WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Are we ok now? Should i restart my pc?
Im not even sure what kind of mess my computer was in....im assuming i had a or several viruses?
I certainly do appreciate all the time and help you've given me.
Thank you
Jenn

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Hello.


  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.
  • Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK.

    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

  • If it says "Hidden service detected" DO NOT type anything in. Just press Enter on your keyboard to not do anything to the file.
  • When it is done, a log file should be created on your C: drive called "TDSSKiller.txt" please copy and paste the contents of that file here.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My pc is very sick!! - Page 1 DXwU4
My pc is very sick!! - Page 1 VvYDg

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
This is the log file.

3:29:03:437 0984 TDSS rootkit removing tool 2.2.7.1 Feb 27 2010 13:29:25
13:29:03:437 0984 ================================================================================
13:29:03:437 0984 SystemInfo:

13:29:03:437 0984 OS Version: 5.1.2600 ServicePack: 3.0
13:29:03:437 0984 Product type: Workstation
13:29:03:437 0984 ComputerName: MYGIRLS
13:29:03:437 0984 UserName: jenn
13:29:03:437 0984 Windows directory: C:\WINDOWS
13:29:03:437 0984 Processor architecture: Intel x86
13:29:03:437 0984 Number of processors: 1
13:29:03:437 0984 Page size: 0x1000
13:29:03:437 0984 Boot type: Normal boot
13:29:03:437 0984 ================================================================================
13:29:03:437 0984 UnloadDriverW: NtUnloadDriver error 2
13:29:03:437 0984 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
13:29:03:500 0984 Initialize success
13:29:03:500 0984
13:29:03:500 0984 Scanning Services ...
13:29:03:500 0984 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
13:29:03:500 0984 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
13:29:03:500 0984 wfopen_ex: Trying to KLMD file open
13:29:03:500 0984 wfopen_ex: File opened ok (Flags 2)
13:29:03:500 0984 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
13:29:03:500 0984 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
13:29:03:500 0984 wfopen_ex: Trying to KLMD file open
13:29:03:500 0984 wfopen_ex: File opened ok (Flags 2)
13:29:03:937 0984 GetAdvancedServicesInfo: Raw services enum returned 382 services
13:29:03:937 0984 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
13:29:03:937 0984 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
13:29:03:937 0984
13:29:03:937 0984 Scanning Kernel memory ...
13:29:03:937 0984 Devices to scan: 4
13:29:03:937 0984
13:29:03:937 0984 Driver Name: Disk
13:29:03:937 0984 IRP_MJ_CREATE : F76F5BB0
13:29:03:937 0984 IRP_MJ_CREATE_NAMED_PIPE : 804F9739
13:29:03:937 0984 IRP_MJ_CLOSE : F76F5BB0
13:29:03:937 0984 IRP_MJ_READ : F76EFD1F
13:29:03:937 0984 IRP_MJ_WRITE : F76EFD1F
13:29:03:937 0984 IRP_MJ_QUERY_INFORMATION : 804F9739
13:29:03:937 0984 IRP_MJ_SET_INFORMATION : 804F9739
13:29:03:937 0984 IRP_MJ_QUERY_EA : 804F9739
13:29:03:937 0984 IRP_MJ_SET_EA : 804F9739
13:29:03:937 0984 IRP_MJ_FLUSH_BUFFERS : F76F02E2
13:29:03:937 0984 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F9739
13:29:03:937 0984 IRP_MJ_SET_VOLUME_INFORMATION : 804F9739
13:29:03:937 0984 IRP_MJ_DIRECTORY_CONTROL : 804F9739
13:29:03:937 0984 IRP_MJ_FILE_SYSTEM_CONTROL : 804F9739
13:29:03:937 0984 IRP_MJ_DEVICE_CONTROL : F76F03BB
13:29:03:937 0984 IRP_MJ_INTERNAL_DEVICE_CONTROL : F76F3F28
13:29:03:937 0984 IRP_MJ_SHUTDOWN : F76F02E2
13:29:03:937 0984 IRP_MJ_LOCK_CONTROL : 804F9739
13:29:03:937 0984 IRP_MJ_CLEANUP : 804F9739
13:29:03:937 0984 IRP_MJ_CREATE_MAILSLOT : 804F9739
13:29:03:937 0984 IRP_MJ_QUERY_SECURITY : 804F9739
13:29:03:937 0984 IRP_MJ_SET_SECURITY : 804F9739
13:29:03:937 0984 IRP_MJ_POWER : F76F1C82
13:29:03:937 0984 IRP_MJ_SYSTEM_CONTROL : F76F699E
13:29:03:937 0984 IRP_MJ_DEVICE_CHANGE : 804F9739
13:29:03:937 0984 IRP_MJ_QUERY_QUOTA : 804F9739
13:29:03:937 0984 IRP_MJ_SET_QUOTA : 804F9739
13:29:03:968 0984 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
13:29:03:968 0984 sion
13:29:03:968 0984 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
13:29:03:968 0984
13:29:03:984 0984 Driver Name: Disk
13:29:03:984 0984 IRP_MJ_CREATE : F76F5BB0
13:29:03:984 0984 IRP_MJ_CREATE_NAMED_PIPE : 804F9739
13:29:03:984 0984 IRP_MJ_CLOSE : F76F5BB0
13:29:03:984 0984 IRP_MJ_READ : F76EFD1F
13:29:03:984 0984 IRP_MJ_WRITE : F76EFD1F
13:29:03:984 0984 IRP_MJ_QUERY_INFORMATION : 804F9739
13:29:03:984 0984 IRP_MJ_SET_INFORMATION : 804F9739
13:29:03:984 0984 IRP_MJ_QUERY_EA : 804F9739
13:29:03:984 0984 IRP_MJ_SET_EA : 804F9739
13:29:03:984 0984 IRP_MJ_FLUSH_BUFFERS : F76F02E2
13:29:03:984 0984 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F9739
13:29:03:984 0984 IRP_MJ_SET_VOLUME_INFORMATION : 804F9739
13:29:03:984 0984 IRP_MJ_DIRECTORY_CONTROL : 804F9739
13:29:03:984 0984 IRP_MJ_FILE_SYSTEM_CONTROL : 804F9739
13:29:03:984 0984 IRP_MJ_DEVICE_CONTROL : F76F03BB
13:29:03:984 0984 IRP_MJ_INTERNAL_DEVICE_CONTROL : F76F3F28
13:29:03:984 0984 IRP_MJ_SHUTDOWN : F76F02E2
13:29:03:984 0984 IRP_MJ_LOCK_CONTROL : 804F9739
13:29:03:984 0984 IRP_MJ_CLEANUP : 804F9739
13:29:03:984 0984 IRP_MJ_CREATE_MAILSLOT : 804F9739
13:29:03:984 0984 IRP_MJ_QUERY_SECURITY : 804F9739
13:29:03:984 0984 IRP_MJ_SET_SECURITY : 804F9739
13:29:03:984 0984 IRP_MJ_POWER : F76F1C82
13:29:03:984 0984 IRP_MJ_SYSTEM_CONTROL : F76F699E
13:29:03:984 0984 IRP_MJ_DEVICE_CHANGE : 804F9739
13:29:03:984 0984 IRP_MJ_QUERY_QUOTA : 804F9739
13:29:03:984 0984 IRP_MJ_SET_QUOTA : 804F9739
13:29:04:000 0984 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
13:29:04:000 0984 sion
13:29:04:000 0984 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
13:29:04:000 0984
13:29:04:000 0984 Driver Name: Disk
13:29:04:000 0984 IRP_MJ_CREATE : F76F5BB0
13:29:04:000 0984 IRP_MJ_CREATE_NAMED_PIPE : 804F9739
13:29:04:000 0984 IRP_MJ_CLOSE : F76F5BB0
13:29:04:000 0984 IRP_MJ_READ : F76EFD1F
13:29:04:000 0984 IRP_MJ_WRITE : F76EFD1F
13:29:04:000 0984 IRP_MJ_QUERY_INFORMATION : 804F9739
13:29:04:000 0984 IRP_MJ_SET_INFORMATION : 804F9739
13:29:04:000 0984 IRP_MJ_QUERY_EA : 804F9739
13:29:04:000 0984 IRP_MJ_SET_EA : 804F9739
13:29:04:000 0984 IRP_MJ_FLUSH_BUFFERS : F76F02E2
13:29:04:000 0984 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F9739
13:29:04:000 0984 IRP_MJ_SET_VOLUME_INFORMATION : 804F9739
13:29:04:000 0984 IRP_MJ_DIRECTORY_CONTROL : 804F9739
13:29:04:000 0984 IRP_MJ_FILE_SYSTEM_CONTROL : 804F9739
13:29:04:000 0984 IRP_MJ_DEVICE_CONTROL : F76F03BB
13:29:04:000 0984 IRP_MJ_INTERNAL_DEVICE_CONTROL : F76F3F28
13:29:04:000 0984 IRP_MJ_SHUTDOWN : F76F02E2
13:29:04:000 0984 IRP_MJ_LOCK_CONTROL : 804F9739
13:29:04:000 0984 IRP_MJ_CLEANUP : 804F9739
13:29:04:000 0984 IRP_MJ_CREATE_MAILSLOT : 804F9739
13:29:04:000 0984 IRP_MJ_QUERY_SECURITY : 804F9739
13:29:04:000 0984 IRP_MJ_SET_SECURITY : 804F9739
13:29:04:000 0984 IRP_MJ_POWER : F76F1C82
13:29:04:000 0984 IRP_MJ_SYSTEM_CONTROL : F76F699E
13:29:04:000 0984 IRP_MJ_DEVICE_CHANGE : 804F9739
13:29:04:000 0984 IRP_MJ_QUERY_QUOTA : 804F9739
13:29:04:000 0984 IRP_MJ_SET_QUOTA : 804F9739
13:29:04:015 0984 TDL3_StartIoLastChanceHookDetect: Unable to dump StartIo handler code
13:29:04:015 0984 sion
13:29:04:015 0984 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
13:29:04:015 0984
13:29:04:015 0984 Driver Name: atapi
13:29:04:015 0984 IRP_MJ_CREATE : F75176F2
13:29:04:015 0984 IRP_MJ_CREATE_NAMED_PIPE : 804F9739
13:29:04:015 0984 IRP_MJ_CLOSE : F75176F2
13:29:04:015 0984 IRP_MJ_READ : 804F9739
13:29:04:015 0984 IRP_MJ_WRITE : 804F9739
13:29:04:015 0984 IRP_MJ_QUERY_INFORMATION : 804F9739
13:29:04:015 0984 IRP_MJ_SET_INFORMATION : 804F9739
13:29:04:015 0984 IRP_MJ_QUERY_EA : 804F9739
13:29:04:015 0984 IRP_MJ_SET_EA : 804F9739
13:29:04:015 0984 IRP_MJ_FLUSH_BUFFERS : 804F9739
13:29:04:015 0984 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F9739
13:29:04:015 0984 IRP_MJ_SET_VOLUME_INFORMATION : 804F9739
13:29:04:015 0984 IRP_MJ_DIRECTORY_CONTROL : 804F9739
13:29:04:015 0984 IRP_MJ_FILE_SYSTEM_CONTROL : 804F9739
13:29:04:015 0984 IRP_MJ_DEVICE_CONTROL : F7517712
13:29:04:015 0984 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7513852
13:29:04:015 0984 IRP_MJ_SHUTDOWN : 804F9739
13:29:04:015 0984 IRP_MJ_LOCK_CONTROL : 804F9739
13:29:04:015 0984 IRP_MJ_CLEANUP : 804F9739
13:29:04:015 0984 IRP_MJ_CREATE_MAILSLOT : 804F9739
13:29:04:015 0984 IRP_MJ_QUERY_SECURITY : 804F9739
13:29:04:015 0984 IRP_MJ_SET_SECURITY : 804F9739
13:29:04:015 0984 IRP_MJ_POWER : F751773C
13:29:04:015 0984 IRP_MJ_SYSTEM_CONTROL : F751E336
13:29:04:015 0984 IRP_MJ_DEVICE_CHANGE : 804F9739
13:29:04:015 0984 IRP_MJ_QUERY_QUOTA : 804F9739
13:29:04:015 0984 IRP_MJ_SET_QUOTA : 804F9739
13:29:04:078 0984 siohd: 0
13:29:04:078 0984 C:\WINDOWS\system32\drivers\tsk12.tmp - Verdict: Clean
13:29:04:078 0984
13:29:04:078 0984 Completed
13:29:04:078 0984
13:29:04:078 0984 Results:
13:29:04:078 0984 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
13:29:04:078 0984 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
13:29:04:078 0984 File objects infected / cured / cured on reboot: 0 / 0 / 0
13:29:04:078 0984
13:29:04:093 0984 KLMD(ARK) unloaded successfully

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Im not sure if this was the final step to getting my pc better or if it can even get better,but i still cant log on to msn:(
I am so so grateful for your help with this matter. Your incredible at what you do on here and i appreciate everything!

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Hello.

Please post Extras.txt that OTL made for you.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My pc is very sick!! - Page 1 DXwU4
My pc is very sick!! - Page 1 VvYDg

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
OTL Extras logfile created on: 08/03/2010 11:54:49 AM - Run 1
OTL by OldTimer - Version 3.1.35.0 Folder = C:\Documents and Settings\jenn\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

1,023.00 Mb Total Physical Memory | 579.00 Mb Available Physical Memory | 57.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.24 Gb Total Space | 73.21 Gb Free Space | 65.81% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MYGIRLS
Current User Name: jenn
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.js [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
jsfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe" = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe:*:Enabled:backWeb-7288971 -- File not found
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger -- File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server -- File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader -- (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- File not found
"C:\Program Files\AOL 9.0\waol.exe" = C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL -- (America Online, Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon -- File not found
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed -- File not found
"C:\Program Files\Common Files\AOL\1148567101\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1148567101\EE\AOLServiceHost.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL -- File not found
"C:\Program Files\Common Files\AOL\1157239062\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1157239062\EE\AOLServiceHost.exe:*:Enabled:AOL -- File not found
"C:\Program Files\WinAntiVirus Pro 2006\Updater.exe" = C:\Program Files\WinAntiVirus Pro 2006\Updater.exe:*:Enabled:updater.exe -- File not found
"C:\Program Files\Grisoft\AVG7\avginet.exe" = C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe -- File not found
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe" = C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe -- File not found
"C:\Program Files\Grisoft\AVG7\avgcc.exe" = C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe -- File not found
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)
"C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater -- ()
"C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare -- (Eastman Kodak Company)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- File not found
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" = C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe:*:Enabled:Pure Networks Net2Go -- (Pure Networks, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD LE
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{257E440F-781F-459B-9A68-A0872B80C1D6}" = Windows Live Photo Gallery
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2E086814-7392-4E0F-ADB8-54A81E47406C}" = Broadcom Advanced Control Suite 2
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150080}" = J2SE Runtime Environment 5.0 Update 8
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{34C17174-BEA7-45A8-9BD0-7E5AF3639B3E}" = Kodak Memory Albums
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CCB26F5-E2A7-4C91-8340-9149D7B7C2BE}" = Virtual Earth 3D (Beta)
"{4192EAC0-6B36-4723-B216-D0E86E7757AC}" = Jasc Paint Shop Photo Album 5
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{578B6EF9-119B-4FB8-8377-7DAFA9588B97}" = Network Magic
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.5
"{6E179C77-7335-458D-9537-4F4EAC0181ED}" = Photo Click
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}" = Jasc Paint Shop Pro Studio, Dell Editon
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch®️ Jukebox
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_SMALLBUSINESSR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_SMALLBUSINESSR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Application Accelerator
"{91120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007
"{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9527450C-64B3-11D5-9B31-000021116B62}" = SmartCamera Ver 2.1
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}" = Dell Picture Studio v3.0
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C084BC61-E537-11DE-8616-005056806466}" = Google Earth
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9507D0D-1A9C-486E-91D6-33A71CCA55F2}" = Pure Networks Platform
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D5A145FC-D00C-4F1A-9119-EB4D9D659750}" = Windows Live Toolbar
"{D67A151F-B9F9-480E-8929-A68EC22A2B2F}" = Viewsat Loader 2.0
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Arcade Master" = Arcade Master
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.5
"Creative MuVo N200 Media Explorer" = Creative MuVo N200 Media Explorer
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{2E086814-7392-4E0F-ADB8-54A81E47406C}" = Broadcom Advanced Control Suite 2
"Lexmark Skin: Elastic" = Lexmark Skin: Elastic
"Lexmark X1100 Series" = Lexmark X1100 Series
"LimeWire" = LimeWire 5.2.13
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MuVo Driver" = MuVo Driver
"Network MagicUninstall" = Network Magic
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"SMALLBUSINESSR" = Microsoft Office Small Business 2007 Trial
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Smilebox" = Smilebox

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 07/03/2010 6:36:04 PM | Computer Name = MYGIRLS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from:
with error: The connection with the server was terminated abnormally

Error - 07/03/2010 6:36:05 PM | Computer Name = MYGIRLS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from:
with error: This network connection does not exist.

Error - 07/03/2010 8:48:38 PM | Computer Name = MYGIRLS | Source = Pure Networks Platform Service | ID = 1
Description = Service failed to start with error 0x80070002.

Error - 07/03/2010 8:53:06 PM | Computer Name = MYGIRLS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from:
with error: The connection with the server was terminated abnormally

Error - 07/03/2010 8:53:06 PM | Computer Name = MYGIRLS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from:
with error: This network connection does not exist.

Error - 07/03/2010 10:53:08 PM | Computer Name = MYGIRLS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from:
with error: The connection with the server was terminated abnormally

Error - 08/03/2010 10:43:10 AM | Computer Name = MYGIRLS | Source = Pure Networks Platform Service | ID = 1
Description = Service failed to start with error 0x80070002.

Error - 08/03/2010 10:47:43 AM | Computer Name = MYGIRLS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from:
with error: The connection with the server was terminated abnormally

Error - 08/03/2010 10:47:43 AM | Computer Name = MYGIRLS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from:
with error: This network connection does not exist.

Error - 08/03/2010 12:47:47 PM | Computer Name = MYGIRLS | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from:
with error: The connection with the server was terminated abnormally

[ System Events ]
Error - 22/02/2010 6:58:59 PM | Computer Name = MYGIRLS | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 22/02/2010 6:58:59 PM | Computer Name = MYGIRLS | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 22/02/2010 7:01:07 PM | Computer Name = MYGIRLS | Source = Service Control Manager | ID = 7022
Description = The Pure Networks Platform Service service hung on starting.

Error - 22/02/2010 7:01:10 PM | Computer Name = MYGIRLS | Source = Service Control Manager | ID = 7024
Description = The Pure Networks Platform Service service terminated with service-specific
error 2147942402 (0x80070002).

Error - 23/02/2010 8:04:37 AM | Computer Name = MYGIRLS | Source = Service Control Manager | ID = 7022
Description = The Pure Networks Platform Service service hung on starting.

Error - 23/02/2010 8:04:39 AM | Computer Name = MYGIRLS | Source = Service Control Manager | ID = 7024
Description = The Pure Networks Platform Service service terminated with service-specific
error 2147942402 (0x80070002).

Error - 05/03/2010 10:02:31 AM | Computer Name = MYGIRLS | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 05/03/2010 10:02:31 AM | Computer Name = MYGIRLS | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 05/03/2010 10:03:50 AM | Computer Name = MYGIRLS | Source = Service Control Manager | ID = 7022
Description = The Pure Networks Platform Service service hung on starting.

Error - 05/03/2010 10:03:54 AM | Computer Name = MYGIRLS | Source = Service Control Manager | ID = 7024
Description = The Pure Networks Platform Service service terminated with service-specific
error 2147942402 (0x80070002).


< End of report >

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Thats a good sign....i can now post this "extras" report!
Thanks again for all your help!
Do you have any other recomendations?
Kind Regards,
Jenn

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Hello.

I see that you are running Limewire.
P2P(Peer to peer) applications are designed to help you easily share and distribute files between you and a group of people. But they can also be used to distribute malware, and thus are not considered safe.
The removal of these programs is optional, but highly recommended.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

    J2SE Runtime Environment 5.0 Update 8
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) SE Runtime Environment 6 Update 1
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    LimeWire 5.2.13
    Viewpoint Media Player

Please run OTL.exe.

  • Copy the commands with file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    :files
    c:\windows\SYSTEM32\bpaeicjy.tmp
    c:\windows\SYSTEM32\eeakngcu.tmp
    c:\windows\SYSTEM32\qttss.tmp


  • Return to OTL, right click in the "Custom Scans/Fixes" window (under the light green bar) and choose Paste.

  • Click the red Run Fix button.
  • A fix log in Notepad will appear. Copy the contents of the fix log to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTL.exe
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My pc is very sick!! - Page 1 DXwU4
My pc is very sick!! - Page 1 VvYDg

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Sorry to ask you such silly questions....im sure you have much more impotant things to attend to, but if i delete the limewire will that allow me to download? Im actually trying to download itunes but i still get an error saying " the windows installer service could not be accessed. This can occur if you are running windows in safe mode, or if the windows installer is not correctly installed"

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
I thought i would just go ahead and remove all the programs you recommened in the above post but i ran into the same problem as i did when i tried to download the itunes."the windows installer service could not be accessed. This can occur if you are running windows in safe mode, or if the windows installer is not correctly installed"
Im not sure if i should try and remove these programs in safe mode or what my next step should be?
I appreciate any help or information you may be able to provide.
Kind Regards,
Jenn

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Can you not run normal mode?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My pc is very sick!! - Page 1 DXwU4
My pc is very sick!! - Page 1 VvYDg

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Hey,
I can run my pc in normal mode but i can't download anything for some reason, nor can i remove any programs you requested above.
I get a message saying ."the windows installer service could not be accessed. This can occur if you are running windows in safe mode, or if the windows installer is not correctly installed"
Any suggestions?
I appreciate your time.
Kind Regards,
Jenn

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Hello.
Do you get that error in normal mode? the error happens in Safe Mode because the installer service doesn't run in Safe Mode.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My pc is very sick!! - Page 1 DXwU4
My pc is very sick!! - Page 1 VvYDg

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Actually i get this message in normal mode!
My pc will allow me to go online but thats it!! As i said in my previous message i cannot remove anything nor will it allow me to download anything without that message popping up!
This is certainly confusing.
Thanks again,
Jenn

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
Hello.

Please re-run Combofix and post the new log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My pc is very sick!! - Page 1 DXwU4
My pc is very sick!! - Page 1 VvYDg

descriptionMy pc is very sick!! - Page 1 EmptyRe: My pc is very sick!!

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum