This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Several issues, hijackthis log included

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm trying to help someone cleanup their laptop, which seems to have several issues. On bootup, there is a pop-up for Personal Anti-virus, which I can close out, but I can't find anything called that in the Add/Remove Programs list. The machine will crash and reboot randomly, sometimes after being on for a while, sometimes just mins. I installed Malwarebytes Antimalware and Spybot in safe mode, but neither program will run. I tried renaming the executables but no luck. I'm including the HJT log here in hopes someone can tell me what's wrong with this machine, as I'm sure it's infected with something.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:50:48 PM, on 5/1/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\FLASHC~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Alltel\AlltelWiFi\AlltelWiFi.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Convesoft\Orion\Messenger.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Apoint2K\Apntex.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [SetPanel] C:\Acer\APanel\APanel.cmd
O4 - HKLM\..\Run: [AlltelWiFi] C:\Program Files\Alltel\AlltelWiFi\Alltel.lnk
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: Orion.lnk = C:\Convesoft\Orion\Messenger.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{155520D7-C049-4223-A4A3-643C520DA4E2}: NameServer = 75.116.127.154 75.116.63.154
O17 - HKLM\System\CS1\Services\Tcpip\..\{155520D7-C049-4223-A4A3-643C520DA4E2}: NameServer = 75.116.127.154 75.116.63.154
O17 - HKLM\System\CS6\Services\Tcpip\..\{155520D7-C049-4223-A4A3-643C520DA4E2}: NameServer = 75.116.127.154 75.116.63.154
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\Program Files\McAfee\VirusScan\McShield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 9636 bytes
Hi , welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

* As Vista user, you will need to right-click on the file and choose Run As Administrator.

Download OTListIt2 to your desktop.
  • right-click on OTList2.exe and choose Run As Administrator. to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

No need for a Hijackthis log this time.
Here are the logs you requested;

OTListIt Extras logfile created on: 5/1/2009 2:21:46 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.2 Folder = C:\Users\Flash Cadillac\Desktop
Windows Vista Unlicensed product Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.25 Mb Total Physical Memory | 186.55 Mb Available Physical Memory | 18.41% Memory free
2.23 Gb Paging File | 0.99 Gb Available in Paging File | 44.39% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 68.77 Gb Total Space | 42.89 Gb Free Space | 62.37% Space Free | Partition Type: NTFS
Drive D: | 68.56 Gb Total Space | 68.47 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 961.97 Mb Total Space | 786.20 Mb Free Space | 81.73% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: FLASHCADILLA-PC
Current User Name: Flash Cadillac
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
Reg Error: Unknown registry data type File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
"EnableFirewall" = 1
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile
"EnableFirewall" = 1
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications\List]

========== Vista Active Open Ports Exception List ==========


========== Vista Active Application Exception List ==========

{06326A26-3C5A-419D-87E9-B7D42F6D82E5} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=AOL CONNECTIVITY SERVICE DIALER | APP=C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLDIAL.EXE |
{0EA5B12D-7631-464C-AEF2-D0FF969FBB50} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=YAHOO! MESSENGER | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YAHOOMESSENGER.EXE |
{11EAE10D-8E63-4AF3-A30E-81D3A20302F9} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=AOL SHARED COMPONENTS | APP=C:\PROGRAM FILES\COMMON FILES\AOL\1218750347\EE\AOLSOFTWARE.EXE |
{13DB4A83-AE77-4992-9618-379BB8193AC5} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=AOL SYSTEM INFORMATION | APP=C:\PROGRAM FILES\COMMON FILES\AOL\SYSTEM INFORMATION\SINF.EXE |
{176A1615-1396-4AE5-B898-BB224EE13527} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=AOL LOADER | APP=C:\PROGRAM FILES\COMMON FILES\AOL\LOADER\AOLLOAD.EXE |
{2CDCDA02-E919-4AFE-930B-EC2244E54711} = DIR=IN | ACTION=ALLOW | NAME=CYBERLINK POWERCINEMA RESIDENT PROGRAM | APP=C:\PROGRAM FILES\ACER\ACER ARCADE\PCMSERVICE.EXE |
{2D6EC3BC-38D9-4C83-99A2-B6649CFEF9D0} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=AOL SHARED COMPONENTS | APP=C:\PROGRAM FILES\COMMON FILES\AOL\1218750347\EE\AOLSOFTWARE.EXE |
{3F238F56-7B09-471B-A1F2-5FCAB725E61F} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=AOL CONNECTIVITY SERVICE | APP=C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE |
{41FA7C23-3216-4304-BE50-D47C04B14589} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=AOL | APP=C:\PROGRAM FILES\AOL 9.1\WAOL.EXE |
{5E1CE298-0D49-4CC6-B058-C4A89EF9D813} = DIR=IN | ACTION=ALLOW | NAME=HOMEMEDIA | APP=C:\PROGRAM FILES\ACER\HOMEMEDIA\HOMEMEDIA.EXE |
{676A6E87-4F5D-404B-87DA-30BC405D8A9C} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=YAHOO! MESSENGER | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YAHOOMESSENGER.EXE |
{6C3A78C4-E1B7-4BDB-8E9F-7338796FBB3E} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=AOL TOPSPEED | APP=C:\PROGRAM FILES\COMMON FILES\AOL\TOPSPEED\3.0\AOLTPSD3.EXE |
{760B2901-463D-4E36-B6EC-DF21768B58F9} = DIR=IN | ACTION=ALLOW | NAME=CYBERLINK MEDIA SERVER BROWSER ENGINE | APP=C:\PROGRAM FILES\ACER\ACER ARCADE\KERNEL\DMP\CLBROWSERENGINE.EXE |
{7BE917ED-58E2-4523-B35D-A3BBC71F0FD8} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=AOL CONNECTIVITY SERVICE DIALER | APP=C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLDIAL.EXE |
{805B53AD-6E7F-496A-99B9-154877AAD1AB} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=AOL LOADER | APP=C:\PROGRAM FILES\COMMON FILES\AOL\LOADER\AOLLOAD.EXE |
{83A5A6F8-44F5-471A-BBE6-75AC318CF18A} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=AOL | APP=C:\PROGRAM FILES\AOL 9.1\WAOL.EXE |
{84F3D11B-50B7-4E1B-99E9-4D5AC609EBEB} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=AOL SYSTEM INFORMATION | APP=C:\PROGRAM FILES\COMMON FILES\AOL\SYSTEM INFORMATION\SINF.EXE |
{9417B284-3A29-42DA-A012-D48C089599AC} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=AOL TOPSPEED | APP=C:\PROGRAM FILES\COMMON FILES\AOL\TOPSPEED\3.0\AOLTPSD3.EXE |
{CDC33473-8B04-4DAE-AFD0-7C554D50E101} = DIR=IN | ACTION=ALLOW | NAME=CYBERLINK MEDIA SERVER | APP=C:\PROGRAM FILES\ACER\ACER ARCADE\KERNEL\DMS\CLMSSERVICE.EXE |
{EE668238-02BC-4FD8-83A9-1437F276980E} = DIR=IN | ACTION=ALLOW | NAME=CYBERLINK POWERCINEMA | APP=C:\PROGRAM FILES\ACER\ACER ARCADE\POWERCINEMA.EXE |
{EFD54762-4763-4C88-A352-70C01F52FD3B} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=AOL CONNECTIVITY SERVICE | APP=C:\PROGRAM FILES\COMMON FILES\AOL\ACS\AOLACSD.EXE |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0BF78E88-A7C9-4406-89CF-0BA473BA7821}" = Orion
"{10C69612-017B-45F5-B986-7D113D5A2EA3}" = MSN Toolbar
"{11316260-6666-467B-AC34-183FCB5D4335}" = Acer Mobility Center Plug-In
"{116FF17B-1A30-4FC2-9B01-5BC5BD46B0B3}" = Acer eLock Management
"{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 12
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = Acer Crystal Eye Webcam Video Class Camera
"{44CDBD1B-89FB-4E02-8319-2A4C550F664A}" = RTC Client API v1.2
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75852F49-2CAF-443F-B7C2-53DE5847DE56}" = OpenOffice.org 2.0
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111118433}" = Mystery Case Files - Huntsville
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111543617}" = Backspin Billiards
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112310577}" = Flip Words 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
"{AA047D7C-5E7C-4878-B75C-77589151B563}" = Acer Crystal Eye webcam
"{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B29B0066-547B-402c-9C0D-090E2F928A01}" = PANTECH PC USB Modem Software
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BF839132-BD43-4056-ACBF-4377F4A88E2A}" = Acer ePresentation Management
"{C06554A1-2C1E-4D20-B613-EE62C79927CC}" = Acer eNet Management
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE65A9A0-9686-45C6-9098-3C9543A412F0}" = Acer eSettings Management
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F226C1DA-66D7-4ABC-86B5-3F978A660EBF}" = AOL Mail and AIM Gadget
"{F9598BA8-7FC9-4960-9F01-6C8CCC98BFA5}" = Alltel Wi-Fi Connection Software
"Acer Assist" = Acer Assist
"Acer GameZone Console_is1" = Acer GameZone Console 2.0.1.1
"Acer Registration" = Acer Registration
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"AOL Emergency Connect Utility 1.0" = Uninstall AOL Emergency Connect Utility 1.0
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"GridVista" = Acer GridVista
"HDMI" = Intel® Graphics Media Accelerator Driver
"InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"InstallShield_{1598034D-7147-432C-8CA8-888E0632D124}" = NTI Backup NOW! 4.7
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"PKR" = PKR
"QuickLink Mobile" = QuickLink Mobile
"SpywareBlaster_is1" = SpywareBlaster 4.2
"ViewpointMediaPlayer" = Viewpoint Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/29/2009 9:59:49 AM | Computer Name = FlashCadilla-PC | Source = Software Licensing Service | ID = 1020
Description = Proxy Execution Key has failed to load. hr=0xC004D401 Proxy Execution
Policy=WindowsSearchEngine-Licensing-SearchEnabled

