Category: 100
Event: 1000 Source: Application Error
Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Log: 'Application' Date/Time: 01/11/2009 9:41:47 PM
Type: error Category: 100
Event: 1000 Source: Application Error
Faulting application explorer.exe, version 6.0.2900.3156, faulting module unknown, version 0.0.0.0, fault address 0x02a31e77.

Log: 'Application' Date/Time: 01/11/2009 7:38:02 PM
Type: error Category: 2
Event: 100 Source: AVG7
The event description cannot be found.

Log: 'Application' Date/Time: 01/11/2009 7:20:02 PM
Type: error Category: 0
Event: 1000 Source: Application Error
Faulting application set20.tmp, version 11.50.0.42618, faulting module , version 0.0.0.0, fault address 0x00000000.

Log: 'Application' Date/Time: 01/11/2009 7:19:05 PM
Type: error Category: 0
Event: 1000 Source: Application Error
Faulting application set1e.tmp, version 11.50.0.42618, faulting module , version 0.0.0.0, fault address 0x00000000.

Log: 'Application' Date/Time: 01/11/2009 7:17:36 PM
Type: error Category: 0
Event: 1000 Source: Application Error
Faulting application set1c.tmp, version 11.50.0.42618, faulting module , version 0.0.0.0, fault address 0x00000000.

Log: 'Application' Date/Time: 01/11/2009 7:05:21 PM
Type: error Category: 2
Event: 100 Source: AVG7
The event description cannot be found.

Log: 'Application' Date/Time: 01/11/2009 7:04:26 PM
Type: error Category: 2
Event: 100 Source: AVG7
The event description cannot be found.

Log: 'Application' Date/Time: 01/11/2009 6:13:06 PM
Type: error Category: 2
Event: 100 Source: AVG7
The event description cannot be found.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - information Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 03/11/2009 7:40:24 AM
Type: information Category: 1
Event: 4096 Source: Avira AntiVir
The AntiVir service has been started successfully!

Log: 'Application' Date/Time: 03/11/2009 7:40:16 AM
Type: information Category: 1
Event: 4097 Source: Avira AntiVir
The AntiVir service has been stopped!

Log: 'Application' Date/Time: 03/11/2009 7:23:14 AM
Type: information Category: 0
Event: 0 Source: gusvc
The event description cannot be found.

Log: 'Application' Date/Time: 03/11/2009 7:23:14 AM
Type: information Category: 0
Event: 0 Source: iPod Service
The event description cannot be found.

Log: 'Application' Date/Time: 03/11/2009 7:22:39 AM
Type: information Category: 1
Event: 4096 Source: Avira AntiVir
The AntiVir service has been started successfully!

Log: 'Application' Date/Time: 03/11/2009 7:22:33 AM
Type: information Category: 0
Event: 1800 Source: SecurityCenter
The Windows Security Center Service has started.

Log: 'Application' Date/Time: 03/11/2009 7:22:22 AM
Type: information Category: 0
Event: 0 Source: SeaPort
Service started

Log: 'Application' Date/Time: 03/11/2009 7:22:11 AM
Type: information Category: 0
Event: 0 Source: gusvc
The event description cannot be found.

Log: 'Application' Date/Time: 03/11/2009 7:22:10 AM
Type: information Category: 0
Event: 105 Source: Creative Service for CDROM Access
The service was started.

Log: 'Application' Date/Time: 03/11/2009 7:20:54 AM
Type: information Category: 0
Event: 0 Source: SeaPort
Service started

Log: 'Application' Date/Time: 03/11/2009 7:20:44 AM
Type: information Category: 0
Event: 0 Source: gusvc
The event description cannot be found.

Log: 'Application' Date/Time: 03/11/2009 7:20:42 AM
Type: information Category: 0
Event: 105 Source: Creative Service for CDROM Access
The service was started.

Log: 'Application' Date/Time: 03/11/2009 7:19:25 AM
Type: information Category: 0
Event: 0 Source: SeaPort
Service started

Log: 'Application' Date/Time: 03/11/2009 7:19:15 AM
Type: information Category: 0
Event: 0 Source: gusvc
The event description cannot be found.

Log: 'Application' Date/Time: 03/11/2009 7:19:14 AM
Type: information Category: 0
Event: 105 Source: Creative Service for CDROM Access
The service was started.

Log: 'Application' Date/Time: 03/11/2009 7:18:03 AM
Type: information Category: 0
Event: 0 Source: SeaPort
Service started

Log: 'Application' Date/Time: 03/11/2009 7:17:57 AM
Type: information Category: 0
Event: 0 Source: gusvc
The event description cannot be found.

Log: 'Application' Date/Time: 03/11/2009 7:17:56 AM
Type: information Category: 0
Event: 105 Source: Creative Service for CDROM Access
The service was started.

Log: 'Application' Date/Time: 03/11/2009 7:16:45 AM
Type: information Category: 0
Event: 0 Source: SeaPort
Service started

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 03/11/2009 7:22:41 AM
Type: warning Category: 1
Event: 32068 Source: Microsoft Fax
The outgoing routing rule is not valid because it cannot find a valid device. The outgoing faxes that use this rule will not be routed. Verify that the targeted device or devices (if routed to a group of devices) is connected and installed correctly, and turned on. If routed to a group, verify that the group is configured correctly. Country/region code: '*' Area code: '*'

Log: 'Application' Date/Time: 03/11/2009 7:22:41 AM
Type: warning Category: 1
Event: 32026 Source: Microsoft Fax
Fax Service failed to initialize any assigned fax devices (virtual or TAPI). No faxes can be sent or received until a fax device is installed.

Log: 'Application' Date/Time: 02/11/2009 6:07:24 PM
Type: warning Category: 0
Event: 0 Source: System.ServiceModel.Install 3.0.0.0
Configuration section system.serviceModel.activation already exists in c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Config\machine.config.

Log: 'Application' Date/Time: 02/11/2009 6:07:24 PM
Type: warning Category: 0
Event: 0 Source: System.ServiceModel.Install 3.0.0.0
Configuration section system.runtime.serialization already exists in c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Config\machine.config.

Log: 'Application' Date/Time: 02/11/2009 6:07:23 PM
Type: warning Category: 0
Event: 0 Source: System.ServiceModel.Install 3.0.0.0
Configuration section system.serviceModel already exists in c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Config\machine.config.

Log: 'Application' Date/Time: 02/11/2009 6:07:23 PM
Type: warning Category: 0
Event: 0 Source: System.ServiceModel.Install 3.0.0.0
Could not detect IIS installation or IIS is disabled, skipping the Web Host Script Mappings component since it depends upon IIS to function properly. If you believe this message is an error, check your IIS installation to make sure it is installed properly.

Log: 'Application' Date/Time: 02/11/2009 6:06:51 PM
Type: warning Category: 1
Event: 1020 Source: ASP.NET 2.0.50727.0
Updates to the IIS metabase were aborted because IIS is either not installed or is disabled on this machine. To configure ASP.NET to run in IIS, please install or enable IIS and re-register ASP.NET using aspnet_regiis.exe /i.

Log: 'Application' Date/Time: 02/11/2009 6:04:17 PM
Type: warning Category: 0
Event: 0 Source: System.ServiceModel.Install 3.0.0.0
HTTP namespace reservations are not installed.

Log: 'Application' Date/Time: 02/11/2009 6:04:16 PM
Type: warning Category: 0
Event: 0 Source: System.ServiceModel.Install 3.0.0.0
HttpModules node ServiceModel does not exist in System.Web section group.

Log: 'Application' Date/Time: 02/11/2009 6:04:16 PM
Type: warning Category: 0
Event: 0 Source: System.ServiceModel.Install 3.0.0.0
HttpHandlers node *.svc does not exist in System.Web section group.

Log: 'Application' Date/Time: 02/11/2009 6:04:16 PM
Type: warning Category: 0
Event: 0 Source: System.ServiceModel.Install 3.0.0.0
All compilation assembly nodes do not exist in System.Web section group.

Log: 'Application' Date/Time: 02/11/2009 6:04:16 PM
Type: warning Category: 0
Event: 0 Source: System.ServiceModel.Install 3.0.0.0
A configuration entry for BuildProvider System.ServiceModel.Activation.ServiceBuildProvider, System.ServiceModel, Version=3.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 does not exist.

Log: 'Application' Date/Time: 02/11/2009 6:04:14 PM
Type: warning Category: 0
Event: 0 Source: System.ServiceModel.Install 3.0.0.0
Could not detect IIS installation or IIS is disabled, skipping the Web Host Script Mappings component since it depends upon IIS to function properly. If you believe this message is an error, check your IIS installation to make sure it is installed properly.

Log: 'Application' Date/Time: 02/11/2009 6:02:44 PM
Type: warning Category: 1
Event: 1020 Source: ASP.NET 2.0.50727.0
Updates to the IIS metabase were aborted because IIS is either not installed or is disabled on this machine. To configure ASP.NET to run in IIS, please install or enable IIS and re-register ASP.NET using aspnet_regiis.exe /i.

Log: 'Application' Date/Time: 02/11/2009 5:51:38 PM
Type: warning Category: 1
Event: 32068 Source: Microsoft Fax
The outgoing routing rule is not valid because it cannot find a valid device. The outgoing faxes that use this rule will not be routed. Verify that the targeted device or devices (if routed to a group of devices) is connected and installed correctly, and turned on. If routed to a group, verify that the group is configured correctly. Country/region code: '*' Area code: '*'

Log: 'Application' Date/Time: 02/11/2009 5:51:38 PM
Type: warning Category: 1
Event: 32026 Source: Microsoft Fax
Fax Service failed to initialize any assigned fax devices (virtual or TAPI). No faxes can be sent or received until a fax device is installed.

Log: 'Application' Date/Time: 02/11/2009 5:31:47 PM
Type: warning Category: 2
Event: 4113 Source: Avira AntiVir
AntiVir has detected 'GAME/Casino.Gen' in the file C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP597\A0184074.dll

Log: 'Application' Date/Time: 02/11/2009 5:16:45 PM
Type: warning Category: 1
Event: 32068 Source: Microsoft Fax
The outgoing routing rule is not valid because it cannot find a valid device. The outgoing faxes that use this rule will not be routed. Verify that the targeted device or devices (if routed to a group of devices) is connected and installed correctly, and turned on. If routed to a group, verify that the group is configured correctly. Country/region code: '*' Area code: '*'

Log: 'Application' Date/Time: 02/11/2009 5:16:45 PM
Type: warning Category: 1
Event: 32026 Source: Microsoft Fax
Fax Service failed to initialize any assigned fax devices (virtual or TAPI). No faxes can be sent or received until a fax device is installed.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 03/11/2009 7:15:20 AM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1053" attempting to start the service dlcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}

Log: 'System' Date/Time: 03/11/2009 7:15:00 AM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The dlcf_device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 03/11/2009 7:15:00 AM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the dlcf_device service to connect.

Log: 'System' Date/Time: 03/11/2009 7:15:00 AM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1053" attempting to start the service dlcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}

Log: 'System' Date/Time: 02/11/2009 5:49:20 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1053" attempting to start the service dlcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}

Log: 'System' Date/Time: 02/11/2009 5:49:11 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The dlcf_device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 02/11/2009 5:49:11 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the dlcf_device service to connect.

Log: 'System' Date/Time: 02/11/2009 5:49:11 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1053" attempting to start the service dlcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}

Log: 'System' Date/Time: 02/11/2009 5:48:45 PM
Type: error Category: 102
Event: 1003 Source: System Error
Error code 1000000a, parameter1 00000000, parameter2 0000001c, parameter3 00000001, parameter4 804fb006.

Log: 'System' Date/Time: 02/11/2009 3:44:25 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1053" attempting to start the service dlcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}

Log: 'System' Date/Time: 02/11/2009 3:44:16 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The dlcf_device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 02/11/2009 3:44:16 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the dlcf_device service to connect.

Log: 'System' Date/Time: 02/11/2009 3:44:16 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1053" attempting to start the service dlcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}

Log: 'System' Date/Time: 02/11/2009 3:21:48 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1053" attempting to start the service dlcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}

Log: 'System' Date/Time: 02/11/2009 3:14:17 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The dlcf_device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 02/11/2009 3:14:17 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the dlcf_device service to connect.

Log: 'System' Date/Time: 02/11/2009 3:14:17 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1053" attempting to start the service dlcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}

Log: 'System' Date/Time: 02/11/2009 7:26:57 AM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1053" attempting to start the service dlcf_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441060}

Log: 'System' Date/Time: 02/11/2009 7:26:48 AM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The dlcf_device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - information Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 03/11/2009 7:40:24 AM
Type: information Category: 0
Event: 7036 Source: Service Control Manager
The Avira AntiVir Guard service entered the running state.

Log: 'System' Date/Time: 03/11/2009 7:40:19 AM
Type: information Category: 0
Event: 7035 Source: Service Control Manager
The Avira AntiVir Guard service was successfully sent a start control.

Log: 'System' Date/Time: 03/11/2009 7:40:16 AM
Type: information Category: 0
Event: 7036 Source: Service Control Manager
The Avira AntiVir Guard service entered the stopped state.

Log: 'System' Date/Time: 03/11/2009 7:28:23 AM
Type: information Category: 8
Event: 18 Source: Windows Update Agent
Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on Tuesday, November 03, 2009 at 6:00 PM:
- Security Update for Microsoft Visual C++ 2008 Redistributable Package (KB973924)
- February 2007 CardSpace Update for Windows XP (KB925720)
- Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB954459)
- Update for Windows XP (KB961118)
- Update for Internet Explorer 7 for Windows XP (KB976749)
- Microsoft .NET Framework 2.0 Service Pack 2 Security Update for Windows 2000, Windows Server 2003, and Windows XP (KB974417)

Log: 'System' Date/Time: 03/11/2009 7:28:15 AM
Type: information Category: 8
Event: 18 Source: Windows Update Agent
Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on Tuesday, November 03, 2009 at 6:00 PM:
- Security Update for Microsoft Visual C++ 2008 Redistributable Package (KB973924)
- February 2007 CardSpace Update for Windows XP (KB925720)
- Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB954459)
- Update for Windows XP (KB961118)
- Microsoft .NET Framework 2.0 Service Pack 2 Security Update for Windows 2000, Windows Server 2003, and Windows XP (KB974417)

Log: 'System' Date/Time: 03/11/2009 7:28:15 AM
Type: information Category: 8
Event: 18 Source: Windows Update Agent
Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on Tuesday, November 03, 2009 at 6:00 PM:
- Security Update for Microsoft Visual C++ 2008 Redistributable Package (KB973924)
- Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB954459)
- Update for Windows XP (KB961118)
- Microsoft .NET Framework 2.0 Service Pack 2 Security Update for Windows 2000, Windows Server 2003, and Windows XP (KB974417)

Log: 'System' Date/Time: 03/11/2009 7:26:57 AM
Type: information Category: 8
Event: 18 Source: Windows Update Agent
Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on Tuesday, November 03, 2009 at 6:00 PM:
- Security Update for Microsoft Visual C++ 2008 Redistributable Package (KB973924)
- Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB954459)
- Update for Windows XP (KB961118)

Log: 'System' Date/Time: 03/11/2009 7:26:57 AM
Type: information Category: 8
Event: 18 Source: Windows Update Agent
Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on Tuesday, November 03, 2009 at 6:00 PM:
- Security Update for Microsoft Visual C++ 2008 Redistributable Package (KB973924)
- Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB954459)

Log: 'System' Date/Time: 03/11/2009 7:26:38 AM
Type: information Category: 8
Event: 18 Source: Windows Update Agent
Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on Tuesday, November 03, 2009 at 6:00 PM:
- Security Update for Microsoft Visual C++ 2008 Redistributable Package (KB973924)

Log: 'System' Date/Time: 03/11/2009 7:26:10 AM
Type: information Category: 0
Event: 7036 Source: Service Control Manager
The Background Intelligent Transfer Service service entered the running state.

Log: 'System' Date/Time: 03/11/2009 7:26:09 AM
Type: information Category: 0
Event: 7035 Source: Service Control Manager
The Background Intelligent Transfer Service service was successfully sent a start control.

Log: 'System' Date/Time: 03/11/2009 7:24:01 AM
Type: information Category: 0
Event: 7036 Source: Service Control Manager
The HTTP SSL service entered the running state.

Log: 'System' Date/Time: 03/11/2009 7:24:01 AM
Type: information Category: 0
Event: 7035 Source: Service Control Manager
The HTTP SSL service was successfully sent a start control.

Log: 'System' Date/Time: 03/11/2009 7:23:43 AM
Type: information Category: 0
Event: 4201 Source: Tcpip
The system detected that network adapter \DEVICE\TCPIP_{71E20ADB-FAB7-4A62-9A8B-EC9C09E51739} was connected to the network, and has initiated normal operation over the network adapter.

Log: 'System' Date/Time: 03/11/2009 7:23:14 AM
Type: information Category: 0
Event: 7036 Source: Service Control Manager
The Google Software Updater service entered the stopped state.

Log: 'System' Date/Time: 03/11/2009 7:23:14 AM
Type: information Category: 0
Event: 7036 Source: Service Control Manager
The iPod Service service entered the running state.

Log: 'System' Date/Time: 03/11/2009 7:23:12 AM
Type: information Category: 0
Event: 7035 Source: Service Control Manager
The iPod Service service was successfully sent a start control.

Log: 'System' Date/Time: 03/11/2009 7:23:07 AM
Type: information Category: 0
Event: 7036 Source: Service Control Manager
The IMAPI CD-Burning COM Service service entered the stopped state.

Log: 'System' Date/Time: 03/11/2009 7:23:02 AM
Type: information Category: 0
Event: 7036 Source: Service Control Manager
The Remote Access Connection Manager service entered the running state.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 02/11/2009 6:03:45 PM
Type: warning Category: 0
Event: 20 Source: Print
Printer Driver Microsoft XPS Document Writer for Windows NT x86 Version-3 was added or updated. Files:- mxdwdrv.dll, unidrvui.dll, mxdwdui.gpd, unidrv.hlp, mxdwdui.dll, mxdwdui.ini, stddtype.gdl, stdnames.gpd, stdschem.gdl, stdschmx.gdl, unidrv.dll, unires.dll, XpsSvcs.dll.

Log: 'System' Date/Time: 01/11/2009 9:34:27 AM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 01/11/2009 9:20:47 AM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 31/10/2009 10:01:29 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 31/10/2009 8:12:16 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 31/10/2009 7:17:36 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 31/10/2009 6:50:16 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 31/10/2009 6:36:37 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 29/10/2009 10:32:01 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 29/10/2009 6:53:31 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 29/10/2009 5:04:17 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 29/10/2009 4:07:49 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 29/10/2009 3:34:39 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 29/10/2009 3:20:59 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 28/10/2009 10:56:48 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 28/10/2009 10:43:08 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 28/10/2009 9:58:01 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 28/10/2009 9:44:14 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 28/10/2009 9:27:35 PM
Type: warning Category: 0
Event: 10 Source: W32Time
The time provider 'NtpClient' returned an error when asked for time samples. The error will be ignored. The error was: The handle is invalid. (0x80070006)
 
Hi IT Novice

Let´s try this.........

Run chkdsk
  • Got to Start, Run and type cmd and hit Enter
  • When the command window comes up, type: chkdsk c:
  • hit Enter again.
  • Maximize the command window, and wait for the scan to finish.
  • Read the results carefully to see if it says that it found problems with your file system.
IF it has found any problems with your file system,
  • Go To Start, Run and type cmd
  • hit Enter
  • Type this into the command window at the prompt:

    • chkdsk c: /F <==notice the /F, with one space between c: and /F
  • hit Enter
  • You will get a message that the volume is locked, and a request to do the repair on Reboot.
  • Answer Y
  • Then type exit to close the Command window.
  • Go to Start, Turn Off Computer and choose Reboot
  • It will scan again and make the repairs as the first part of the reboot process.

After it reboots, run the first sequence again (without the /F parameter), and see if it still shows an error.
Tell me what it found originally, and if there was a problem, whether the final sequence showed no errors.
It's possible that the chkdsk c: /F sequence may have to be run on reboot twice to pick up everything.

post back if it helped.

Thanks peku006
 
Hi IT Novice

Let´s try this.........

Run chkdsk
  • Got to Start, Run and type cmd and hit Enter
  • When the command window comes up, type: chkdsk c:
  • hit Enter again.
  • Maximize the command window, and wait for the scan to finish.
  • Read the results carefully to see if it says that it found problems with your file system.
IF it has found any problems with your file system,
  • Go To Start, Run and type cmd
  • hit Enter
  • Type this into the command window at the prompt:

    • chkdsk c: /F <==notice the /F, with one space between c: and /F
  • hit Enter
  • You will get a message that the volume is locked, and a request to do the repair on Reboot.
  • Answer Y
  • Then type exit to close the Command window.
  • Go to Start, Turn Off Computer and choose Reboot
  • It will scan again and make the repairs as the first part of the reboot process.

After it reboots, run the first sequence again (without the /F parameter), and see if it still shows an error.
Tell me what it found originally, and if there was a problem, whether the final sequence showed no errors.
It's possible that the chkdsk c: /F sequence may have to be run on reboot twice to pick up everything.

post back if it helped.

Thanks peku006

Hi Peku006,
I have run this sequence 3 times with the F parameter and without as it found problems;
1st attempt it was "correcting errors in the MFT BITMAP attribute" & "Correcting Errors in the Volume Bitmap"
It said it found problems with the File System and to run again with /F

I did this and ran the chkdsk and it was correcting errors in the Volume Bitmap. And it still Found problems with the File System and to run again with /F - which i did.

ran it a 3rd time and got the same messages.

thanks
 
Hi IT Novice

Not a Malware Issues

At this stage your machine looks to be clean of malware, so the problems you are experiencing are not likely to be malware related. I think the best and fastest solution for you is to post on a PC troubleshooting forum like the Browsers, Internet & email forum at WhatTheTech. They specialize in handling problems like this so you are certain to get expert assistance and a speedy resolution is very likely.

I'm sorry that I could not be of more help to you, and I wish you the best of luck with solving your computer problems. If you have any questions or require any other assistance please let me know.

Thanks peku006
 
Back
Top