I'm also unable to do any upgrades from Microsoft's site -- it hangs. I also can't run Help and Support, or the System Information programs on the laptop. (They show an hourglass briefly and then nothing.) I've copied the Rooter.txt and the OTlistit.txt below (It won't create an "Extras.txt" file.)
Microsoft Windows XP Professional (5.1.2600) Service Pack 2
C:\ [Fixed] - NTFS - (Total:57224 Mo/Free:1216 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
E:\ [Removable] (Total:120 Mo/Free:63 Mo)
Thu 03/26/2009|10:24
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\alg.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\WINDOWS\system32\wuauclt.exe
---------- C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
---------- C:\PROGRA~1\AVG\AVG8\avgrsx.exe
---------- C:\PROGRA~1\AVG\AVG8\avgnsx.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Documents and Settings\Em\Desktop\Rooter.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
----------------------\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - Thu 03/26/2009|10:25
----------------------\\ Scan completed at 10:25
OTListIt logfile created on: 3/26/2009 10:25:55 AM - Run 10
OTListIt2 by OldTimer - Version 2.0.7.1 Folder = C:\Documents and Settings\Em\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18241)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.50 Gb Total Physical Memory | 1.09 Gb Available Physical Memory | 72.82% Memory free
3.35 Gb Paging File | 3.10 Gb Available in Paging File | 92.61% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 37.19 Gb Free Space | 66.55% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 120.73 Mb Total Space | 63.59 Mb Free Space | 52.67% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: EMILY
Current User Name: Em
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\Em\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (0L81CY3S7W0 [Disabled | Stopped]) -- File not found
SRV - (23KJWN [Disabled | Stopped]) -- File not found
SRV - (2B585B5 [Disabled | Stopped]) -- File not found
SRV - (6to4 [Auto | Running]) -- C:\WINDOWS\system32\6to4v32.dll ()
SRV - (8OO5O [Disabled | Stopped]) -- File not found
SRV - (Apple Mobile Device [Disabled | Stopped]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Disabled | Stopped]) -- C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ccwiz [Disabled | Stopped]) -- File not found
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DgVip_Service [Disabled | Stopped]) -- File not found
SRV - (DWMRCS [Disabled | Stopped]) -- C:\WINDOWS\SYSTEM32\DWRCS.EXE (DameWare Development LLC)
SRV - (F5P3KNCC73 [Disabled | Stopped]) -- File not found
SRV - (F8Z5L5Q [Disabled | Stopped]) -- File not found
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (FwcAgent [Disabled | Stopped]) -- C:\Program Files\Microsoft Firewall Client 2004\FwcAgent.exe (Microsoft ® Corporation)
SRV - (HCE13QIBP [Disabled | Stopped]) -- File not found
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IBMPMSVC [Disabled | Stopped]) -- C:\WINDOWS\system32\ibmpmsvc.exe ()
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [Disabled | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Irmon [Auto | Running]) -- C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Disabled | Stopped]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (jdyk [Disabled | Stopped]) -- File not found
SRV - (jldk [Disabled | Stopped]) -- File not found
SRV - (jlqk [Disabled | Stopped]) -- File not found
SRV - (JQ33FQ21X [Disabled | Stopped]) -- File not found
SRV - (jqjk [Disabled | Stopped]) -- File not found
SRV - (jqka [Disabled | Stopped]) -- File not found
SRV - (jqtk [Disabled | Stopped]) -- File not found
SRV - (jtqa [Disabled | Stopped]) -- File not found
SRV - (jwka [Disabled | Stopped]) -- File not found
SRV - (jwmk [Disabled | Stopped]) -- File not found
SRV - (jwqa [Disabled | Stopped]) -- File not found
SRV - (jwqk [Disabled | Stopped]) -- File not found
SRV - (jwtk [Disabled | Stopped]) -- File not found
SRV - (Lavasoft Ad-Aware Service [Disabled | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LBTServ [Disabled | Stopped]) -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (MDM [Disabled | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (mstsc [Disabled | Stopped]) -- C:\WINDOWS\System32\mstsc.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [Disabled | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (OL2VNFYC0GS [Disabled | Stopped]) -- File not found
SRV - (ose [Disabled | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Portable Media Serial [Disabled | Stopped]) -- File not found
SRV - (Q1JO6D [Disabled | Stopped]) -- File not found
SRV - (R95MDJ [Disabled | Stopped]) -- File not found
SRV - (RCZAXNA [Disabled | Stopped]) -- File not found
SRV - (RL7W6BORIDB [Disabled | Stopped]) -- File not found
SRV - (T2TI2BKXN [Disabled | Stopped]) -- File not found
SRV - (TSG55AHBB [Disabled | Stopped]) -- File not found
SRV - (U3IDB9OS [Disabled | Stopped]) -- File not found
SRV - (VHOGX4 [Disabled | Stopped]) -- File not found
SRV - (Windows_Twains [Disabled | Stopped]) -- File not found
SRV - (WMPNetworkSvc [Disabled | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (X4QIT7BI [Disabled | Stopped]) -- File not found
SRV - (ZBFROERBN [Disabled | Stopped]) -- File not found
========== Driver Services (SafeList) ==========
DRV - (ADIHdAudAddService [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (AEAudio [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\AEAudio.sys (Andrea Electronics Corporation)
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atmeltpm [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\atmeltpm.sys (Atmel, Inc.)
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (e1express [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\e1e5132.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWAZL [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (iastor [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (IBMPMDRV [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys (Lenovo.)
DRV - (Lbd [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LHidFilt [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (LMouFilt [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (NETw4x32 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\NETw4x32.sys (Intel Corporation)
DRV - (NSCIRDA [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\nscirda.sys (National Semiconductor Corporation)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Smapint [System | Running]) -- C:\WINDOWS\System32\drivers\Smapint.sys (Microsoft Corporation)
DRV - (SynTP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (TDSMAPI [System | Running]) -- C:\WINDOWS\System32\drivers\TDSMAPI.SYS ()
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = 00000000;
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/03/24 17:11:05 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/21 11:02:03 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/08 12:27:17 | 00,000,000 | ---D | M]
[2009/03/21 11:02:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Em\Application Data\mozilla\Extensions
[2009/03/21 11:02:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Em\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/21 11:02:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Em\Application Data\mozilla\Firefox\Profiles\qtl4nlkn.default\extensions
[2009/03/08 17:31:10 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/03/07 15:41:00 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/08 12:27:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/03/07 15:40:53 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/07 15:40:53 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/01/19 18:28:04 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/01/19 18:28:04 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/01/19 18:28:04 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/01/19 18:28:04 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/01/19 18:28:04 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/01/19 18:28:04 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/01/19 18:28:04 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Microsoft Firewall Client Name Space Service Provider] - C:\Program Files\Microsoft Firewall Client 2004\FwcWsp.dll (Microsoft ® Corporation)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1196868946421 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\*.tmp files]
[2009/03/26 10:24:53 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/03/26 10:24:45 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\Em\Desktop\Rooter.exe
[2009/03/26 10:24:37 | 00,499,200 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Em\Desktop\OTListIt2.exe
[2009/03/24 19:32:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Em\Application Data\HouseCall 6.6
[2009/03/24 19:31:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Em\Application Data\Sun
[2009/03/24 17:22:13 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$
[2009/03/24 17:11:31 | 00,107,912 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/24 17:11:31 | 00,010,520 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/03/24 17:11:31 | 00,001,507 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/03/24 17:11:26 | 00,325,640 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/24 17:11:24 | 00,027,656 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/03/24 17:11:19 | 34,448,456 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/24 17:11:19 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/03/24 17:11:19 | 00,401,372 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/03/24 17:11:19 | 00,066,382 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/24 17:11:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2009/03/24 16:55:10 | 00,055,640 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2009/03/23 15:32:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2009/03/22 09:37:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Em\Application Data\Malwarebytes
[2009/03/21 23:37:20 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/03/21 23:37:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2009/03/21 11:49:12 | 00,007,919 | ---- | C] () -- C:\DOCUME~1\Em\My Documents\test.xlsx
[2009/03/21 11:35:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Em\Application Data\AdobeUM
[2009/03/21 11:35:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Em\Local Settings\Application Data\Adobe
[2009/03/21 11:35:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2009/03/21 11:07:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Em\Application Data\Macromedia
[2009/03/21 11:02:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Em\Local Settings\Application Data\Mozilla
[2009/03/21 11:02:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Em\Application Data\Mozilla
[2009/03/21 09:36:13 | 00,070,016 | ---- | C] () -- C:\Documents and Settings\Em\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/21 09:28:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Em\Local Settings\Application Data\Microsoft Help
[2009/03/15 13:35:06 | 05,886,648 | -H-- | C] () -- C:\Documents and Settings\Em\Local Settings\Application Data\IconCache.db
[2009/03/15 13:23:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Em\Application Data\Adobe
[2009/03/15 12:38:11 | 00,000,073 | -HS- | C] () -- C:\DOCUME~1\Em\My Documents\desktop.ini
[2009/03/15 12:38:11 | 00,000,000 | R--D | C] -- C:\DOCUME~1\Em\My Documents\My Pictures
[2009/03/15 12:38:11 | 00,000,000 | R--D | C] -- C:\DOCUME~1\Em\My Documents\My Music
[2009/03/15 12:38:07 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Em\Application Data\desktop.ini
[2009/03/15 12:38:06 | 00,000,000 | --SD | C] -- C:\Documents and Settings\Em\Application Data\Microsoft
[2009/03/15 12:38:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Em\Local Settings\Application Data\Microsoft
[2009/03/08 15:08:11 | 00,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/03/08 14:52:20 | 00,064,160 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/03/08 14:44:45 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/03/08 14:44:39 | 00,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2009/03/08 14:44:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/03/08 14:18:25 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/03/08 14:18:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/03/07 16:23:55 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/07 16:23:55 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/07 16:23:53 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/07 16:23:52 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/05 21:24:52 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/03/05 20:51:32 | 00,001,372 | ---- | C] () -- C:\Program Files\CQ0TO8BGG.bat
[2009/03/05 20:45:49 | 00,001,377 | ---- | C] () -- C:\Program Files\GSGR5AC05.bat
[2009/03/05 20:35:34 | 00,001,380 | ---- | C] () -- C:\Program Files\GXE4SHMOA.bat
[2009/03/05 17:10:45 | 00,001,366 | ---- | C] () -- C:\Program Files\DG0KDG.bat
[2009/03/04 23:30:29 | 00,001,368 | ---- | C] () -- C:\Program Files\NISD3YC.bat
[2009/03/04 19:16:35 | 00,001,366 | ---- | C] () -- C:\Program Files\NS738567Z5J.bat
[2009/03/04 18:31:36 | 00,001,377 | ---- | C] () -- C:\Program Files\VVN4BC.bat
[2009/03/04 17:13:54 | 00,001,372 | ---- | C] () -- C:\Program Files\QI2JU.bat
[2009/03/04 15:37:46 | 00,001,369 | ---- | C] () -- C:\Program Files\G7S9EXQVVS.bat
[2009/03/02 16:14:28 | 00,001,370 | ---- | C] () -- C:\Program Files\Q9ZBQ3A2GBUH.bat
[2009/03/02 16:01:23 | 00,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/03/02 16:01:16 | 00,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/02 16:01:12 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2009/03/02 15:41:29 | 00,001,373 | ---- | C] () -- C:\Program Files\2TJCUY.bat
[2009/03/02 15:26:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/02 15:23:09 | 00,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2009/03/02 15:18:35 | 00,001,369 | ---- | C] () -- C:\Program Files\9Y5VBUL.bat
[2009/03/02 15:11:33 | 00,001,363 | ---- | C] () -- C:\Program Files\T6G0L.bat
[2009/03/02 15:02:32 | 00,001,372 | ---- | C] () -- C:\Program Files\IGO405.bat
[2009/03/02 14:23:26 | 00,001,380 | ---- | C] () -- C:\Program Files\V24X6R3GO.bat
[2009/03/02 13:36:50 | 00,001,371 | ---- | C] () -- C:\Program Files\KGS4HC.bat
[2009/03/02 13:34:10 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\*.tmp files]
[2009/03/26 10:21:44 | 34,448,456 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/03/26 10:20:24 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/03/26 10:20:11 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/03/26 10:20:09 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/03/25 23:39:40 | 00,066,382 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/03/24 21:22:06 | 05,886,648 | -H-- | M] () -- C:\Documents and Settings\Em\Local Settings\Application Data\IconCache.db
[2009/03/24 17:11:31 | 00,107,912 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/24 17:11:31 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/03/24 17:11:31 | 00,001,507 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/03/24 17:11:26 | 00,325,640 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/24 17:11:24 | 00,027,656 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/03/24 17:11:19 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/03/24 17:11:19 | 00,401,372 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/03/24 16:24:11 | 00,000,603 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/03/24 16:24:11 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/03/24 16:24:11 | 00,000,211 | RHS- | M] () -- C:\boot.ini
[2009/03/24 00:00:44 | 00,499,200 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Em\Desktop\OTListIt2.exe
[2009/03/24 00:00:30 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\Em\Desktop\Rooter.exe
[2009/03/23 15:34:05 | 00,000,686 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2009/03/22 09:23:32 | 00,000,073 | -HS- | M] () -- C:\DOCUME~1\Em\My Documents\desktop.ini
[2009/03/21 23:37:53 | 00,033,866 | ---- | M] () -- C:\WINDOWS\System32\info.dat
[2009/03/21 23:35:48 | 00,160,764 | ---- | M] () -- C:\WINDOWS\System32\ljcbol.key
[2009/03/21 23:04:48 | 00,004,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\beep.sys
[2009/03/21 23:04:48 | 00,004,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\beep.sys
[2009/03/21 11:49:13 | 00,007,919 | ---- | M] () -- C:\DOCUME~1\Em\My Documents\test.xlsx
[2009/03/21 09:36:13 | 00,070,016 | ---- | M] () -- C:\Documents and Settings\Em\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/08 15:00:30 | 00,526,534 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/08 15:00:30 | 00,445,096 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/03/08 15:00:30 | 00,072,554 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/03/08 14:52:03 | 00,015,688 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/03/08 14:51:54 | 00,064,160 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/03/08 14:28:53 | 00,352,023 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090308-143049.backup
[2009/03/07 16:23:55 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/02 16:01:23 | 00,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2009/03/02 16:01:16 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/02 13:51:54 | 00,050,578 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090308-142853.backup
========== Alternate Data Streams ==========
@Alternate Data Stream - 8 bytes -> C:\WINDOWS\commonXP_20080824.vbs:Bookmarks
@Alternate Data Stream - 8 bytes -> C:\WINDOWS\commonXP_20080727.vbs:Bookmarks
@Alternate Data Stream - 8 bytes -> C:\WINDOWS\commonXP_20080327.vbs:Bookmarks
@Alternate Data Stream - 8 bytes -> C:\WINDOWS\commonXP_20080109.vbs:Bookmarks
@Alternate Data Stream - 6555 bytes -> C:\WINDOWS\commonXP_20080327.vbs:Undo
@Alternate Data Stream - 364 bytes -> C:\WINDOWS\commonXP_20080109.vbs:Undo
@Alternate Data Stream - 21608 bytes -> C:\WINDOWS\commonXP_20080824.vbs:Undo
@Alternate Data Stream - 19182 bytes -> C:\WINDOWS\commonXP_20080727.vbs:Undo
< End of report >
Thanks,
Peggy V.