Announcement Banner
UNSOLVED

dalem29

updated

16 years ago

D

dalem29

2 Intern

•

2198 Posts

0

2445

February 17th, 2011 12:00

Slow Startup

This XPS 420 computer is painfully slow to start up. From the time I press the switch until I can press the icon for MSN "seems" to border on almost 5 minutes. Last week when we had the bunch of updates, the desktop and all of its icons came up , but after the download and installation and restart,  nothing else showed up on the status bar except the clock.. The missing items included the icons for Online Armor and Avast 5. I don't know if they just didn't load, or if its just the icons not showing up in the tray. This doesn't have on every startup. Another problem that shows up at times during the day, is that I have to restart the browser, which is IE7. Neither IE8 or SP2 will download and install correctly which is why I have neither. The update acts like everything is going OK, then toward the end of the process the installation "reverts" and the process is aborted.  And the last few weeks even the WD updates sometimes fail on the first try.

Once this computer is up and going it works fine, and various scans for malware come up clean. Not sure if I should reinstall the OS or how involved it would be,  and really have no desire to if it would involve losing all my saved files, pics, clips, etc. Trying to make it last until I can get a new computer, but I wanted to find out if there is anything showing up here that could be bogging me down.  I have never done a defrag or chkdsk of this machine, because it says it is not fragmented that much...so that might be part of the problem. Any advice welcome, but would like to see if anything shows up in this log.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:54:50 PM, on 2/17/2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18565)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Online Armor\OAcat.exe
C:\Program Files\Online Armor\oasrv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
C:\Windows\system32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Online Armor\oaui.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\MobileCenter.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Online Armor\OAhlp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\RocketTime.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Online Armor\oaui.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe -expressboot
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RocketAppCenter.exe] "C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\MobileCenter.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Rocket.Time.lnk = ?
O8 - Extra context menu item: Search Image on TinEye - file://C:\Users\Dale\Documents\TinEye 1.0\TinEye.js
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (Emsisoft Web Malware Scan) - http://ax.emsisoft.com/emsisoft_webscan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{73189B5E-92B3-46AC-BCFF-33C6B52CEFF2}: NameServer = 208.67.222.222,208.67.220.220
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Online Armor Helper Service (OAcat) - Unknown owner - C:\Program Files\Online Armor\OAcat.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Listener Service (sprtlisten) - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files\Online Armor\oasrv.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10816 bytes

  • kevin27_b3d29f

    2 Intern

    •

    1547 Posts

    797

    0

    Posted February 21st, 2011 05:00

    Hi dalem29,

    Welcome to the MR Forums.

    We will do a check for malware but I think the amount of Security on the system, ThreatFire, Avast, OA, Winpatrol could be the reason its is taking longer to start the system. We may be able to counteract this by disabling some of the other un-needed startup entries.

    It is more than likely these programs that are hindering the install of SP2 and IE8 but we will get to the later.

    Please uninstall ThreatFire from the system via "Programs and Features" in Control Panel. The other security app you have running are more than adequate to help keep you protected. ThreatFire is really not needed.

     

    Download and scan with CCleaner
    1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free or Slim versions instead of the Standard Build.
    2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"
    3. Then select the items you wish to clean up.
    In the Windows Tab:

    • Clean all entries in the "Internet Explorer" section except Cookies if you want to keep those.
    • Clean all the entries in the "Windows Explorer" section.
    • Clean all entries in the "System" section.
    • Clean all entries in the "Advanced" section.
    • Clean any others that you choose.

    In the Applications Tab:

    • Clean all except cookies in the Firefox/Mozilla section if you use it.
    • Clean all in the Opera section if you use it.
    • Clean Sun Java in the Internet Section.
    • Clean any others that you choose.

    4. Click the "Run Cleaner" button.
    5. A pop up box will appear advising this process will permanently delete files from your system.
    6. Click "OK" and it will scan and clean your system.
    7. Click "exit" when done.

     

     

    Then Please download Malwarebytes Anti-Malware and save it to your desktop.
    alternate download link 1
    alternate download link 2

    MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

    • Make sure you are connected to the Internet.
    • Double-click on mbam-setup.exe to install the application.
    • When the installation begins, follow the prompts and do not make any changes to default settings.
    • When installation has finished, make sure you leave both of these checked:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
    • Then click Finish.

    MBAM will automatically start and you will be asked to update the program before performing a scan.

    • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
    • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.

    On the Scanner tab:

    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
    • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
    • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
    • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
    • Click OK to close the message box and continue with the removal process.

    Back at the main Scanner screen:

    • Click on the Show Results button to see a list of any malware that was found.
    • Make sure that everything is checked, and click Remove Selected.
    • When removal is completed, a log report will open in Notepad.
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
    • Exit MBAM when done.

    Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

     

     

     

    I then need to see some additional information about what is happening in your machine.
    Please perform the following scan:

    • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • Double click on the DDS icon, allow it to run.
    • A small box will open, with an explanation about the tool.
    • When done, DDS will open two (2) logs
      1. DDS.txt
      2. Attach.txt
    • Save both reports to your desktop.
    • The instructions here ask you to attach the Attach.txt.
      DDS.jpg
    • Instead of attaching, please copy/past both logs into your next reply.

       

       

    • Close the program window, and delete the program from your desktop.

    Please note: You may have to disable any script protection running if the scan fails to run.
    After downloading the tool, disconnect from the internet and disable all antivirus protection.
    Run the scan, enable your A/V and reconnect to the internet.
    Information on A/V control HERE

     

    Please copy/paste back the MBAM log and BOTH DDS logs for review.

    Thanks.

  • dalem29

    2 Intern

    •

    2198 Posts

    797

    0

    Posted February 21st, 2011 10:00

    Hi Kevin:

    I do want to clean this out, but something came up this morning that might not allow me to get back to you until tomorrow or Wednesday. Hopefully that will be OK. Will try to get to this as soon as I can.

    EDIT: Got the situation resolved, here are the logs.

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5832

    Windows 6.0.6001 Service Pack 1
    Internet Explorer 7.0.6001.18000

    2/21/2011 1:41:18 PM
    mbam-log-2011-02-21 (13-41-18).txt

    Scan type: Quick scan
    Objects scanned: 140056
    Time elapsed: 2 minute(s), 59 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

     

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5832

    Windows 6.0.6001 Service Pack 1
    Internet Explorer 7.0.6001.18000

    2/21/2011 1:41:18 PM
    mbam-log-2011-02-21 (13-41-18).txt

    Scan type: Quick scan
    Objects scanned: 140056
    Time elapsed: 2 minute(s), 59 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5832

    Windows 6.0.6001 Service Pack 1
    Internet Explorer 7.0.6001.18000

    2/21/2011 1:41:18 PM
    mbam-log-2011-02-21 (13-41-18).txt

    Scan type: Quick scan
    Objects scanned: 140056
    Time elapsed: 2 minute(s), 59 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    DDS (Ver_10-12-12.02) - NTFSx86 
    Run by Dale at 13:47:59.47 on Mon 02/21/2011
    Internet Explorer: 7.0.6001.18000
    Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.3069.1745 [GMT -7:00]

    AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
    SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: Online Armor Firewall *Enabled* {5841EF60-F43F-AE8D-642F-D79F12883626}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Online Armor\OAcat.exe
    C:\Program Files\Online Armor\oasrv.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe
    C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Online Armor\oaui.exe
    C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\MobileCenter.exe
    C:\Windows\ehome\ehtray.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\RocketTime.exe
    C:\Program Files\Online Armor\OAhlp.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\NOTEPAD.EXE
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\Dale\Downloads\dds.com
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uWindow Title = Internet Explorer provided by Dell
    uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080426
    mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080426
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: KeyScramblerBHO Class: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    TB: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [RocketAppCenter.exe] "c:\program files\rocket software\rocket mobile & security apps\MobileCenter.exe"
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
    mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
    mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
    mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
    mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
    mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
    mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
    mRun: [@OnlineArmor GUI] "c:\program files\online armor\oaui.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [WinPatrol] c:\program files\billp studios\winpatrol\WinPatrol.exe -expressboot
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\rocket~1.lnk - c:\program files\rocket software\rocket mobile & security apps\RocketTime.exe
    mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Search Image on TinEye - file://c:\users\dale\documents\tineye 1.0\TinEye.js
    IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll
    IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} - hxxp://ax.emsisoft.com/emsisoft_webscan.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: {73189B5E-92B3-46AC-BCFF-33C6B52CEFF2} = 208.67.222.222,208.67.220.220
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\online~1\oaevent.dll
    Hosts: 127.0.0.1 www.spywareinfo.com

    ============= SERVICES / DRIVERS ===============

    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-6-17 294608]
    R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2010-11-17 202064]
    R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [2010-11-17 38856]
    R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2010-11-17 25000]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
    R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2010-4-22 93872]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-3-16 176128]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-17 17744]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-6-17 51280]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-17 40384]
    R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [2009-11-27 34712]
    R2 OAcat;Online Armor Helper Service;c:\program files\online armor\oacat.exe [2010-11-17 380784]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-9-11 1153368]
    R2 sprtlisten;SupportSoft Listener Service;c:\program files\common files\supportsoft\bin\sprtlisten.exe [2008-1-8 1213728]
    R2 SvcOnlineArmor;Online Armor;c:\program files\online armor\oasrv.exe [2010-11-17 3652696]
    R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-10-27 6573568]
    R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-10-27 229888]
    R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2010-9-2 114952]
    R3 OAnet;OnlineArmor Service;c:\windows\system32\drivers\OAnet.sys [2010-11-17 29120]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

    =============== File Associations ===============

    txtfile=c:\windows\NOTEPAD.EXE %1

    =============== Created Last 30 ================

    2011-02-18 14:36:45 5890896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{56718300-7413-409f-a91b-82e42682e5c4}\mpengine.dll
    2011-02-17 19:50:38 388096 ----a-r- c:\users\dale\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
    2011-02-15 13:39:59 -------- d-----w- c:\progra~2\InstallMate
    2011-01-30 15:45:12 135568 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
    2011-01-26 11:59:32 -------- d-----w- c:\users\dale\appdata\roaming\Uniblue
    2011-01-26 11:59:15 -------- d-----w- c:\program files\Uniblue
    2011-01-26 11:58:37 -------- d-----w- c:\users\dale\appdata\local\PackageAware

    ==================== Find3M  ====================

    2011-01-08 07:50:00 34304 ----a-w- c:\windows\system32\atmlib.dll
    2011-01-08 05:57:10 292352 ----a-w- c:\windows\system32\atmfd.dll
    2010-12-31 20:06:36 38848 ----a-w- c:\windows\avastSS.scr
    2010-12-31 13:25:17 2038784 ----a-w- c:\windows\system32\win32k.sys
    2010-12-28 14:57:35 409600 ----a-w- c:\windows\system32\odbc32.dll
    2010-12-26 02:04:25 413696 ----a-w- c:\windows\system32\wrap_oal.dll
    2010-12-26 02:04:25 110592 ----a-w- c:\windows\system32\OpenAL32.dll
    2010-12-20 15:40:24 833024 ----a-w- c:\windows\system32\wininet.dll
    2010-12-20 15:37:57 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-12-20 14:12:59 389632 ----a-w- c:\windows\system32\html.iec
    2010-12-20 13:51:45 1383424 ----a-w- c:\windows\system32\mshtml.tlb
    2010-12-14 15:49:30 1169408 ----a-w- c:\windows\system32\sdclt.exe

    ============= FINISH: 13:52:11.96 ===============



    DDS (Ver_10-12-12.02) - NTFSx86 
    Run by Dale at 13:47:59.47 on Mon 02/21/2011
    Internet Explorer: 7.0.6001.18000
    Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.3069.1745 [GMT -7:00]

    AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
    SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: Online Armor Firewall *Enabled* {5841EF60-F43F-AE8D-642F-D79F12883626}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Online Armor\OAcat.exe
    C:\Program Files\Online Armor\oasrv.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe
    C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Online Armor\oaui.exe
    C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\MobileCenter.exe
    C:\Windows\ehome\ehtray.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\RocketTime.exe
    C:\Program Files\Online Armor\OAhlp.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\NOTEPAD.EXE
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\Dale\Downloads\dds.com
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uWindow Title = Internet Explorer provided by Dell
    uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080426
    mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080426
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: KeyScramblerBHO Class: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    TB: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [RocketAppCenter.exe] "c:\program files\rocket software\rocket mobile & security apps\MobileCenter.exe"
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
    mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
    mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
    mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
    mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
    mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
    mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
    mRun: [@OnlineArmor GUI] "c:\program files\online armor\oaui.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [WinPatrol] c:\program files\billp studios\winpatrol\WinPatrol.exe -expressboot
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\rocket~1.lnk - c:\program files\rocket software\rocket mobile & security apps\RocketTime.exe
    mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Search Image on TinEye - file://c:\users\dale\documents\tineye 1.0\TinEye.js
    IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll
    IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} - hxxp://ax.emsisoft.com/emsisoft_webscan.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: {73189B5E-92B3-46AC-BCFF-33C6B52CEFF2} = 208.67.222.222,208.67.220.220
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\online~1\oaevent.dll
    Hosts: 127.0.0.1 www.spywareinfo.com

    ============= SERVICES / DRIVERS ===============

    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-6-17 294608]
    R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2010-11-17 202064]
    R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [2010-11-17 38856]
    R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2010-11-17 25000]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
    R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2010-4-22 93872]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-3-16 176128]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-17 17744]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-6-17 51280]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-17 40384]
    R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [2009-11-27 34712]
    R2 OAcat;Online Armor Helper Service;c:\program files\online armor\oacat.exe [2010-11-17 380784]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-9-11 1153368]
    R2 sprtlisten;SupportSoft Listener Service;c:\program files\common files\supportsoft\bin\sprtlisten.exe [2008-1-8 1213728]
    R2 SvcOnlineArmor;Online Armor;c:\program files\online armor\oasrv.exe [2010-11-17 3652696]
    R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-10-27 6573568]
    R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-10-27 229888]
    R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2010-9-2 114952]
    R3 OAnet;OnlineArmor Service;c:\windows\system32\drivers\OAnet.sys [2010-11-17 29120]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

    =============== File Associations ===============

    txtfile=c:\windows\NOTEPAD.EXE %1

    =============== Created Last 30 ================

    2011-02-18 14:36:45 5890896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{56718300-7413-409f-a91b-82e42682e5c4}\mpengine.dll
    2011-02-17 19:50:38 388096 ----a-r- c:\users\dale\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
    2011-02-15 13:39:59 -------- d-----w- c:\progra~2\InstallMate
    2011-01-30 15:45:12 135568 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
    2011-01-26 11:59:32 -------- d-----w- c:\users\dale\appdata\roaming\Uniblue
    2011-01-26 11:59:15 -------- d-----w- c:\program files\Uniblue
    2011-01-26 11:58:37 -------- d-----w- c:\users\dale\appdata\local\PackageAware

    ==================== Find3M  ====================

    2011-01-08 07:50:00 34304 ----a-w- c:\windows\system32\atmlib.dll
    2011-01-08 05:57:10 292352 ----a-w- c:\windows\system32\atmfd.dll
    2010-12-31 20:06:36 38848 ----a-w- c:\windows\avastSS.scr
    2010-12-31 13:25:17 2038784 ----a-w- c:\windows\system32\win32k.sys
    2010-12-28 14:57:35 409600 ----a-w- c:\windows\system32\odbc32.dll
    2010-12-26 02:04:25 413696 ----a-w- c:\windows\system32\wrap_oal.dll
    2010-12-26 02:04:25 110592 ----a-w- c:\windows\system32\OpenAL32.dll
    2010-12-20 15:40:24 833024 ----a-w- c:\windows\system32\wininet.dll
    2010-12-20 15:37:57 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-12-20 14:12:59 389632 ----a-w- c:\windows\system32\html.iec
    2010-12-20 13:51:45 1383424 ----a-w- c:\windows\system32\mshtml.tlb
    2010-12-14 15:49:30 1169408 ----a-w- c:\windows\system32\sdclt.exe

    ============= FINISH: 13:52:11.96 ===============

     


    DDS (Ver_10-12-12.02) - NTFSx86 
    Run by Dale at 13:47:59.47 on Mon 02/21/2011
    Internet Explorer: 7.0.6001.18000
    Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.3069.1745 [GMT -7:00]

    AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
    SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: Online Armor Firewall *Enabled* {5841EF60-F43F-AE8D-642F-D79F12883626}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Online Armor\OAcat.exe
    C:\Program Files\Online Armor\oasrv.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe
    C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Online Armor\oaui.exe
    C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\MobileCenter.exe
    C:\Windows\ehome\ehtray.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\RocketTime.exe
    C:\Program Files\Online Armor\OAhlp.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\NOTEPAD.EXE
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\Dale\Downloads\dds.com
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uWindow Title = Internet Explorer provided by Dell
    uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080426
    mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080426
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: KeyScramblerBHO Class: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    TB: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [RocketAppCenter.exe] "c:\program files\rocket software\rocket mobile & security apps\MobileCenter.exe"
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
    mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
    mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
    mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
    mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
    mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
    mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
    mRun: [@OnlineArmor GUI] "c:\program files\online armor\oaui.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [WinPatrol] c:\program files\billp studios\winpatrol\WinPatrol.exe -expressboot
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\rocket~1.lnk - c:\program files\rocket software\rocket mobile & security apps\RocketTime.exe
    mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Search Image on TinEye - file://c:\users\dale\documents\tineye 1.0\TinEye.js
    IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll
    IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} - hxxp://ax.emsisoft.com/emsisoft_webscan.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: {73189B5E-92B3-46AC-BCFF-33C6B52CEFF2} = 208.67.222.222,208.67.220.220
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\online~1\oaevent.dll
    Hosts: 127.0.0.1 www.spywareinfo.com

    ============= SERVICES / DRIVERS ===============

    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-6-17 294608]
    R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2010-11-17 202064]
    R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [2010-11-17 38856]
    R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2010-11-17 25000]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
    R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2010-4-22 93872]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-3-16 176128]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-17 17744]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-6-17 51280]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-17 40384]
    R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [2009-11-27 34712]
    R2 OAcat;Online Armor Helper Service;c:\program files\online armor\oacat.exe [2010-11-17 380784]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-9-11 1153368]
    R2 sprtlisten;SupportSoft Listener Service;c:\program files\common files\supportsoft\bin\sprtlisten.exe [2008-1-8 1213728]
    R2 SvcOnlineArmor;Online Armor;c:\program files\online armor\oasrv.exe [2010-11-17 3652696]
    R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-10-27 6573568]
    R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-10-27 229888]
    R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2010-9-2 114952]
    R3 OAnet;OnlineArmor Service;c:\windows\system32\drivers\OAnet.sys [2010-11-17 29120]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

    =============== File Associations ===============

    txtfile=c:\windows\NOTEPAD.EXE %1

    =============== Created Last 30 ================

    2011-02-18 14:36:45 5890896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{56718300-7413-409f-a91b-82e42682e5c4}\mpengine.dll
    2011-02-17 19:50:38 388096 ----a-r- c:\users\dale\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
    2011-02-15 13:39:59 -------- d-----w- c:\progra~2\InstallMate
    2011-01-30 15:45:12 135568 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
    2011-01-26 11:59:32 -------- d-----w- c:\users\dale\appdata\roaming\Uniblue
    2011-01-26 11:59:15 -------- d-----w- c:\program files\Uniblue
    2011-01-26 11:58:37 -------- d-----w- c:\users\dale\appdata\local\PackageAware

    ==================== Find3M  ====================

    2011-01-08 07:50:00 34304 ----a-w- c:\windows\system32\atmlib.dll
    2011-01-08 05:57:10 292352 ----a-w- c:\windows\system32\atmfd.dll
    2010-12-31 20:06:36 38848 ----a-w- c:\windows\avastSS.scr
    2010-12-31 13:25:17 2038784 ----a-w- c:\windows\system32\win32k.sys
    2010-12-28 14:57:35 409600 ----a-w- c:\windows\system32\odbc32.dll
    2010-12-26 02:04:25 413696 ----a-w- c:\windows\system32\wrap_oal.dll
    2010-12-26 02:04:25 110592 ----a-w- c:\windows\system32\OpenAL32.dll
    2010-12-20 15:40:24 833024 ----a-w- c:\windows\system32\wininet.dll
    2010-12-20 15:37:57 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-12-20 14:12:59 389632 ----a-w- c:\windows\system32\html.iec
    2010-12-20 13:51:45 1383424 ----a-w- c:\windows\system32\mshtml.tlb
    2010-12-14 15:49:30 1169408 ----a-w- c:\windows\system32\sdclt.exe

    ============= FINISH: 13:52:11.96 ===============


    DDS (Ver_10-12-12.02) - NTFSx86 
    Run by Dale at 13:47:59.47 on Mon 02/21/2011
    Internet Explorer: 7.0.6001.18000
    Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.3069.1745 [GMT -7:00]

    AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
    SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: Online Armor Firewall *Enabled* {5841EF60-F43F-AE8D-642F-D79F12883626}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Online Armor\OAcat.exe
    C:\Program Files\Online Armor\oasrv.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe
    C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Online Armor\oaui.exe
    C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\MobileCenter.exe
    C:\Windows\ehome\ehtray.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\RocketTime.exe
    C:\Program Files\Online Armor\OAhlp.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\NOTEPAD.EXE
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\Dale\Downloads\dds.com
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uWindow Title = Internet Explorer provided by Dell
    uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080426
    mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080426
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: KeyScramblerBHO Class: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    TB: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [RocketAppCenter.exe] "c:\program files\rocket software\rocket mobile & security apps\MobileCenter.exe"
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
    mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
    mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
    mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
    mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
    mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
    mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
    mRun: [@OnlineArmor GUI] "c:\program files\online armor\oaui.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [WinPatrol] c:\program files\billp studios\winpatrol\WinPatrol.exe -expressboot
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\rocket~1.lnk - c:\program files\rocket software\rocket mobile & security apps\RocketTime.exe
    mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Search Image on TinEye - file://c:\users\dale\documents\tineye 1.0\TinEye.js
    IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll
    IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} - hxxp://ax.emsisoft.com/emsisoft_webscan.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: {73189B5E-92B3-46AC-BCFF-33C6B52CEFF2} = 208.67.222.222,208.67.220.220
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\online~1\oaevent.dll
    Hosts: 127.0.0.1 www.spywareinfo.com

    ============= SERVICES / DRIVERS ===============

    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-6-17 294608]
    R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2010-11-17 202064]
    R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [2010-11-17 38856]
    R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2010-11-17 25000]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
    R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2010-4-22 93872]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-3-16 176128]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-17 17744]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-6-17 51280]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-17 40384]
    R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [2009-11-27 34712]
    R2 OAcat;Online Armor Helper Service;c:\program files\online armor\oacat.exe [2010-11-17 380784]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-9-11 1153368]
    R2 sprtlisten;SupportSoft Listener Service;c:\program files\common files\supportsoft\bin\sprtlisten.exe [2008-1-8 1213728]
    R2 SvcOnlineArmor;Online Armor;c:\program files\online armor\oasrv.exe [2010-11-17 3652696]
    R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-10-27 6573568]
    R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-10-27 229888]
    R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2010-9-2 114952]
    R3 OAnet;OnlineArmor Service;c:\windows\system32\drivers\OAnet.sys [2010-11-17 29120]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

    =============== File Associations ===============

    txtfile=c:\windows\NOTEPAD.EXE %1

    =============== Created Last 30 ================

    2011-02-18 14:36:45 5890896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{56718300-7413-409f-a91b-82e42682e5c4}\mpengine.dll
    2011-02-17 19:50:38 388096 ----a-r- c:\users\dale\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
    2011-02-15 13:39:59 -------- d-----w- c:\progra~2\InstallMate
    2011-01-30 15:45:12 135568 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
    2011-01-26 11:59:32 -------- d-----w- c:\users\dale\appdata\roaming\Uniblue
    2011-01-26 11:59:15 -------- d-----w- c:\program files\Uniblue
    2011-01-26 11:58:37 -------- d-----w- c:\users\dale\appdata\local\PackageAware

    ==================== Find3M  ====================

    2011-01-08 07:50:00 34304 ----a-w- c:\windows\system32\atmlib.dll
    2011-01-08 05:57:10 292352 ----a-w- c:\windows\system32\atmfd.dll
    2010-12-31 20:06:36 38848 ----a-w- c:\windows\avastSS.scr
    2010-12-31 13:25:17 2038784 ----a-w- c:\windows\system32\win32k.sys
    2010-12-28 14:57:35 409600 ----a-w- c:\windows\system32\odbc32.dll
    2010-12-26 02:04:25 413696 ----a-w- c:\windows\system32\wrap_oal.dll
    2010-12-26 02:04:25 110592 ----a-w- c:\windows\system32\OpenAL32.dll
    2010-12-20 15:40:24 833024 ----a-w- c:\windows\system32\wininet.dll
    2010-12-20 15:37:57 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-12-20 14:12:59 389632 ----a-w- c:\windows\system32\html.iec
    2010-12-20 13:51:45 1383424 ----a-w- c:\windows\system32\mshtml.tlb
    2010-12-14 15:49:30 1169408 ----a-w- c:\windows\system32\sdclt.exe

    ============= FINISH: 13:52:11.96 ===============



    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-12-12.02)

    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume3
    Install Date: 4/25/2008 7:55:50 PM
    System Uptime: 2/21/2011 11:29:43 AM (2 hours ago)

    Motherboard: Dell Inc. |  | 0TP406
    Processor: Intel(R) Core(TM)2 Quad CPU    Q6600  @ 2.40GHz | CPU | 2394/1066mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 283 GiB total, 193.719 GiB free.
    D: is FIXED (NTFS) - 15 GiB total, 10.952 GiB free.
    E: is CDROM (CDFS)
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP942: 1/25/2011 5:44:10 AM - Windows Update
    RP943: 1/28/2011 5:24:58 AM - Windows Update
    RP944: 1/29/2011 8:12:48 AM - Scheduled Checkpoint
    RP945: 1/31/2011 6:30:04 PM - Scheduled Checkpoint
    RP946: 2/1/2011 5:01:53 AM - Windows Update
    RP947: 2/1/2011 5:05:26 AM - Windows Update
    RP948: 2/1/2011 5:10:03 AM - Windows Update
    RP949: 2/3/2011 6:33:21 AM - Installed Adobe Reader X.
    RP950: 2/4/2011 7:54:38 AM - Windows Update
    RP951: 2/5/2011 4:54:05 PM - Scheduled Checkpoint
    RP952: 2/6/2011 7:30:07 AM - Scheduled Checkpoint
    RP953: 2/7/2011 8:03:54 PM - Scheduled Checkpoint
    RP954: 2/8/2011 6:07:48 AM - Windows Update
    RP955: 2/8/2011 6:10:14 AM - Windows Update
    RP956: 2/8/2011 6:47:34 AM - Windows Update
    RP957: 2/9/2011 5:42:57 AM - Windows Update
    RP958: 2/10/2011 7:49:01 PM - Scheduled Checkpoint
    RP959: 2/11/2011 5:56:21 AM - Windows Update
    RP960: 2/12/2011 1:42:20 PM - Scheduled Checkpoint
    RP961: 2/15/2011 5:50:42 AM - Windows Update
    RP962: 2/15/2011 5:54:15 AM - Windows Update
    RP963: 2/15/2011 5:57:05 AM - Windows Update
    RP964: 2/17/2011 12:50:04 PM - Installed HiJackThis
    RP965: 2/18/2011 7:35:25 AM - Windows Update
    RP966: 2/20/2011 4:15:35 PM - Scheduled Checkpoint
    RP967: 2/21/2011 12:24:09 PM - Scheduled Checkpoint

    ==== Installed Programs ======================

    7-Zip 9.15 beta
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Reader X (10.0.1)
    avast! Free Antivirus
    Belarc Advisor 7.2
    Browser Address Error Redirector
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center Localization Chinese Standard
    Catalyst Control Center Localization Chinese Traditional
    Catalyst Control Center Localization French
    Catalyst Control Center Localization German
    Catalyst Control Center Localization Hungarian
    Catalyst Control Center Localization Italian
    Catalyst Control Center Localization Japanese
    Catalyst Control Center Localization Korean
    Catalyst Control Center Localization Polish
    Catalyst Control Center Localization Portuguese
    Catalyst Control Center Localization Spanish
    Catalyst Control Center Localization Thai
    Catalyst Control Center Localization Turkish
    ccc-core-static
    ccc-utility
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help English
    CCC Help French
    CCC Help German
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Spanish
    CCC Help Thai
    CCC Help Turkish
    CCleaner
    Celestia 1.6.0
    Compatibility Pack for the 2007 Office system
    Conexant D850 PCI V.92 Modem
    Dell Getting Started Guide
    Dell Support Center
    Digital Line Detect
    DIGOpt
    DiskCheckup V3.0
    FLV Player 2.0 (build 25)
    Free RAR Extract Frog
    HiJackThis
    HijackThis 2.0.2
    Hitman Pro 3.5
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Intel(R) Matrix Storage Manager
    Intel(R) PRO Network Connections 12.1.12.4
    Junk Mail filter update
    KeyScrambler
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Digital Image Library 9 - Blocker
    Microsoft Encarta Encyclopedia Standard 2005
    Microsoft Money 2005
    Microsoft Office Live Add-in 1.5
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Picture It! Library 10
    Microsoft Picture It! Premium 10
    Microsoft Silverlight
    Microsoft Streets and Trips 2005
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Word 2002
    Microsoft Works
    Microsoft Works 2005 Setup Launcher
    Microsoft Works Suite Add-in for Microsoft Word
    Modem Diagnostic Tool
    MSN
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Music, Photos & Videos Launcher
    NetWaiting
    OGA Notifier 2.0.0048.0
    Online Armor 4.5
    OpenAL
    Product Documentation Launcher
    Quicken 2002 New User Edition
    Qwest Installer
    Qwest QuickAssist Desktop Tools
    RealPlayer
    Rocket.Time
    Roxio Creator Audio
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator DE
    Roxio Creator Tools
    Roxio Express Labeler 3
    Roxio Update Manager
    runtime
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Shockwave
    Skins
    Speccy
    Spybot - Search & Destroy
    SpywareBlaster 4.4
    SUPERAntiSpyware
    TinEye Internet Explorer plugin 1.0
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    User's Guides
    VideoLAN VLC media player 0.8.6h
    WIDCOMM Bluetooth Software 6.0.1.4300
    Windows 7 Upgrade Advisor
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Mail
    Windows Live Messenger
    Windows Live Upload Tool
    WinPatrol
    WinRAR archiver
    Works Upgrade
    XPS MiniView Gadget

    ==== Event Viewer Messages From Past Week ========

    2/21/2011 10:23:17 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
    2/20/2011 6:15:19 AM, Error: Service Control Manager [7000]  - The Windows Media Player Network Sharing Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
    2/20/2011 6:15:18 AM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Windows Media Player Network Sharing Service service to connect.
    2/20/2011 6:14:18 AM, Error: Service Control Manager [7001]  - The Workstation service depends on the SMB 2.0 MiniRedirector service which failed to start because of the following error:  Access is denied.
    2/20/2011 6:14:18 AM, Error: Service Control Manager [7001]  - The srv service depends on the srv2 service which failed to start because of the following error:  Access is denied.
    2/20/2011 6:14:18 AM, Error: Service Control Manager [7000]  - The srv2 service failed to start due to the following error:  Access is denied.
    2/20/2011 6:14:18 AM, Error: Service Control Manager [7000]  - The SMB 2.0 MiniRedirector service failed to start due to the following error:  Access is denied.
    2/20/2011 6:14:18 AM, Error: Service Control Manager [7000]  - The SMB 1.x MiniRedirector service failed to start due to the following error:  Access is denied.
    2/20/2011 11:14:42 AM, Error: Service Control Manager [7001]  - The Server service depends on the srv service which failed to start because of the following error:  Access is denied.
    2/20/2011 11:14:42 AM, Error: Service Control Manager [7001]  - The Computer Browser service depends on the Server service which failed to start because of the following error:  The dependency service or group failed to start.
    2/20/2011 11:14:42 AM, Error: Service Control Manager [7000]  - The srv service failed to start due to the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The Workstation service depends on the bowser service which failed to start because of the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The UPnP Device Host service depends on the HTTP service which failed to start because of the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The SSDP Discovery service depends on the HTTP service which failed to start because of the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The srv2 service depends on the srvnet service which failed to start because of the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The srv service depends on the srv2 service which failed to start because of the following error:  The dependency service or group failed to start.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The Server service depends on the srv service which failed to start because of the following error:  The dependency service or group failed to start.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The Print Spooler service depends on the HTTP service which failed to start because of the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The Function Discovery Resource Publication service depends on the HTTP service which failed to start because of the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7001]  - The Computer Browser service depends on the Workstation service which failed to start because of the following error:  The dependency service or group failed to start.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7000]  - The WebDav Client Redirector Driver service failed to start due to the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7000]  - The SupportSoft Listener Service service failed to start due to the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7000]  - The srvnet service failed to start due to the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7000]  - The SMB MiniRedirector Wrapper and Engine service failed to start due to the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7000]  - The mrtRate service failed to start due to the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7000]  - The HTTP service failed to start due to the following error:  Access is denied.
    2/19/2011 7:29:29 AM, Error: Service Control Manager [7000]  - The bowser service failed to start due to the following error:  Access is denied.
    2/17/2011 4:57:17 AM, Error: Service Control Manager [7022]  - The Online Armor service hung on starting.
    2/17/2011 12:38:43 PM, Error: EventLog [6008]  - The previous system shutdown at 12:36:02 PM on 2/17/2011 was unexpected.
    2/17/2011 12:34:56 PM, Error: Microsoft-Windows-DistributedCOM [10000]  - Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}. The error: "0" Happened while starting this command: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
    2/17/2011 10:26:21 PM, Error: EventLog [6008]  - The previous system shutdown at 10:22:52 PM on 2/17/2011 was unexpected.
    2/17/2011 10:21:51 PM, Error: Service Control Manager [7000]  - The Windows Modules Installer service failed to start due to the following error:  Access is denied.
    2/17/2011 10:21:51 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "5" attempting to start the service TrustedInstaller with arguments "" in order to run the server: {752073A1-23F2-4396-85F0-8FDB879ED0ED}
    2/17/2011 10:21:24 PM, Error: Service Control Manager [7043]  - The Windows Update service did not shut down properly after receiving a preshutdown control.
    2/15/2011 5:53:17 AM, Error: Microsoft-Windows-WindowsUpdateClient [20]  - Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Windows Defender - KB915597 (Definition 1.97.1752.0).
    2/15/2011 11:13:23 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Eventlog service.
    2/14/2011 5:18:35 AM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the SBSD Security Center Service service to connect.
    2/14/2011 5:18:35 AM, Error: Service Control Manager [7000]  - The SBSD Security Center Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
    2/14/2011 5:18:14 AM, Error: Service Control Manager [7000]  - The FileInfo service failed to start due to the following error:  The system cannot find the file specified.

    ==== End Of File ===========================

  • kevin27_b3d29f

    2 Intern

    •

    1547 Posts

    797

    0

    Posted February 21st, 2011 13:00

    No worries, Thank You for letting me know.

  • dalem29

    2 Intern

    •

    2198 Posts

    797

    0

    Posted February 21st, 2011 13:00

    Not sure why I am ending up with multiple posting of these files. Tried to delete some of them, but hopefully you have enough to work with. :emotion-10:

  • kevin27_b3d29f

    2 Intern

    •

    1547 Posts

    797

    0

    Posted February 22nd, 2011 13:00

    Hi,

    The logs are clean but there is an awful lot of security on the system that does not need to be there. I suspect that it is all this security that is hindering the install of SP2..

     

    Please uninstall the following programs via add/remove programs and then reboot the system. With only Avast installed you should notice a dramatic difference in the boot up time.


    DiskCheckup V3.0
    HijackThis 2.0.2
    Hitman Pro 3.5
    KeyScrambler
    Online Armor 4.5
    Spybot - Search & Destroy
    SpywareBlaster 4.4
    SUPERAntiSpyware
    WinPatrol

     

     

    Then please disable Avast by right clicking it taskbar icon > Hover over the "Avast Shield Control" > and select Disable Permanently > answer Yes to the prompt asking for confirmation to allow the shut off of Avast.

     

     

    Go here to run an online scannner from ESET.

    • Note: You will need to use Internet explorer for this scan
    • Turn off the real time scanner of any existing antivirus program while performing the online scan
    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the activex control to install
    • Click Start
    • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
    • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
    • Click Scan
    • Wait for the scan to finish
    • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
    • Copy and paste that log as a reply to this topic and also let me know how things are now.

     

    Please post the ESET report back for review.

    Thanks.

  • dalem29

    2 Intern

    •

    2198 Posts

    797

    0

    Posted February 22nd, 2011 16:00

    Yeah...I probably have way too much stuff on there, in keeping with the layered security approach, but before I run the scan tomorrow, I have a few questions.  Unsure about what to do with Online Armor, since that is my firewall. Do you want me to turn it off and then turn on the Windows Firewall instead, during the course of the scan? And can I safely turn off  the Avast shields during the ESET scan?

    I will go ahead and get rid of HJT and Disk Checkup since I only use them on rare occasions. Use Hitman Pro to scan once a week or so. Not sure how much good Spybot Search and Destroy and Spyware Blaster are, probably could do without, nor am I sure how useful Super Anti Spyware is. That  would still leave MBAM as my main scanner and fixer upper. Also, I would like to keep my Key Scrambler and Win Patrol after we are done, not sure how many resources they consume.

  • kevin27_b3d29f

    2 Intern

    •

    1547 Posts

    797

    0

    Posted February 23rd, 2011 13:00

    Hi,

    Once we are finished, you can reinstall some of the programs that your are about to uninstall. Spybot and Spyware blaster fundamentally do the same thing. WinPatrol will stop alot of our tools from working correctly, Once OA is uninstalled, you will need to activate the Windows firewall if it is not done so automatically. SAS is not really needed on the system if you have MBAM.

    It is perfectly safe to disable Avast while running the ESET scan,.

    Just for now I would like to see what is doing what on the system and that is going to mean removing everything and then installing things one at a time until we find what is conflicting with what to make the boot up take as long as it does. Plus, it will make installing SP2 and IE8 a lot easier if all that security is not on board.

    Thanks.

  • dalem29

    2 Intern

    •

    2198 Posts

    794

    0

    Posted February 23rd, 2011 15:00

    I have looked in the usual places trying to track down the log, which in Vista can be a chore, but the scan came up clean and no threats were found. It takes a bit of time on the "black" spash screen and the one with the progress bar scrolling, but almost immediately goes to the desktop and loads from there fairly quickly. Much improved. Installed Outpost Firewall, since Online Armor has lately been trying to imitate Comodo by tossing out too many alert pop ups for me to "Allow". Will keep Spybot S&D for its host file and install Win Patrol again so Scotty can "guard the gate", so to speak. Yeah, I had too much security stuff on there

  • kevin27_b3d29f

    2 Intern

    •

    1547 Posts

    794

    0

    Posted February 25th, 2011 10:00

    Hi,

    We are no where near compleation yet. Please do not start reinstalling any programs just yet. We need to deal with other things first.

    Please leave only Avast, the Windows Firewall and Windows Defender installed. All the rest we will get to later.

    The ESET log will be located at C:\Program Files\Eset\Eset Online Scanner\log.txt

    Please post the ESET log and a fresh set of DDS logs.

    Thanks.

  • dalem29

    2 Intern

    •

    2198 Posts

    327

    0

    Posted February 25th, 2011 13:00

    After a lengthy search I found this log of sorts on the C Drive>ProgamFiles. Hope it is what we need. Once I post it I will run the other scan and post those logs. Not sure what the problem is with the ESET and DDS logs font size. When I open the post to edit it, they look to be of the proper size, which appears to be a number 3. If need be I can kick it up a notch.

    ESETSmartInstaller@High as CAB hook log:

    OnlineScanner.ocx - registred OK

    # version=7

    # iexplore.exe=7.00.6000.16386 (vista_rtm.061101-2205)

    # OnlineScanner.ocx=1.0.0.6425

    # api_version=3.0.2

    # EOSSerial=05e974c773bcfd47826598518229f455

    # end=finished

    # remove_checked=false

    # archives_checked=true

    # unwanted_checked=true

    # unsafe_checked=true

    # antistealth_checked=true

    # utc_time=2011-02-23 10:58:34

    # local_time=2011-02-23 03:58:34 (-0700, Mountain Standard Time)

    # country="United States"

    # lang=1033

    # osver=6.0.6001 NT Service Pack 1

    # compatibility_mode=768 16777215 100 0 20757330 20757330 0 0

    # compatibility_mode=5892 16776573 100 100 14473 135106793 0 0

    # compatibility_mode=8192 67108863 100 0 0 0 0 0

    # scanned=126715

    # found=0

    # cleaned=0

    # scan_time=2669

     


    DDS (Ver_10-12-12.02) - NTFSx86 
    Run by Dale at 15:00:56.37 on Fri 02/25/2011
    Internet Explorer: 7.0.6002.18005
    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3069.1852 [GMT -7:00]

    AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\spoolsv.exe
    C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\MobileCenter.exe
    C:\Windows\ehome\ehtray.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Rocket Software\Rocket Mobile & Security Apps\RocketTime.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
    C:\Windows\system32\STacSV.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\prevhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Users\Dale\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YRXEUYXT\dds[1].scr

    ============== Pseudo HJT Report ===============

    uWindow Title = Internet Explorer provided by Dell
    uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080426
    mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3080426
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: KeyScramblerBHO Class: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
    BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
    TB: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - No File
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [RocketAppCenter.exe] "c:\program files\rocket software\rocket mobile & security apps\MobileCenter.exe"
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
    mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
    mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
    mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
    mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
    mRun: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\rocket~1.lnk - c:\program files\rocket software\rocket mobile & security apps\RocketTime.exe
    mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Search Image on TinEye - file://c:\users\dale\documents\tineye 1.0\TinEye.js
    IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll
    IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} - hxxp://ax.emsisoft.com/emsisoft_webscan.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: {73189B5E-92B3-46AC-BCFF-33C6B52CEFF2} = 208.67.222.222,208.67.220.220
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    SEH: {4F07DA45-8170-4859-9B5F-037EF2970034} - No File
    Hosts: 127.0.0.1 www.spywareinfo.com

    ============= SERVICES / DRIVERS ===============

    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-2-23 371544]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-6-17 301528]
    R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2010-4-22 93872]
    R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-3-16 176128]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-17 19544]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-6-17 53592]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-17 42184]
    R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
    R2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [2009-11-27 34712]
    R2 sprtlisten;SupportSoft Listener Service;c:\program files\common files\supportsoft\bin\sprtlisten.exe [2008-1-8 1213728]
    R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-10-27 6573568]
    R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-10-27 229888]
    R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2010-9-2 114952]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

    =============== File Associations ===============

    txtfile=c:\windows\NOTEPAD.EXE %1

    =============== Created Last 30 ================

    2011-02-25 11:53:48 -------- d-----w- c:\program files\Windows Portable Devices
    2011-02-25 11:50:57 2537472 ----a-w- c:\windows\system32\wpdshext.dll
    2011-02-25 11:50:56 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
    2011-02-25 11:50:56 546816 ----a-w- c:\windows\system32\wpd_ci.dll
    2011-02-25 11:50:56 350208 ----a-w- c:\windows\system32\WPDSp.dll
    2011-02-25 11:50:56 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
    2011-02-25 11:50:56 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
    2011-02-25 11:50:56 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
    2011-02-25 11:50:56 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
    2011-02-25 11:49:46 4096 ----a-w- c:\windows\system32\oleaccrc.dll
    2011-02-25 11:49:45 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
    2011-02-25 11:49:45 234496 ----a-w- c:\windows\system32\oleacc.dll
    2011-02-25 11:38:00 797184 ----a-w- c:\windows\system32\FntCache.dll
    2011-02-25 11:38:00 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
    2011-02-25 11:38:00 1068544 ----a-w- c:\windows\system32\DWrite.dll
    2011-02-25 11:11:17 231424 ----a-w- c:\windows\system32\msshsq.dll
    2011-02-24 15:31:43 -------- d-----w- c:\windows\system32\vi-VN
    2011-02-24 15:31:43 -------- d-----w- c:\windows\system32\eu-ES
    2011-02-24 15:31:43 -------- d-----w- c:\windows\system32\ca-ES
    2011-02-24 00:28:52 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-02-24 00:08:14 -------- d-----w- c:\progra~2\Agnitum
    2011-02-23 22:08:32 -------- d-----w- c:\program files\ESET
    2011-02-22 19:13:12 5890896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{18c48e80-339d-42c7-a6c1-9a6bb329bb7e}\mpengine.dll
    2011-02-15 13:39:59 -------- d-----w- c:\progra~2\InstallMate
    2011-01-30 15:45:12 135568 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll

    ==================== Find3M  ====================

    2011-02-23 15:04:21 40648 ----a-w- c:\windows\avastSS.scr
    2011-01-20 16:08:16 478720 ----a-w- c:\windows\system32\dxgi.dll
    2011-01-20 16:08:06 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
    2011-01-20 16:08:06 189952 ----a-w- c:\windows\system32\d3d10core.dll
    2011-01-20 16:08:06 160768 ----a-w- c:\windows\system32\d3d10_1.dll
    2011-01-20 16:08:06 1029120 ----a-w- c:\windows\system32\d3d10.dll
    2011-01-20 16:07:58 37376 ----a-w- c:\windows\system32\cdd.dll
    2011-01-20 16:07:42 258048 ----a-w- c:\windows\system32\winspool.drv
    2011-01-20 16:07:16 586240 ----a-w- c:\windows\system32\stobject.dll
    2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf.dll
    2011-01-20 16:06:35 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
    2011-01-20 16:04:54 98816 ----a-w- c:\windows\system32\mfps.dll
    2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat.dll
    2011-01-20 14:28:38 1554432 ----a-w- c:\windows\system32\xpsservices.dll
    2011-01-20 14:27:50 876032 ----a-w- c:\windows\system32\XpsPrint.dll
    2011-01-20 14:26:30 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
    2011-01-20 14:25:25 847360 ----a-w- c:\windows\system32\OpcServices.dll
    2011-01-20 14:24:32 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
    2011-01-20 14:24:26 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
    2011-01-20 14:15:10 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
    2011-01-20 14:14:39 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
    2011-01-20 14:14:03 302592 ----a-w- c:\windows\system32\mfmp4src.dll
    2011-01-20 14:14:03 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
    2011-01-20 14:11:34 486400 ----a-w- c:\windows\system32\d3d10level9.dll
    2011-01-20 13:47:51 683008 ----a-w- c:\windows\system32\d2d1.dll
    2011-01-08 08:47:50 34304 ----a-w- c:\windows\system32\atmlib.dll
    2011-01-08 06:28:49 292352 ----a-w- c:\windows\system32\atmfd.dll
    2010-12-31 13:57:01 2039808 ----a-w- c:\windows\system32\win32k.sys
    2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32.dll
    2010-12-26 02:04:25 413696 ----a-w- c:\windows\system32\wrap_oal.dll
    2010-12-26 02:04:25 110592 ----a-w- c:\windows\system32\OpenAL32.dll
    2010-12-20 16:36:20 834048 ----a-w- c:\windows\system32\wininet.dll
    2010-12-20 15:37:57 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-12-20 14:55:46 389632 ----a-w- c:\windows\system32\html.iec
    2010-12-14 14:49:23 1169408 ----a-w- c:\windows\system32\sdclt.exe

    ============= FINISH: 15:01:27.84 ===============

     


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-12-12.02)

    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume3
    Install Date: 4/25/2008 7:55:50 PM
    System Uptime: 2/25/2011 2:16:54 PM (1 hours ago)

    Motherboard: Dell Inc. |  | 0TP406
    Processor: Intel(R) Core(TM)2 Quad CPU    Q6600  @ 2.40GHz | CPU | 2394/1066mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 283 GiB total, 227.447 GiB free.
    D: is FIXED (NTFS) - 15 GiB total, 10.952 GiB free.
    E: is CDROM (CDFS)
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================


    ==== Installed Programs ======================

    7-Zip 9.15 beta
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Reader X (10.0.1)
    avast! Free Antivirus
    Belarc Advisor 7.2
    Browser Address Error Redirector
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center Localization Chinese Standard
    Catalyst Control Center Localization Chinese Traditional
    Catalyst Control Center Localization French
    Catalyst Control Center Localization German
    Catalyst Control Center Localization Hungarian
    Catalyst Control Center Localization Italian
    Catalyst Control Center Localization Japanese
    Catalyst Control Center Localization Korean
    Catalyst Control Center Localization Polish
    Catalyst Control Center Localization Portuguese
    Catalyst Control Center Localization Spanish
    Catalyst Control Center Localization Thai
    Catalyst Control Center Localization Turkish
    ccc-core-static
    ccc-utility
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help English
    CCC Help French
    CCC Help German
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Spanish
    CCC Help Thai
    CCC Help Turkish
    CCleaner
    Celestia 1.6.0
    Compatibility Pack for the 2007 Office system
    Conexant D850 PCI V.92 Modem
    Dell Getting Started Guide
    Dell Support Center
    Digital Line Detect
    DIGOpt
    ESET Online Scanner v3
    FLV Player 2.0 (build 25)
    Free RAR Extract Frog
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Intel(R) Matrix Storage Manager
    Intel(R) PRO Network Connections 12.1.12.4
    Junk Mail filter update
    KeyScrambler
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Digital Image Library 9 - Blocker
    Microsoft Encarta Encyclopedia Standard 2005
    Microsoft Money 2005
    Microsoft Office Live Add-in 1.5
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Picture It! Library 10
    Microsoft Picture It! Premium 10
    Microsoft Silverlight
    Microsoft Streets and Trips 2005
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Word 2002
    Microsoft Works
    Microsoft Works 2005 Setup Launcher
    Microsoft Works Suite Add-in for Microsoft Word
    Modem Diagnostic Tool
    MSN
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Music, Photos & Videos Launcher
    NetWaiting
    OGA Notifier 2.0.0048.0
    OpenAL
    Product Documentation Launcher
    Quicken 2002 New User Edition
    Qwest Installer
    Qwest QuickAssist Desktop Tools
    RealPlayer
    Rocket.Time
    Roxio Creator Audio
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator DE
    Roxio Creator Tools
    Roxio Express Labeler 3
    Roxio Update Manager
    runtime
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Shockwave
    Skins
    Speccy
    TinEye Internet Explorer plugin 1.0
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    User's Guides
    VideoLAN VLC media player 0.8.6h
    WIDCOMM Bluetooth Software 6.0.1.4300
    Windows 7 Upgrade Advisor
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Mail
    Windows Live Messenger
    Windows Live Upload Tool
    WinRAR archiver
    Works Upgrade
    XPS MiniView Gadget

    ==== End Of File ===========================