Error - 4/29/2009 9:59:49 AM | Computer Name = FlashCadilla-PC | Source = Software Licensing Service | ID = 1020
Description = Proxy Execution Key has failed to load. hr=0xC004D401 Proxy Execution
Policy=parentalcontrols-EnableFeature

Error - 4/29/2009 9:59:49 AM | Computer Name = FlashCadilla-PC | Source = Software Licensing Service | ID = 1020
Description = Proxy Execution Key has failed to load. hr=0xC004D401 Proxy Execution
Policy=shell32-EnableProxyFeature

Error - 4/29/2009 9:59:52 AM | Computer Name = FlashCadilla-PC | Source = Software Licensing Service | ID = 8193
Description = License Activation Scheduler (SLUINotify.dll) failed with the following
error code: 0xC004D401

Error - 4/29/2009 10:02:13 AM | Computer Name = FlashCadilla-PC | Source = Software Licensing Service | ID = 8193
Description = License Activation Scheduler (SLUINotify.dll) failed with the following
error code: 0xC004D401

Error - 4/29/2009 10:08:48 AM | Computer Name = FlashCadilla-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/29/2009 10:13:21 AM | Computer Name = FlashCadilla-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/29/2009 10:16:44 AM | Computer Name = FlashCadilla-PC | Source = EventSystem | ID = 4609
Description =

Error - 4/29/2009 10:17:37 AM | Computer Name = FlashCadilla-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/29/2009 10:45:05 AM | Computer Name = FlashCadilla-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 2/22/2009 6:22:55 PM | Computer Name = FlashCadilla-PC | Source = PlugPlayManager | ID = 12
Description = The device 'PANTECH USB Modem WWAN Driver #2' (USB\VID_106c&PID_3711&MI_02\6&78b6374&0&8515)
disappeared from the system without first being prepared for removal.

Error - 2/22/2009 9:31:42 PM | Computer Name = FlashCadilla-PC | Source = ACPI | ID = 327693
Description = : The embedded controller (EC) did not respond within the specified
timeout period. This may indicate that there is an error in the EC hardware or
firmware or that the BIOS is accessing the EC incorrectly. You should check with
your computer manufacturer for an upgraded BIOS. In some situations, this error
may cause the computer to function incorrectly.

Error - 2/23/2009 9:12:37 AM | Computer Name = FlashCadilla-PC | Source = PlugPlayManager | ID = 12
Description = The device 'PANTECH USB Modem WWAN Driver #2' (USB\VID_106c&PID_3711&MI_02\6&78b6374&0&8515)
disappeared from the system without first being prepared for removal.

Error - 2/23/2009 8:53:07 PM | Computer Name = FlashCadilla-PC | Source = PlugPlayManager | ID = 12
Description = The device 'PANTECH USB Modem WWAN Driver #2' (USB\VID_106c&PID_3711&MI_02\6&78b6374&0&8515)
disappeared from the system without first being prepared for removal.

Error - 2/24/2009 1:34:06 AM | Computer Name = FlashCadilla-PC | Source = PlugPlayManager | ID = 12
Description = The device 'PANTECH USB Modem WWAN Driver #2' (USB\VID_106c&PID_3711&MI_02\6&78b6374&0&8515)
disappeared from the system without first being prepared for removal.

Error - 2/24/2009 9:41:10 AM | Computer Name = FlashCadilla-PC | Source = PlugPlayManager | ID = 12
Description = The device 'PANTECH USB Modem WWAN Driver #2' (USB\VID_106c&PID_3711&MI_02\6&78b6374&0&8515)
disappeared from the system without first being prepared for removal.

Error - 2/24/2009 2:50:03 PM | Computer Name = FlashCadilla-PC | Source = PlugPlayManager | ID = 12
Description = The device 'PANTECH USB Modem WWAN Driver #2' (USB\VID_106c&PID_3711&MI_02\6&78b6374&0&8515)
disappeared from the system without first being prepared for removal.

Error - 2/24/2009 3:21:20 PM | Computer Name = FlashCadilla-PC | Source = ACPI | ID = 327693
Description = : The embedded controller (EC) did not respond within the specified
timeout period. This may indicate that there is an error in the EC hardware or
firmware or that the BIOS is accessing the EC incorrectly. You should check with
your computer manufacturer for an upgraded BIOS. In some situations, this error
may cause the computer to function incorrectly.

Error - 2/24/2009 3:58:03 PM | Computer Name = FlashCadilla-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 2:56:31 PM on 2/24/2009 was unexpected.

Error - 2/24/2009 3:58:06 PM | Computer Name = FlashCadilla-PC | Source = HTTP | ID = 15016
Description =


< End of report >
OTListIt logfile created on: 5/1/2009 2:21:46 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.2 Folder = C:\Users\Flash Cadillac\Desktop
Windows Vista Unlicensed product Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.25 Mb Total Physical Memory | 186.55 Mb Available Physical Memory | 18.41% Memory free
2.23 Gb Paging File | 0.99 Gb Available in Paging File | 44.39% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 68.77 Gb Total Space | 42.89 Gb Free Space | 62.37% Space Free | Partition Type: NTFS
Drive D: | 68.56 Gb Total Space | 68.47 Gb Free Space | 99.87% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 961.97 Mb Total Space | 786.20 Mb Free Space | 81.73% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: FLASHCADILLA-PC
Current User Name: Flash Cadillac
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated)
PRC - C:\Program Files\Acer\Acer Arcade\PCMService.exe (CyberLink Corp.)
PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation)
PRC - C:\Windows\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Users\Flash Cadillac\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Windows\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\Acer\ALaunch\ALaunchSvc.exe ()
PRC - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe ()
PRC - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe (Cyberlink)
PRC - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
PRC - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (Acer Inc.)
PRC - C:\Acer\Empowering Technology\eNet\eNet Service.exe (Acer Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Acer\Mobility Center\MobilityService.exe ()
PRC - C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe ()
PRC - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
PRC - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe ()
PRC - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (acer)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Alltel\AlltelWiFi\AlltelWiFi.exe (Boingo Wireless, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\system32\igfxext.exe (Intel Corporation)
PRC - C:\Windows\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe (Microsoft Corp.)
PRC - C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE (Acer Inc.)
PRC - C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE (Acer Inc.)
PRC - C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE (Acer Inc.)
PRC - C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE (Acer Inc.)
PRC - C:\Program Files\Apoint2K\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint2K\Apntex.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Internet Explorer\Iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\Iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe (Google Inc.)
PRC - C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe (Adobe Systems, Inc.)
PRC - C:\Windows\system32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Users\Flash Cadillac\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AgereModemAudio [Auto | Running]) – C:\Windows\system32\agrsmsvc.exe (Agere Systems)
SRV - (ALaunchService [Auto | Running]) – C:\Acer\ALaunch\ALaunchSvc.exe ()
SRV - (CLCapSvc [Auto | Running]) – C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe ()
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CLSched [Auto | Running]) – C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe ()
SRV - (CyberLink Media Library Service [Auto | Running]) – C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe (Cyberlink)
SRV - (eDataSecurity Service [Auto | Running]) – C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
SRV - (eLockService [Auto | Running]) – C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (Acer Inc.)
SRV - (eNet Service [Auto | Running]) – C:\Acer\Empowering Technology\eNet\eNet Service.exe (Acer Inc.)
SRV - (eRecoveryService [Auto | Running]) – C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
SRV - (eSettingsService [Auto | Running]) – C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe ()
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (McShield [Unknown | Stopped]) – File not found
SRV - (McSysmon [On_Demand | Stopped]) – File not found
SRV - (MobilityService [Auto | Running]) – C:\Acer\Mobility Center\MobilityService.exe ()
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMIService [Auto | Running]) – C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (acer)
SRV - (WMPNetworkSvc [On_Demand | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (XAudioService [Auto | Running]) – C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)

========== Driver Services (SafeList) ==========

DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (AgereSoftModem [On_Demand | Running]) – C:\Windows\system32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\Windows\system32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (athr [On_Demand | Running]) – C:\Windows\system32\DRIVERS\athr.sys (Atheros Communications, Inc.)
DRV - (b57nd60x [On_Demand | Running]) – C:\Windows\system32\DRIVERS\b57nd60x.sys (Broadcom Corporation)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (DKbFltr [On_Demand | Running]) – C:\Windows\system32\DRIVERS\DKbFltr.sys (Dritek System Inc.)
DRV - (DritekPortIO [System | Running]) – C:\Program Files\Launch Manager\DPortIO.sys (Dritek System Inc.)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (HSFHWAZL [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (iaStorV [Disabled | Stopped]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (igfx [On_Demand | Running]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (int15 [Auto | Running]) – C:\Acer\Empowering Technology\eRecovery\int15.sys (Acer, Inc.)
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\Windows\system32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (mdmxsdk [Auto | Running]) – C:\Windows\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (MegaSR [Disabled | Stopped]) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (NTIDrvr [On_Demand | Running]) – C:\Windows\system32\DRIVERS\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (PSDFilter [Boot | Running]) – C:\Windows\system32\DRIVERS\psdfilter.sys (Egis Incorporated)
DRV - (PSDNServ [Auto | Running]) – C:\Windows\system32\DRIVERS\PSDNServ.sys (Egis Incorporated)
DRV - (psdvdisk [Auto | Running]) – C:\Windows\system32\DRIVERS\PSDVdisk.sys (Egis Incorporated)
DRV - (PTDMBus [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\PTDMBus.sys (DEVGURU Co,LTD.)
DRV - (PTDMMdm [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\PTDMMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDMVsp [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\PTDMVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDMWWAN [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\PTDMWWAN.sys (DEVGURU Co,LTD.)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (SNP2UVC [On_Demand | Running]) – C:\Windows\system32\DRIVERS\snp2uvc.sys ()
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (winachsf [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio [Auto | Running]) – C:\Windows\system32\DRIVERS\xaudio.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {1650a312-02bc-40ee-977e-83f158701739}:26.6
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8


FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/04/29 09:26:05 | 00,000,000 | —D | M]

[2009/04/11 13:49:07 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\mozilla\Extensions
[2009/04/11 13:49:07 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/28 08:43:19 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\mozilla\Firefox\Profiles\v7fl1owx.default\extensions
[2009/04/28 08:43:20 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\mozilla\Firefox\Profiles\v7fl1owx.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Key error. File not found
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (HiTRUST)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [Acer Product Registration] "C:\Program Files\Acer\Acer Registration\ACE1.exe" /startup (Leader Technologies)
O4 - HKLM..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe File not found
O4 - HKLM..\Run: [AlltelWiFi] C:\Program Files\Alltel\AlltelWiFi\Alltel.lnk ()
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe (Egis Incorporated)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [Persistence] C:\Windows\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\Windows\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [RtHDVCpl] RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SetPanel] C:\Acer\APanel\APanel.cmd File not found
O4 - HKLM..\Run: [Skytel] Skytel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O4 - Startup: C:\Users\Flash Cadillac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe ()
O4 - Startup: C:\Users\Flash Cadillac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orion.lnk = C:\Convesoft\Orion\Messenger.exe (Convesoft)
O4 - Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk = C:\Acer\Empowering Technology\eAPLauncher.exe (Acer Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 5 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\system32\igfxdev.dll (Intel Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 00,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/05/01 14:19:50 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Users\Flash Cadillac\Desktop\OTListIt2.exe
[2009/05/01 14:16:06 | 00,000,822 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/01 14:16:05 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/05/01 14:16:03 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/05/01 14:16:02 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/01 12:44:53 | 10,632,47872 | -HS- | C] () – C:\hiberfil.sys
[2009/05/01 12:43:36 | 00,000,000 | —D | C] – C:\HJT
[2009/04/30 20:10:08 | 00,000,000 | —D | C] – C:\Users\Flash Cadillac\AppData\Roaming\Malwarebytes
[2009/04/30 16:58:17 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/04/30 16:56:36 | 00,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2009/04/30 16:54:28 | 00,000,000 | —D | C] – C:\ProgramData\TEMP
[2009/04/30 16:54:23 | 00,000,816 | —- | C] () – C:\Users\Flash Cadillac\Desktop\SpywareBlaster.lnk
[2009/04/30 16:54:22 | 01,071,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSCOMCTL.OCX
[2009/04/30 16:54:22 | 00,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSSTDFMT.DLL
[2009/04/30 16:54:22 | 00,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2009/04/30 16:37:19 | 00,000,000 | —D | C] – C:\tmp
[2009/04/29 09:20:35 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/04/29 09:20:33 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/04/29 09:20:32 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/04/29 09:20:32 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/04/29 09:20:32 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/04/29 09:20:32 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/04/29 09:20:28 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/04/29 09:20:25 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/04/29 09:07:29 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/04/29 09:07:24 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/04/29 09:07:22 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/04/29 09:07:05 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/04/29 09:07:01 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/04/28 09:21:42 | 00,135,759 | —- | C] () – C:\Users\Flash Cadillac\Documents\its me.jpg
[2009/04/25 16:59:47 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Uninstall
[2009/04/25 16:59:22 | 00,000,000 | —D | C] – C:\Program Files\PAV
[2009/04/15 14:19:43 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winhttp.dll
[2009/04/15 14:19:39 | 00,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/04/15 14:19:38 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2009/04/15 14:19:27 | 03,599,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2009/04/15 14:19:27 | 00,551,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcss.dll
[2009/04/15 14:19:26 | 03,547,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2009/04/15 14:19:23 | 00,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2009/04/15 14:19:22 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2009/04/15 14:19:20 | 00,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/04/15 14:19:20 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/04/15 14:19:20 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/04/15 14:19:19 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/04/15 14:19:19 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashost.exe
[2009/04/15 14:19:11 | 01,255,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2009/04/15 14:19:11 | 00,888,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kernel32.dll
[2009/04/15 14:19:09 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secur32.dll
[2009/04/15 14:19:08 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2009/04/15 14:19:08 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2009/04/11 13:48:44 | 00,000,000 | —D | C] – C:\Users\Flash Cadillac\AppData\Roaming\Mozilla
[2009/04/11 12:53:10 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmled.dll
[2009/04/11 12:53:09 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/04/11 12:53:09 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/04/11 12:53:09 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardie.dll
[2009/04/11 12:53:09 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/04/11 12:53:09 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/04/11 12:53:08 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2009/04/11 12:53:08 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2009/04/11 12:53:08 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tdc.ocx
[2009/04/11 12:53:08 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/04/11 12:53:08 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2009/04/11 12:53:07 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/04/11 12:53:07 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/04/11 12:53:07 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/04/11 12:53:07 | 00,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/04/11 12:53:07 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2009/04/11 12:53:06 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webcheck.dll
[2009/04/11 12:53:06 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/04/11 12:53:06 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2009/04/11 12:53:06 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/04/11 12:53:06 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2009/04/11 12:53:06 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/04/11 12:53:06 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2009/04/11 12:53:05 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/04/11 12:53:05 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2009/04/11 12:53:05 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/04/11 12:53:05 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/04/11 12:53:05 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2009/04/11 12:53:05 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/04/11 12:53:04 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/04/11 12:53:04 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/04/11 12:53:04 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/04/11 12:53:03 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/04/11 12:53:02 | 00,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/04/11 12:53:02 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2009/04/11 12:53:02 | 00,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2009/04/11 12:53:01 | 00,391,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/04/11 12:53:01 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2009/04/11 12:52:58 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/04/11 12:52:58 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2009/04/11 12:52:58 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshta.exe
[2009/04/11 12:52:57 | 03,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/04/11 12:52:57 | 00,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/04/11 12:52:57 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2009/04/11 12:52:57 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/04/11 12:52:57 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2009/04/11 12:52:57 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2009/04/11 12:52:57 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2009/04/11 12:52:56 | 01,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/04/11 12:52:56 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/04/11 12:52:55 | 01,206,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/04/11 12:52:55 | 00,914,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/04/11 12:52:51 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/04/11 12:52:40 | 11,063,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/04/11 12:52:38 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2008/11/01 06:32:46 | 00,000,002 | —- | C] () – C:\Windows\msoffice.ini
[2008/04/12 02:02:08 | 00,000,030 | —- | C] () – C:\Windows\SETPANEL.INI
[2008/04/12 02:02:04 | 00,000,092 | —- | C] () – C:\Windows\CLEANUP.INI
[2008/04/12 01:24:59 | 01,749,376 | —- | C] () – C:\Windows\System32\snp2uvc.sys
[2008/04/12 01:24:59 | 00,172,032 | —- | C] ( ) – C:\Windows\System32\rsnp2uvc.dll
[2008/04/12 01:24:59 | 00,028,032 | —- | C] () – C:\Windows\System32\sncduvc.sys
[2008/04/12 01:24:58 | 00,053,248 | —- | C] ( ) – C:\Windows\System32\csnp2uvc.dll
[2008/04/12 01:24:58 | 00,000,131 | —- | C] () – C:\Windows\System32\PidList.ini
[2008/03/21 13:59:03 | 00,001,024 | RH– | C] () – C:\Windows\System32\NTIBUN4.dll
[2008/03/21 12:40:11 | 00,065,536 | —- | C] () – C:\Windows\System32\NATTraversal.dll
[2008/03/21 12:35:54 | 00,015,656 | —- | C] () – C:\Windows\System32\drivers\int15_64.sys
[2008/03/21 11:31:32 | 00,001,694 | —- | C] () – C:\Windows\RtDefLvl.ini
[2008/03/21 11:07:47 | 01,749,376 | —- | C] () – C:\Windows\System32\drivers\snp2uvc.sys
[2008/03/21 11:07:47 | 00,028,032 | —- | C] () – C:\Windows\System32\drivers\sncduvc.sys
[2008/03/21 11:07:47 | 00,000,131 | —- | C] () – C:\Windows\PidList.ini
[2008/03/21 11:07:35 | 01,953,696 | —- | C] () – C:\Windows\System32\igklg400.dll
[2008/03/21 11:07:35 | 01,533,360 | —- | C] () – C:\Windows\System32\igklg450.dll
[2008/03/21 11:07:35 | 00,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1409.dll
[2008/03/21 11:07:35 | 00,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2006/11/02 06:23:31 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 06:23:31 | 00,000,144 | —- | C] () – C:\Windows\win.ini
[2006/11/02 03:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2001/12/26 18:12:30 | 00,065,536 | —- | C] () – C:\Windows\System32\multiplex_vcd.dll
[2001/09/04 01:46:38 | 00,110,592 | —- | C] () – C:\Windows\System32\Hmpg12.dll
[2001/07/30 18:33:56 | 00,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC.dll
[2001/07/24 00:04:36 | 00,118,784 | —- | C] () – C:\Windows\System32\HMPV2_ENC_MMX.dll

========== Files - Modified Within 30 Days ==========

[2009/05/01 14:19:52 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Users\Flash Cadillac\Desktop\OTListIt2.exe
[2009/05/01 14:16:06 | 00,000,822 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/01 14:05:40 | 00,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/05/01 14:05:40 | 00,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/05/01 14:05:25 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/05/01 14:05:18 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/05/01 14:05:14 | 10,632,47872 | -HS- | M] () – C:\hiberfil.sys
[2009/05/01 12:30:54 | 21,290,3757 | —- | M] () – C:\Windows\MEMORY.DMP
[2009/05/01 12:27:15 | 00,304,720 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/04/30 16:54:23 | 00,000,816 | —- | M] () – C:\Users\Flash Cadillac\Desktop\SpywareBlaster.lnk
[2009/04/30 16:37:44 | 00,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/04/30 16:37:44 | 00,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/04/30 16:37:44 | 00,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/04/28 09:21:50 | 00,135,759 | —- | M] () – C:\Users\Flash Cadillac\Documents\its me.jpg
[2009/04/06 10:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mrt.exe

========== LOP Check ==========

[2009/04/30 20:10:08 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming
[2008/11/14 02:25:50 | 00,000,000 | -HSD | M] – C:\Users\Flash Cadillac\AppData\Roaming\.#
[2008/08/09 04:17:13 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\Acer
[2008/03/21 12:58:52 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\Acer GameZone Console
[2008/08/09 13:17:17 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\Adobe
[2008/11/01 06:32:47 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\AOL
[2008/08/12 20:06:33 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\CyberLink
[2008/08/08 19:06:29 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\Google
[2008/08/09 04:15:59 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\Identities
[2008/08/09 04:17:06 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\Leadertech
[2008/08/09 04:14:07 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\Macromedia
[2009/04/30 20:10:08 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\Malwarebytes
[2009/04/29 18:40:08 | 00,000,000 | –SD | M] – C:\Users\Flash Cadillac\AppData\Roaming\Microsoft
[2009/04/11 13:49:07 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\Mozilla
[2009/04/30 21:02:56 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\OpenOffice.org2
[2008/08/16 13:58:34 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\Smith Micro
[2008/08/28 00:13:49 | 00,000,000 | —D | M] – C:\Users\Flash Cadillac\AppData\Roaming\Yahoo!
[2009/05/01 14:05:25 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/05/01 14:04:30 | 00,032,564 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >
Hi wbocock,

I must ask the obvious question…did you use right click and run as Adminstrator when you tried to run MBAM?

Next, let's look deeper. Download Rooter.exe to your desktop
  • Then right click Rooter.exe and chose Run as Adminstrator to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows). Post that in your next reply.

Thanks
Here's the Rooter log you requested. I did right click and try running Mbam as Admin after I renamed it, it did start, I tried to update it, it downloaded the update, then closed and did not come up again. Microsoft Windows Vista Home Edition (6.0.6001) Service Pack 1 C:\ [Fixed] - NTFS - (Total:70423 Mo/Free:2958 Mo) D:\ [Fixed] - NTFS - (Total:70207 Mo/Free:484 Mo) E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) F:\ [Removable] (Total:961 Mo/Free:786 Mo) Fri 05/01/2009|16:11 ———————-\\ Processes.. –Locked– [System Process] –Locked– System ———- \SystemRoot\System32\smss.exe ———- C:\Windows\system32\csrss.exe ———- C:\Windows\system32\wininit.exe ———- C:\Windows\system32\csrss.exe ———- C:\Windows\system32\services.exe ———- C:\Windows\system32\lsass.exe ———- C:\Windows\system32\lsm.exe ———- C:\Windows\system32\winlogon.exe ———- C:\Windows\system32\svchost.exe ———- C:\Windows\system32\svchost.exe ———- C:\Windows\System32\svchost.exe ———- C:\Windows\System32\svchost.exe ———- C:\Windows\System32\svchost.exe ———- C:\Windows\system32\svchost.exe –Locked– audiodg.exe ———- C:\Windows\system32\svchost.exe ———- C:\Windows\system32\SLsvc.exe ———- C:\Windows\system32\svchost.exe ———- C:\Windows\system32\svchost.exe ———- C:\Windows\System32\spoolsv.exe ———- C:\Windows\system32\svchost.exe ———- C:\Windows\system32\taskeng.exe ———- C:\Windows\system32\Dwm.exe ———- C:\Windows\Explorer.EXE ———- C:\Windows\system32\taskeng.exe ———- C:\Program Files\Windows Defender\MSASCui.exe ———- C:\Windows\RtHDVCpl.exe ———- C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe ———- C:\Program Files\Acer\Acer Arcade\PCMService.exe ———- C:\Windows\System32\hkcmd.exe ———- C:\Windows\System32\igfxpers.exe ———- C:\Windows\system32\igfxsrvc.exe ———- C:\Users\FLASHC~1\AppData\Local\Temp\RtkBtMnt.exe ———- C:\Windows\system32\agrsmsvc.exe ———- C:\Acer\ALaunch\ALaunchSvc.exe ———- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe ———- C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe ———- C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe ———- C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe ———- C:\Acer\Empowering Technology\eNet\eNet Service.exe ———- C:\Program Files\Common Files\LightScribe\LSSrvc.exe ———- C:\Acer\Mobility Center\MobilityService.exe ———- C:\Windows\system32\svchost.exe ———- C:\Windows\system32\svchost.exe ———- C:\Windows\System32\svchost.exe ———- C:\Windows\system32\SearchIndexer.exe ———- C:\Windows\system32\DRIVERS\xaudio.exe ———- C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe ———- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe ———- C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe ———- C:\Acer\Empowering Technology\ePower\ePowerSvc.exe ———- C:\Windows\system32\wbem\wmiprvse.exe ———- C:\Windows\system32\wbem\wmiprvse.exe ———- C:\Windows\system32\wbem\unsecapp.exe ———- C:\Program Files\Windows Media Player\wmpnscfg.exe ———- C:\Program Files\Windows Media Player\wmpnetwk.exe ———- C:\Program Files\Launch Manager\LManager.exe ———- C:\Program Files\Apoint2K\Apoint.exe ———- C:\Program Files\Alltel\AlltelWiFi\AlltelWiFi.exe ———- C:\Program Files\Java\jre6\bin\jusched.exe ———- C:\Program Files\Windows Sidebar\sidebar.exe ———- C:\Windows\system32\igfxext.exe ———- C:\Windows\system32\igfxsrvc.exe ———- C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe ———- C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE ———- C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE ———- C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE ———- C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE ———- C:\Program Files\Apoint2K\ApMsgFwd.exe ———- C:\Program Files\Apoint2K\Apntex.exe ———- C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe ———- C:\Program Files\Internet Explorer\Iexplore.exe ———- C:\Program Files\Internet Explorer\Iexplore.exe ———- C:\Program Files\Internet Explorer\Iexplore.exe ———- C:\Program Files\Internet Explorer\Iexplore.exe ———- C:\Windows\system32\WUDFHost.exe ———- C:\Program Files\Internet Explorer\Iexplore.exe ———- C:\Program Files\Internet Explorer\Iexplore.exe ———- C:\Windows\system32\SearchProtocolHost.exe ———- C:\Windows\system32\SearchFilterHost.exe ———- C:\Windows\system32\SearchProtocolHost.exe ———- C:\Windows\system32\DllHost.exe ———- C:\Windows\system32\DllHost.exe ———- C:\Windows\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! 1 - "C:\Rooter$\Rooter_1.txt" - Fri 05/01/2009|16:12 ———————-\\ Scan completed at 16:12
Hi wbocock,

Before we throw something heavy at this, what happened to McAfee? Was it uninstalled or did it get disabled?



Download OTScanit2 to your Desktop and rigt click (run as adminstrator) on it to extract the files. It will create a folder named OTScanIt on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanit folder and right click on OTScanit.exe select Run as Adminstrator to start the program.
  • Check the box that says Scan All Users
  • Check the Radio button for Rootkit check YES
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Note: if it is to large to attach then upload to Mediafire and post the sharing link in your next reply.

Thanks
Hi wbocock,

Let's get rid of the McAfee then. It's only partialy uninstalled and may be causing problems.

Please download the Mcafee removal tool from
HERE
  • Save it to your desktop
  • Make sure all McAfee application windows are closed.
  • Double-click MCPR.exe and the removal tool will start automatically.
  • Note: Windows Vista users must right-click and select Run as Administrator.
    Once the removal tool is finished, you will be prompted to restart your computer. If you choose to restart later, your McAfee product will not be fully removed until you do.
  • Wait for the computer to restart.

Next

Back up your registry with ERUNT
  • Download ERUNT from Here and save it to your desktop.
  • Right click erunt-setup.exe and select Run as Administrator to install the program
  • Follow the prompts, and then uncheck Create NTREGOPT desktop icon at the Additional Tasks screen.
  • Click No when you are prompted about creating an ERUNT entry in the startup folder.
  • At the next screen, uncheck Show documentation and check Launch ERUNT
  • If ERUNT doesn't start by itself, launch it from the desktop shortcut.
  • At the configuration screen, make sure all 3 checkboxes are checked
  • Click Ok to run the backup process

It is vitally important that combofix is renamed before it is even started to download


Download ComboFix from one of these locations:

Link 1
Link 2
Link 3
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log and a new HJT (hijackthis) log.

Thanks
Here are the new HJT log and Combofix log. The Mcafee removal tool didn't run, at least it didn't appear to. I ran it as administrator, it seemed to start then nothing happened. I waited a few minutes and checked in task manager and didn't see it. I started it again, it appeared to start again then I got a message from windows that it ended improperly. The registry backup ran successfully though.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:38:28 PM, on 5/2/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.exe
C:\HJT\HijackThis.exe
C:\Windows\system32\WerCon.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [AlltelWiFi] C:\Program Files\Alltel\AlltelWiFi\Alltel.lnk
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: Orion.lnk = C:\Convesoft\Orion\Messenger.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{155520D7-C049-4223-A4A3-643C520DA4E2}: NameServer = 75.116.127.154 75.116.63.154
O17 - HKLM\System\CS1\Services\Tcpip\..\{155520D7-C049-4223-A4A3-643C520DA4E2}: NameServer = 75.116.127.154 75.116.63.154
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\Program Files\McAfee\VirusScan\McShield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 7061 bytes
ComboFix 09-05-02.4 - Flash Cadillac 05/02/2009 17:31.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1013.363 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Flash Cadillac\AppData\Roaming\.#
c:\users\Flash Cadillac\Documents\My Documents.url
c:\windows\system32\drivers\UACcpapiuqvvmeesrh.sys
c:\windows\system32\UACaqmtcerpbxrmfry.dat
c:\windows\system32\UACbixnrphjtdivona.dll
c:\windows\system32\UACcsootlrrnyptbvl.dll
c:\windows\system32\UACdffkopleibcuwie.log
c:\windows\system32\UACefieupjwmfrssbs.dll
c:\windows\system32\UACegwpmqfqjohvxgn.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACmtbyogmxpxmofsw.dll
c:\windows\system32\UACvneuvdlwccxnevy.dll
c:\windows\system32\UACwucmnsqyyufffsm.log
c:\windows\system32\x64
c:\windows\system32\x64\csnp2uvc.dll
c:\windows\system32\x64\rsnpvc64.dll
c:\windows\system32\x64\sncduvc.sys
c:\windows\system32\x64\snp2uvc.sys
c:\windows\system32\x64\vsnpvc64.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-04-02 to 2009-05-02 )))))))))))))))))))))))))))))))
.

2009-05-02 20:49 . 2009-05-02 20:49 ——– d—–w c:\program files\ERUNT
2009-05-01 20:11 . 2009-05-01 20:12 ——– d—–w C:\Rooter$
2009-05-01 18:16 . 2009-02-11 14:19 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-01 18:16 . 2009-02-11 14:19 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-01 18:16 . 2009-05-01 18:16 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-01 16:43 . 2009-05-01 16:50 ——– d—–w C:\HJT
2009-05-01 00:10 . 2009-05-01 00:10 ——– d—–w c:\users\Flash Cadillac\AppData\Roaming\Malwarebytes
2009-04-30 20:58 . 2009-04-30 20:58 ——– d—–w c:\programdata\Malwarebytes
2009-04-30 20:58 . 2009-04-30 20:58 ——– d—–w c:\users\All Users\Malwarebytes
2009-04-30 20:56 . 2009-05-01 18:05 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-04-30 20:54 . 2009-05-01 18:10 ——– d—a-w c:\programdata\TEMP
2009-04-30 20:54 . 2009-05-01 18:10 ——– d—a-w c:\users\All Users\TEMP
2009-04-30 20:54 . 2005-08-25 23:18 118784 —-a-w c:\windows\system32\MSSTDFMT.DLL
2009-04-30 20:54 . 2009-05-01 00:07 ——– d—–w c:\program files\SpywareBlaster
2009-04-30 20:37 . 2009-05-01 16:43 ——– d—–w C:\tmp
2009-04-29 13:20 . 2008-06-20 01:14 97800 —-a-w c:\windows\system32\infocardapi.dll
2009-04-29 13:20 . 2008-06-20 01:14 105016 —-a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-04-29 13:20 . 2008-06-20 01:14 622080 —-a-w c:\windows\system32\icardagt.exe
2009-04-29 13:20 . 2008-06-20 01:14 11264 —-a-w c:\windows\system32\icardres.dll
2009-04-29 13:20 . 2008-06-20 01:14 43544 —-a-w c:\windows\system32\PresentationHostProxy.dll
2009-04-29 13:20 . 2008-06-20 01:14 781344 —-a-w c:\windows\system32\PresentationNative_v0300.dll
2009-04-29 13:20 . 2008-06-20 01:14 326160 —-a-w c:\windows\system32\PresentationHost.exe
2009-04-29 13:07 . 2008-07-27 18:03 96760 —-a-w c:\windows\system32\dfshim.dll
2009-04-29 13:07 . 2008-07-27 18:03 282112 —-a-w c:\windows\system32\mscoree.dll
2009-04-29 13:07 . 2008-07-27 18:03 41984 —-a-w c:\windows\system32\netfxperf.dll
2009-04-29 13:07 . 2008-07-27 18:03 158720 —-a-w c:\windows\system32\mscorier.dll
2009-04-29 13:07 . 2008-07-27 18:03 83968 —-a-w c:\windows\system32\mscories.dll
2009-04-25 20:59 . 2009-05-01 17:06 ——– d—–w c:\program files\Common Files\Uninstall
2009-04-25 20:59 . 2009-05-01 17:06 ——– d—–w c:\program files\PAV
2009-04-11 17:48 . 2009-04-11 17:48 ——– d—–w c:\users\Flash Cadillac\AppData\Local\Mozilla
2009-04-11 16:52 . 2009-03-08 11:31 45568 —-a-w c:\windows\system32\mshta.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-02 21:30 . 2006-11-02 12:58 6 —ha-w c:\windows\Tasks\SA.DAT
2009-05-01 16:35 . 2008-08-11 11:51 1356 —-a-w c:\users\Flash Cadillac\AppData\Local\d3d9caps.dat
2009-04-29 14:17 . 2008-03-21 16:49 ——– d—–w c:\program files\Acer GameZone
2009-04-28 21:31 . 2008-03-21 17:05 ——– d—–w c:\program files\Yahoo!
2009-04-19 07:16 . 2006-11-02 11:18 ——– d—–w c:\program files\Windows Mail
2009-04-01 02:54 . 2008-08-09 17:13 ——– d—–w c:\program files\Common Files\Adobe
2009-03-17 03:38 . 2009-04-15 18:19 40960 —-a-w c:\windows\AppPatch\apihex86.dll
2009-03-17 03:38 . 2009-04-15 18:19 13824 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 18:19 24064 —-a-w c:\windows\system32\amxread.dll
2009-03-13 03:12 . 2009-02-15 18:13 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-13 03:12 . 2008-08-08 20:12 ——– d—–w c:\program files\Java
2009-03-08 11:34 . 2009-04-11 16:52 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-04-11 16:53 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-04-11 16:53 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-04-11 16:52 109056 —-a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-04-11 16:52 109568 —-a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-04-11 16:52 132608 —-a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-04-11 16:52 107520 —-a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-04-11 16:52 107008 —-a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-04-11 16:52 103936 —-a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-04-11 16:53 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-04-11 16:53 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-04-11 16:53 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-04-11 16:53 66560 —-a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-04-11 16:52 169472 —-a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-04-11 16:53 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-04-11 16:53 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:22 . 2009-04-11 16:53 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-03 04:46 . 2009-04-15 18:19 3599328 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-15 18:19 3547632 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:39 . 2009-04-15 18:19 183296 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-15 18:19 551424 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-15 18:19 26112 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-15 18:19 98304 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-15 18:19 44032 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 04:37 . 2009-04-15 18:19 54784 —-a-w c:\windows\system32\iasads.dll
2009-03-03 03:04 . 2009-04-15 18:19 666624 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-15 18:19 17408 —-a-w c:\windows\system32\iashost.exe
2009-02-13 08:49 . 2009-04-15 18:19 72704 —-a-w c:\windows\system32\secur32.dll
2009-02-13 08:49 . 2009-04-15 18:19 1255936 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 03:10 . 2009-03-11 19:18 2033152 —-a-w c:\windows\system32\win32k.sys
2008-01-21 02:57 . 2006-11-02 12:48 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-01-03 09:00 39472 —-a-w c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-12 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-05 525360]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2008-01-25 155648]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-22 133656]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-01-04 768520]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-07-21 159744]
"Acer Product Registration"="c:\program files\Acer\Acer Registration\ACE1.exe" [2007-11-26 3387392]
"Acer Assist Launcher"="c:\program files\Acer\Acer Assist\launcher.exe" [2007-11-19 1261568]
"AlltelWiFi"="c:\program files\Alltel\AlltelWiFi\Alltel.lnk" [2008-11-19 2413]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-13 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-03-11 5296128]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-11-20 1826816]

c:\users\Flash Cadillac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-7-14 393216]
Orion.lnk - c:\convesoft\Orion\Messenger.exe [2007-9-5 2482176]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2008-3-21 535336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EE668238-02BC-4FD8-83A9-1437F276980E}"= c:\program files\Acer\Acer Arcade\PowerCinema.exe:CyberLink PowerCinema
"{2CDCDA02-E919-4AFE-930B-EC2244E54711}"= c:\program files\Acer\Acer Arcade\PCMService.exe:CyberLink PowerCinema Resident Program
"{760B2901-463D-4E36-B6EC-DF21768B58F9}"= c:\program files\Acer\Acer Arcade\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{CDC33473-8B04-4DAE-AFD0-7C554D50E101}"= c:\program files\Acer\Acer Arcade\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{5E1CE298-0D49-4CC6-B058-C4A89EF9D813}"= c:\program files\Acer\HomeMedia\HomeMedia.exe:HomeMedia
"{06326A26-3C5A-419D-87E9-B7D42F6D82E5}"= UDP:c:\program files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{7BE917ED-58E2-4523-B35D-A3BBC71F0FD8}"= TCP:c:\program files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{3F238F56-7B09-471B-A1F2-5FCAB725E61F}"= UDP:c:\program files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service
"{EFD54762-4763-4C88-A352-70C01F52FD3B}"= TCP:c:\program files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service
"{2D6EC3BC-38D9-4C83-99A2-B6649CFEF9D0}"= UDP:c:\program files\Common Files\aol\1218750347\ee\aolsoftware.exe:AOL Shared Components
"{11EAE10D-8E63-4AF3-A30E-81D3A20302F9}"= TCP:c:\program files\Common Files\aol\1218750347\ee\aolsoftware.exe:AOL Shared Components
"{83A5A6F8-44F5-471A-BBE6-75AC318CF18A}"= UDP:c:\program files\AOL 9.1\waol.exe:AOL
"{41FA7C23-3216-4304-BE50-D47C04B14589}"= TCP:c:\program files\AOL 9.1\waol.exe:AOL
"{9417B284-3A29-42DA-A012-D48C089599AC}"= UDP:c:\program files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{6C3A78C4-E1B7-4BDB-8E9F-7338796FBB3E}"= TCP:c:\program files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{176A1615-1396-4AE5-B898-BB224EE13527}"= UDP:c:\program files\Common Files\aol\Loader\aolload.exe:AOL Loader
"{805B53AD-6E7F-496A-99B9-154877AAD1AB}"= TCP:c:\program files\Common Files\aol\Loader\aolload.exe:AOL Loader
"{13DB4A83-AE77-4992-9618-379BB8193AC5}"= UDP:c:\program files\Common Files\aol\System Information\sinf.exe:AOL System Information
"{84F3D11B-50B7-4E1B-99E9-4D5AC609EBEB}"= TCP:c:\program files\Common Files\aol\System Information\sinf.exe:AOL System Information
"{676A6E87-4F5D-404B-87DA-30BC405D8A9C}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{0EA5B12D-7631-464C-AEF2-D0FF969FBB50}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger

R3 PTDMBus;PANTECH USB Modem Composite Device Driver ;c:\windows\system32\DRIVERS\PTDMBus.sys [2007-08-18 29952]
R3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\DRIVERS\PTDMMdm.sys [2007-08-18 41856]
R3 PTDMVsp;PANTECH USB Modem Serial Port ;c:\windows\system32\DRIVERS\PTDMVsp.sys [2007-08-18 39936]
R3 PTDMWWAN;PANTECH USB Modem WWAN Driver;c:\windows\system32\DRIVERS\PTDMWWAN.sys [2007-08-18 59520]
S2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-09-19 51200]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-07-22 180736]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKLM-Run-ALaunch - c:\acer\ALaunch\AlaunchClient.exe
HKLM-Run-Acer Tour Reminder - c:\acer\AcerTour\Reminder.exe
HKLM-Run-SetPanel - c:\acer\APanel\APanel.cmd
HKLM-Run-eRecoveryService - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.drudgereport.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {155520D7-C049-4223-A4A3-643C520DA4E2} = 75.116.127.154 75.116.63.154
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-02 17:34
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-05-02 17:36
ComboFix-quarantined-files.txt 2009-05-02 21:36

Pre-Run: 46,546,198,528 bytes free
Post-Run: 46,685,302,784 bytes free

256 — E O F — 2009-05-01 16:50
Hi wbocock,

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
Do Not copy the word CODE

KillAll:

Folder::
c:\program files\PAV

DirLook::
c:\program files\Common Files\Uninstall

Reglock:: 
[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]

Registry::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]



Next

Try running MBAM again.

Please post back with
  • combofix log
  • MBAM log
  • new HJT log.

How's the computer?

Thanks
Here are the new logs. The computer seems to be much better, the PAV pop-ups are gone, I was able to get Mbam updated and ran a scan with it also.

ComboFix 09-05-02.4 - Flash Cadillac 05/03/2009 10:43.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1013.212 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\users\Flash Cadillac\Desktop\CFScript.txt
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\PAV

.
((((((((((((((((((((((((( Files Created from 2009-04-03 to 2009-05-03 )))))))))))))))))))))))))))))))
.

2009-05-02 20:49 . 2009-05-02 20:49 ——– d—–w c:\program files\ERUNT
2009-05-01 20:11 . 2009-05-01 20:12 ——– d—–w C:\Rooter$
2009-05-01 18:16 . 2009-02-11 14:19 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-01 18:16 . 2009-02-11 14:19 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-01 18:16 . 2009-05-01 18:16 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-01 16:43 . 2009-05-02 21:38 ——– d—–w C:\HJT
2009-05-01 00:10 . 2009-05-01 00:10 ——– d—–w c:\users\Flash Cadillac\AppData\Roaming\Malwarebytes
2009-04-30 20:58 . 2009-04-30 20:58 ——– d—–w c:\programdata\Malwarebytes
2009-04-30 20:58 . 2009-04-30 20:58 ——– d—–w c:\users\All Users\Malwarebytes
2009-04-30 20:56 . 2009-05-01 18:05 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-04-30 20:54 . 2009-05-01 18:10 ——– d—a-w c:\programdata\TEMP
2009-04-30 20:54 . 2009-05-01 18:10 ——– d—a-w c:\users\All Users\TEMP
2009-04-30 20:54 . 2005-08-25 23:18 118784 —-a-w c:\windows\system32\MSSTDFMT.DLL
2009-04-30 20:54 . 2009-05-01 00:07 ——– d—–w c:\program files\SpywareBlaster
2009-04-30 20:37 . 2009-05-01 16:43 ——– d—–w C:\tmp
2009-04-29 13:20 . 2008-06-20 01:14 97800 —-a-w c:\windows\system32\infocardapi.dll
2009-04-29 13:20 . 2008-06-20 01:14 105016 —-a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-04-29 13:20 . 2008-06-20 01:14 622080 —-a-w c:\windows\system32\icardagt.exe
2009-04-29 13:20 . 2008-06-20 01:14 11264 —-a-w c:\windows\system32\icardres.dll
2009-04-29 13:20 . 2008-06-20 01:14 43544 —-a-w c:\windows\system32\PresentationHostProxy.dll
2009-04-29 13:20 . 2008-06-20 01:14 781344 —-a-w c:\windows\system32\PresentationNative_v0300.dll
2009-04-29 13:20 . 2008-06-20 01:14 326160 —-a-w c:\windows\system32\PresentationHost.exe
2009-04-29 13:07 . 2008-07-27 18:03 96760 —-a-w c:\windows\system32\dfshim.dll
2009-04-29 13:07 . 2008-07-27 18:03 282112 —-a-w c:\windows\system32\mscoree.dll
2009-04-29 13:07 . 2008-07-27 18:03 41984 —-a-w c:\windows\system32\netfxperf.dll
2009-04-29 13:07 . 2008-07-27 18:03 158720 —-a-w c:\windows\system32\mscorier.dll
2009-04-29 13:07 . 2008-07-27 18:03 83968 —-a-w c:\windows\system32\mscories.dll
2009-04-25 20:59 . 2009-05-01 17:06 ——– d—–w c:\program files\Common Files\Uninstall
2009-04-11 17:48 . 2009-04-11 17:48 ——– d—–w c:\users\Flash Cadillac\AppData\Local\Mozilla
2009-04-11 16:52 . 2009-03-08 11:31 45568 —-a-w c:\windows\system32\mshta.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-03 14:46 . 2006-11-02 12:58 6 —ha-w c:\windows\Tasks\SA.DAT
2009-05-01 16:35 . 2008-08-11 11:51 1356 —-a-w c:\users\Flash Cadillac\AppData\Local\d3d9caps.dat
2009-04-29 14:17 . 2008-03-21 16:49 ——– d—–w c:\program files\Acer GameZone
2009-04-28 21:31 . 2008-03-21 17:05 ——– d—–w c:\program files\Yahoo!
2009-04-19 07:16 . 2006-11-02 11:18 ——– d—–w c:\program files\Windows Mail
2009-04-01 02:54 . 2008-08-09 17:13 ——– d—–w c:\program files\Common Files\Adobe
2009-03-17 03:38 . 2009-04-15 18:19 40960 —-a-w c:\windows\AppPatch\apihex86.dll
2009-03-17 03:38 . 2009-04-15 18:19 13824 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 18:19 24064 —-a-w c:\windows\system32\amxread.dll
2009-03-13 03:12 . 2009-02-15 18:13 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-13 03:12 . 2008-08-08 20:12 ——– d—–w c:\program files\Java
2009-03-08 11:34 . 2009-04-11 16:52 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-04-11 16:53 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-04-11 16:53 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-04-11 16:52 109056 —-a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-04-11 16:52 109568 —-a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-04-11 16:52 132608 —-a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-04-11 16:52 107520 —-a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-04-11 16:52 107008 —-a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-04-11 16:52 103936 —-a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-04-11 16:53 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-04-11 16:53 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-04-11 16:53 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-04-11 16:53 66560 —-a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-04-11 16:52 169472 —-a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-04-11 16:53 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-04-11 16:53 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:22 . 2009-04-11 16:53 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-03 04:46 . 2009-04-15 18:19 3599328 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-15 18:19 3547632 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:39 . 2009-04-15 18:19 183296 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-15 18:19 551424 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-15 18:19 26112 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-15 18:19 98304 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-15 18:19 44032 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 04:37 . 2009-04-15 18:19 54784 —-a-w c:\windows\system32\iasads.dll
2009-03-03 03:04 . 2009-04-15 18:19 666624 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-15 18:19 17408 —-a-w c:\windows\system32\iashost.exe
2009-02-13 08:49 . 2009-04-15 18:19 72704 —-a-w c:\windows\system32\secur32.dll
2009-02-13 08:49 . 2009-04-15 18:19 1255936 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 03:10 . 2009-03-11 19:18 2033152 —-a-w c:\windows\system32\win32k.sys
2008-01-21 02:57 . 2006-11-02 12:48 174 –sha-w c:\program files\desktop.ini
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of c:\program files\Common Files\Uninstall —-



((((((((((((((((((((((((((((( SnapShot@2009-05-02_21.35.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-05-03 14:38 58678 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-01-21 01:58 . 2009-05-02 13:57 58678 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:02 . 2009-05-03 14:38 78506 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-11 12:55 . 2009-05-02 21:40 3762 c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2008-08-11 12:55 . 2009-04-24 07:40 3762 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2008-08-09 08:15 . 2009-05-03 14:38 8148 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3645618677-2451694311-1706327001-1000_UserData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-01-03 09:00 39472 —-a-w c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-12 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-05 525360]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2008-01-25 155648]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-22 133656]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-01-04 768520]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-07-21 159744]
"Acer Product Registration"="c:\program files\Acer\Acer Registration\ACE1.exe" [2007-11-26 3387392]
"Acer Assist Launcher"="c:\program files\Acer\Acer Assist\launcher.exe" [2007-11-19 1261568]
"AlltelWiFi"="c:\program files\Alltel\AlltelWiFi\Alltel.lnk" [2008-11-19 2413]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-13 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-03-11 5296128]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-11-20 1826816]

c:\users\Flash Cadillac\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-7-14 393216]
Orion.lnk - c:\convesoft\Orion\Messenger.exe [2007-9-5 2482176]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2008-3-21 535336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EE668238-02BC-4FD8-83A9-1437F276980E}"= c:\program files\Acer\Acer Arcade\PowerCinema.exe:CyberLink PowerCinema
"{2CDCDA02-E919-4AFE-930B-EC2244E54711}"= c:\program files\Acer\Acer Arcade\PCMService.exe:CyberLink PowerCinema Resident Program
"{760B2901-463D-4E36-B6EC-DF21768B58F9}"= c:\program files\Acer\Acer Arcade\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{CDC33473-8B04-4DAE-AFD0-7C554D50E101}"= c:\program files\Acer\Acer Arcade\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{5E1CE298-0D49-4CC6-B058-C4A89EF9D813}"= c:\program files\Acer\HomeMedia\HomeMedia.exe:HomeMedia
"{06326A26-3C5A-419D-87E9-B7D42F6D82E5}"= UDP:c:\program files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{7BE917ED-58E2-4523-B35D-A3BBC71F0FD8}"= TCP:c:\program files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{3F238F56-7B09-471B-A1F2-5FCAB725E61F}"= UDP:c:\program files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service
"{EFD54762-4763-4C88-A352-70C01F52FD3B}"= TCP:c:\program files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service
"{2D6EC3BC-38D9-4C83-99A2-B6649CFEF9D0}"= UDP:c:\program files\Common Files\aol\1218750347\ee\aolsoftware.exe:AOL Shared Components
"{11EAE10D-8E63-4AF3-A30E-81D3A20302F9}"= TCP:c:\program files\Common Files\aol\1218750347\ee\aolsoftware.exe:AOL Shared Components
"{83A5A6F8-44F5-471A-BBE6-75AC318CF18A}"= UDP:c:\program files\AOL 9.1\waol.exe:AOL
"{41FA7C23-3216-4304-BE50-D47C04B14589}"= TCP:c:\program files\AOL 9.1\waol.exe:AOL
"{9417B284-3A29-42DA-A012-D48C089599AC}"= UDP:c:\program files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{6C3A78C4-E1B7-4BDB-8E9F-7338796FBB3E}"= TCP:c:\program files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{176A1615-1396-4AE5-B898-BB224EE13527}"= UDP:c:\program files\Common Files\aol\Loader\aolload.exe:AOL Loader
"{805B53AD-6E7F-496A-99B9-154877AAD1AB}"= TCP:c:\program files\Common Files\aol\Loader\aolload.exe:AOL Loader
"{13DB4A83-AE77-4992-9618-379BB8193AC5}"= UDP:c:\program files\Common Files\aol\System Information\sinf.exe:AOL System Information
"{84F3D11B-50B7-4E1B-99E9-4D5AC609EBEB}"= TCP:c:\program files\Common Files\aol\System Information\sinf.exe:AOL System Information
"{676A6E87-4F5D-404B-87DA-30BC405D8A9C}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{0EA5B12D-7631-464C-AEF2-D0FF969FBB50}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger

R3 PTDMBus;PANTECH USB Modem Composite Device Driver ;c:\windows\system32\DRIVERS\PTDMBus.sys [2007-08-18 29952]
R3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\DRIVERS\PTDMMdm.sys [2007-08-18 41856]
R3 PTDMVsp;PANTECH USB Modem Serial Port ;c:\windows\system32\DRIVERS\PTDMVsp.sys [2007-08-18 39936]
R3 PTDMWWAN;PANTECH USB Modem WWAN Driver;c:\windows\system32\DRIVERS\PTDMWWAN.sys [2007-08-18 59520]
S2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-09-19 51200]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-07-22 180736]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.drudgereport.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {155520D7-C049-4223-A4A3-643C520DA4E2} = 75.116.127.154 75.116.63.154
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-03 10:47
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(4748)
c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\acer\Empowering Technology\EPOWER\SysHook.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\audiodg.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
c:\program files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
c:\acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\windows\System32\drivers\XAudio.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\windows\System32\WUDFHost.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\acer\Empowering Technology\ePower\ePowerSvc.exe
c:\program files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Launch Manager\LManager.exe
c:\program files\Alltel\AlltelWiFi\AlltelWiFi.exe
c:\windows\System32\igfxext.exe
c:\windows\System32\igfxsrvc.exe
c:\windows\System32\igfxsrvc.exe
c:\acer\Empowering Technology\eNet\eNMTray.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\acer\Empowering Technology\ePower\ePower_DMC.exe
c:\acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
c:\users\FLASHC~1\AppData\Local\Temp\RtkBtMnt.exe
c:\acer\Empowering Technology\eRecovery\eRAgent.exe
c:\program files\Apoint2K\ApMsgFwd.exe
c:\program files\Apoint2K\ApntEx.exe
.
**************************************************************************
.
Completion time: 2009-05-03 10:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-03 14:51

Pre-Run: 46,722,375,680 bytes free
Post-Run: 46,594,342,912 bytes free

280 — E O F — 2009-05-01 16:50


Malwarebytes' Anti-Malware 1.36
Database version: 2070
Windows 6.0.6001 Service Pack 1

5/3/2009 11:41:55 AM
mbam-log-2009-05-03 (11-41-55).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 144670
Time elapsed: 39 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2e59498d-7e44-4452-9044-0973b080b9e8} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Qoobox\Quarantine\C\Windows\System32\UACbixnrphjtdivona.dll.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Windows\System32\UACefieupjwmfrssbs.dll.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Windows\System32\UACmtbyogmxpxmofsw.dll.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Windows\System32\UACvneuvdlwccxnevy.dll.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Users\Flash Cadillac\My Documents\My Music\My Music.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Users\Flash Cadillac\My Documents\My Pictures\My Pictures.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Users\Flash Cadillac\My Documents\My Videos\My Video.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Users\Flash Cadillac\Favorites\Antivirus Scan.url (Rogue.Link) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:48:44 AM, on 5/3/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Alltel\AlltelWiFi\AlltelWiFi.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Convesoft\Orion\Messenger.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Users\FLASHC~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [AlltelWiFi] C:\Program Files\Alltel\AlltelWiFi\Alltel.lnk
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: Orion.lnk = C:\Convesoft\Orion\Messenger.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{155520D7-C049-4223-A4A3-643C520DA4E2}: NameServer = 75.116.127.154 75.116.63.154
O17 - HKLM\System\CS1\Services\Tcpip\..\{155520D7-C049-4223-A4A3-643C520DA4E2}: NameServer = 75.116.127.154 75.116.63.154
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\Program Files\McAfee\VirusScan\McShield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 7876 bytes
Hi Wbocock,

Sound promising.

Did you run the McAfee removal tool?

Open hijackthis, do a system scan only and checkmark these lines, if present

O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\Program Files\McAfee\VirusScan\McShield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.


I'm not sure which version of java you have currently installed. I see you have downloaded the new version 6 Update 13 (jre-6u13-windows-i586-p.exe). If you have installed this version, please uninstall
  • Java™ 6 Update 12
    Java™ 6 Update 7
  • Do not uninstall Java TM 6 Update 13 if found! :yeah:


If you didn't install it yet and no longer have a copy of Java TM 6 Update 13, please follow these instructions.
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 13
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u13-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Open Control Panel > Add/Remove Programs:
  • Java™ 6 Update 12

    Java™ 6 Update 7
  • Do not uninstall Java TM 6 Update 13 if found! :yeah:
Reboot your computer.

  • Double-click on the saved file to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.

In order to run this next scan, as a Vista user you will need to launch Internet Explorer by Right clicking your Internet Explorer icon and select run as Administrator

Please do not surf anywhere except to the Kaspersky site to do the scan as your browser will have Adminstrator rights.

Please close the browser after the scan has completed and you have saved the results.

You will need to use Internet Explorer for this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply along with a new HijackThis log.

Please post back with the Kaspersky log and a new HJT log.

You should also be able to install Avast.

Thanks
I was finally able to get the Mcafee removal tool to run, so the entries didn't show up in HJT. I've installed the updated Java and uninstalled the older updates. I've also installed Avast and updated it. Here is the Kaspersky log and a new HJT log;

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Monday, May 4, 2009
Operating System: Microsoft Windows Vista Home Basic Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Monday, May 04, 2009 14:33:54
Records in database: 2128960
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 102762
Threat name: 2
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 01:16:22


File name / Threat name / Threats count
C:\Program Files\PKR\pkr.exe Infected: not-a-virus:Monitor.Win32.PKRPoker.e 1
C:\Qoobox\Quarantine\C\Windows\System32\UACcsootlrrnyptbvl.dll.vir Infected: Packed.Win32.Tdss.h 1

The selected area was scanned.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:07:05 AM, on 5/4/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\FLASHC~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Alltel\AlltelWiFi\AlltelWiFi.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Convesoft\Orion\Messenger.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Apoint2K\Apntex.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [AlltelWiFi] C:\Program Files\Alltel\AlltelWiFi\Alltel.lnk
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: Orion.lnk = C:\Convesoft\Orion\Messenger.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{155520D7-C049-4223-A4A3-643C520DA4E2}: NameServer = 75.116.127.154 75.116.63.154
O17 - HKLM\System\CS1\Services\Tcpip\..\{155520D7-C049-4223-A4A3-643C520DA4E2}: NameServer = 75.116.127.154 75.116.63.154
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 7489 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI