This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Split

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Not really sure whats going on with the computer, this may or may not be the correct sub forum to place this in, but perhaps an HJT log can help. Computer crashes frequently to a blue dos screen that says something along the lines of "apaxi.sys" error, I can't recall the exact word but its close I believe. Also when I try to reboot I frequently get a dos screen that says that windows didn't load correctly and asking if i want to revert to safe mode, the last known working configuration, or load windows anyways. If this topic needs to be moved then I apologize, otherwise I'm not quite sure what needs to be done. I was on here before and got help when it was TomCoyote, and I believe someone suggested not uploading certain attachments because they could be infected, so I hope the logs below are fine.

Also, forgot to mention, when it does reboot, it goes to a disk check screen and will never fully finish the check, usually freezes in the 3rd phase so I always have to skip the check. And I also use EndItAll when the system does load so that I can at least get some power and speed out of the machine.

HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:53:01 PM, on 4/20/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\QuickTime\qttask.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Winamp Remote\bin\Orb.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\ATF_Cleaner.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://broadband.zoomtown.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://broadband.zoomtown.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Road Runner High Speed Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Policies\Explorer\Run: [mwkqw.exe] C:\WINDOWS\system\mwkqw.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Add To Compaq Organize… - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184020652671
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin7USA.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 7549 bytes

_________________________________________

Malwarebytes' Anti-Malware 1.36
Database version: 2016
Windows 5.1.2600 Service Pack 2

4/20/2009 7:50:29 PM
mbam-log-2009-04-20 (19-50-29).txt

Scan type: Quick Scan
Objects scanned: 84208
Time elapsed: 12 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fb0e529a-3d2c-473e-83fe-9e56ac6cc0eb} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Broken.SecurityProviders) -> Bad: (msapsspc.dll schannel.dll digest.dll msnsspc.dll) Good: (msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi mcfarljd,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
OTListIt Extras logfile created on: 5/2/2009 12:34:56 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

447.48 Mb Total Physical Memory | 89.60 Mb Available Physical Memory | 20.02% Memory free
1.03 Gb Paging File | 0.76 Gb Available in Paging File | 74.01% Paging File free
Paging file location(s): C:\pagefile.sys 1344 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.22 Gb Total Space | 13.72 Gb Free Space | 7.53% Space Free | Partition Type: NTFS
Drive D: | 4.07 Gb Total Space | 0.69 Gb Free Space | 17.06% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 993.21 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KILLA_CHUBS
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.js [@ = JSFile] – C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\System32\CScript.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service
"10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10244:TCP" = 10244:TCP:LocalSubNet:Enabled:Zune Network Sharing Service
"10285:UDP" = 10285:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10286:UDP" = 10286:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10287:UDP" = 10287:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10288:UDP" = 10288:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10289:UDP" = 10289:UDP:LocalSubNet:Enabled:Zune Network Sharing Service
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"16001:TCP" = 16001:TCP:*:Enabled:BitComet 16001 TCP
"16001:UDP" = 16001:UDP:*:Enabled:BitComet 16001 UDP

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2006/10/30 10:36:32 | 15,338,560 | —- | M] (Apple Computer, Inc.) – C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
[2005/05/06 15:54:37 | 02,297,856 | —- | M] (www.BitComet.com) – C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client
[2008/04/15 08:54:29 | 00,510,976 | —- | M] (GRISOFT, s.r.o.) – C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe
[2008/04/04 01:52:29 | 00,418,816 | —- | M] (GRISOFT, s.r.o.) – C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe
[2008/04/15 08:54:29 | 00,579,584 | —- | M] (GRISOFT, s.r.o.) – C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe
[2008/04/04 01:52:36 | 00,406,528 | —- | M] (GRISOFT, s.r.o.) – C:\Program Files\Grisoft\AVG7\avgemc.exe:*:Enabled:avgemc.exe
[2004/08/10 11:37:28 | 00,061,440 | —- | M] (America Online, Inc.) – C:\Program Files\AIM\aim.exe:*:Disabled:AOL Instant Messenger
[2008/01/29 22:19:32 | 00,073,728 | —- | M] (Orb Networks, Inc.) – C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb
[2008/03/31 21:54:06 | 00,507,904 | —- | M] (Orb Networks) – C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray
[2008/03/27 21:00:24 | 05,844,992 | —- | M] (Orb Networks) – C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client
[2007/08/03 12:48:06 | 00,116,008 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Shared\NL3\NeroPatentActivation.exe:*:Disabled:NeroPatentActivation.exe
[2007/08/03 12:48:06 | 00,857,384 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Shared\NL3\NeroUpgrade.exe:*:Disabled:NeroUpgrade.exe
[2007/08/08 09:34:26 | 02,475,304 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Nero Web\SetupX.exe:*:Disabled:SetupX.exe
[2007/08/08 09:34:58 | 17,704,232 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\Nero StartSmart\NeroStartSmart.exe:*:Disabled:NeroStartSmart.exe
[2009/04/17 17:46:12 | 03,912,232 | —- | M] (Fengtao Software Inc.) – C:\Program Files\DVDFab 5\DVDFab.exe:*:Disabled:DVDFab 5

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0DC86BEC-5CE3-413A-BB61-C40A3D186B24}" = Scan
"{0F8F3415-CB0A-49A6-A23A-D8390444B127}" = DeadAIM
"{0FF18B53-CA57-40BB-B562-21A27B662005}" = 1600
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy
"{1526D87C-A955-4FAB-BF18-697BA457E352}" = Norton WMI Update
"{17293791-C82E-476C-9997-9A0FF234A19B}" = HP Product Assistant
"{181821B7-82AA-44DA-9DAF-EF254CCB670A}" = Fax
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1B680FBA-E317-4E93-AF43-3B59798A4BE0}" = Copy
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp
"{224C47F4-CB95-406C-8AD6-81002FEED0CF}" = Hoyle Casino 2004
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 12
"{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator 2
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{342C7C88-D335-4bc2-8CF1-281857629CE2}" = HP PSC & OfficeJet 4.7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{391E18CE-7D3B-45E9-A8F0-34E77F14F47A}" = ProductContext
"{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}" = DAEMON Tools
"{442BE28B-782B-4DC0-B490-E70A403B1C69}" = Readme
"{446DBFFA-4088-48E3-8932-74316BA4CAE4}" = iTunes
"{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{50D8FFDD-90CD-4859-841F-AA1961C7767A}" = QuickTime
"{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5DF3D1BB-894E-4DCD-8275-159AC9829B43}" = McAfee VirusScan Enterprise
"{5E06C076-E4E7-4239-A886-B3D8AC84C166}" = HP Print Diagnostic Utility
"{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{64FC0C98-B035-4530-B15D-3D30610B6DF1}" = HP Software Update
"{655CB07D-C944-40BE-B93F-55957CAC7625}" = AiO_Scan
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7169B8E4-2632-46B1-AA5F-167CB5FE5029}" = Symantec Network Drivers Update
"{71883667-71F2-48A1-AB72-28D518D8AC4A}" = Seagate Manager Installer
"{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}" = cp_dwShrek2Cards1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{76902AF9-DA86-419D-B533-077643124722}" = Sony ACID Pro 5.0
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{85CFD253-38AE-4DB1-ACB7-F0F4C791990D}" = AiOSoftware
"{870815CA-6B60-47B6-88DD-A67F42D2F03E}" = GPL MPEG-1/2 DirectShow Decoder Filter
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" =
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8AEA4BE2-2B52-41C0-BB7D-9F2D17AF1033}" = Nero 8
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = RecordNow!
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD Player
"{9DE9E293-5D7B-4312-88C2-BDFAEC5310AE}" = Microsoft .NET Framework 3.0
"{A0126FC5-B225-4EA2-B008-E88B65C38DE5}" = Screenblast VideoFactory 2.0a
"{A14F7508-B784-40B8-B11A-E0E2EEB7229F}" = Adobe Premiere Pro 1.5
"{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}" = Apple Software Update
"{A5B9D22C-755A-4AC6-9904-875E80838BB6}" = CP_AtenaShokunin1Config
"{A6359CCF-215D-43D9-8366-479D231F2A72}" = Belkin Wireless USB Utility
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A9212616-FCA2-4173-BD99-5C741EB3A068}" = Ulead DVD PictureShow 2 SE Basic
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B19FBD79-99BB-4878-93ED-7028E9C265EB}" = ViviCam 3765 Digital Camera Driver
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director
"{B9153993-0843-44AC-9074-75C833FD8CEC}" = ViviCam 3765(Documents)
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BBC0D330-C37B-4472-BFB9-AA217CF0C95F}" = Ulead Photo Express 4.0 SE
"{BD29EBAC-AD7D-4b27-B727-4CC6AC52D36B}" = MarketResearch
"{C278F05D-696C-4898-82AE-83886134BC12}" = PrintingPress
"{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}" = Microsoft Plus! Digital Media Edition
"{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus 2004
"{C86A8B40-0702-45FA-BFEC-82B0C5932038}" = Sony Media Manager 2.1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB449D5A-7710-47aa-B9F5-352B877C90E6}" = 1600_Help
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer
"{D0122362-6333-4DE4-93F6-A5A2F3CC101A}" = Compaq Organize
"{D271DAE0-8D68-4C97-8356-A126D48A1D8C}" = Ulead Photo Explorer 8.0 SE Basic
"{D6414CC7-F215-467F-88B1-546ED863F35B}" = CC_ccStart
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}" = ccCommon
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{E47EE8FB-ACC0-4608-859C-4E2851B18A6A}" = SymNet
"{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton AntiVirus Parent MSI
"{ED55BFEF-90F3-4926-9536-D94FDBBF65DC}" = Zune
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F4C6CC40-1142-49be-A28C-7BBD36F0B41A}" = 1600Trb
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates
"{FC37ABD0-2108-4beb-B010-1254E0662B5A}" = MSRedist
"6F128087AFFFF5D4F4FEE6429736470CD5C1E4E2" = Windows Driver Package - Microsoft WPD (12/01/2006 1.2.0.0)
"AC3Filter" = AC3Filter (remove only)
"Ad-aware 6 Professional" = Ad-aware 6 Professional
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AdobeESD" = Adobe Download Manager 2.0 (Remove Only)
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"AnyDVD" = AnyDVD
"AOL Instant Messenger" = AOL Instant Messenger
"AVG7Uninstall" = AVG 7.5
"BackWeb-1940576 Uninstaller" = Compaq Connections
"BitComet" = BitComet 0.58
"CCleaner" = CCleaner (remove only)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Compaq Instant Support" = Compaq Instant Support
"dBpowerAMP Music Converter" = dBpowerAMP Music Converter
"DC++" = DC++ 0.667
"Defraggler" = Defraggler (remove only)
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.1.4
"DVDFab Ghosthunter release_is1" = DVDFab Ghosthunter release 5.3.5.0
"dvdSanta 4.00 - Create Your Own DVD Movies!_is1" = dvdSanta 4.00
"DVDXCopy" = DVDXCopy 1.2.1 b628 (remove only)
"EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 3.5 Home Edition
"EphPod" = EphPod
"ERUNT_is1" = ERUNT 1.1j
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"HijackThis" = HijackThis 2.0.2
"hp deskjet 5550 series" = hp deskjet 5550 series (Remove only)
"HP Photo & Imaging" = HP Image Zone 4.7
"HPExtendedCapabilities" = HP Extended Capabilities 4.7
"InstallShield_{224C47F4-CB95-406C-8AD6-81002FEED0CF}" = Hoyle Casino 2004
"InstallShield_{44A537A5-859C-43A6-8285-C0668142A090}" = iPod for Windows 2005-03-23
"InstallShield_{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"InstallShield_{71883667-71F2-48A1-AB72-28D518D8AC4A}" = Seagate Manager Installer
"InstallShield_{A6359CCF-215D-43D9-8366-479D231F2A72}" = Belkin Wireless USB Utility
"InterActual Player" = InterActual Player
"Launcher" = Outspark Launcher
"LiveReg" = LiveReg (Symantec Corporation)
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"MainApp.exe_is1" = CloneDVD 4.1.0.23
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MavenAppMgr" = Maven Application Manager
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"myTunes Redux_is1" = myTunes Redux 1.0
"MyTunes_is1" = MyTunes 1.0
"NVIDIA" =
"Orb" = Winamp Remote
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"QuicktimePluginDeinstallKey" = Quicktime Browser Plug-In
"RealPlayer 6.0" = RealPlayer
"Road Runner Install_is1" = Road Runner Install
"S3" = VIA/S3G Display Driver
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.3
"SymSetup.{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus 2004 (Symantec Corporation)
"System Monitor for Windows 98/NT/XP/2000/2003_is1" = System Monitor for Windows 98/NT/XP/2000/2003
"Ulead COOL 360 1.0" = Ulead COOL 360 1.0
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"VSO Inspector_is1" = VSO Inspector 2.0
"VTDisplay" = S3 S3Display
"VTGamma2" = S3 S3Gamma2
"VTInfo2" = S3 S3Info2
"VTOverlay" = S3 S3Overlay
"Webshots Desktop" = Webshots Desktop
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinPcapInst" = WinPcap 3.0
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XviD_is1" = XviD MPEG-4 Video Codec
"ZoomTown" = ZoomTown Software

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/1/2009 11:59:46 PM | Computer Name = KILLA_CHUBS | Source = SecurityCenter | ID = 1806
Description = The Windows Security Center was unable to establish event queries
with WMI to monitor service start/stop.

Error - 5/2/2009 12:20:28 AM | Computer Name = KILLA_CHUBS | Source = WinMgmt | ID = 28
Description = WinMgmt could not initialize the core parts. This could be due to
a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient
disk space or insufficient memory.

Error - 5/2/2009 12:20:36 AM | Computer Name = KILLA_CHUBS | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 5/2/2009 12:20:42 AM | Computer Name = KILLA_CHUBS | Source = SecurityCenter | ID = 1806
Description = The Windows Security Center was unable to establish event queries
with WMI to monitor service start/stop.

Error - 5/2/2009 12:48:50 AM | Computer Name = KILLA_CHUBS | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt2.exe, version 2.0.15.2, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5/2/2009 12:50:06 AM | Computer Name = KILLA_CHUBS | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt2.exe, version 2.0.15.2, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5/2/2009 12:50:17 AM | Computer Name = KILLA_CHUBS | Source = Application Hang | ID = 1001
Description = Fault bucket 1256421836.

Error - 5/2/2009 12:20:10 PM | Computer Name = KILLA_CHUBS | Source = WinMgmt | ID = 28
Description = WinMgmt could not initialize the core parts. This could be due to
a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient
disk space or insufficient memory.

Error - 5/2/2009 12:20:10 PM | Computer Name = KILLA_CHUBS | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 5/2/2009 12:20:26 PM | Computer Name = KILLA_CHUBS | Source = SecurityCenter | ID = 1806
Description = The Windows Security Center was unable to establish event queries
with WMI to monitor service start/stop.

[ System Events ]
Error - 5/1/2009 9:14:59 PM | Computer Name = KILLA_CHUBS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/1/2009 9:15:03 PM | Computer Name = KILLA_CHUBS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/1/2009 9:15:07 PM | Computer Name = KILLA_CHUBS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/1/2009 9:15:11 PM | Computer Name = KILLA_CHUBS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/1/2009 9:15:14 PM | Computer Name = KILLA_CHUBS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/1/2009 9:15:18 PM | Computer Name = KILLA_CHUBS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/1/2009 11:58:09 PM | Computer Name = KILLA_CHUBS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/2/2009 12:18:28 AM | Computer Name = KILLA_CHUBS | Source = Application Popup | ID = 877
Description = There was error [DATABASE OPEN FAILED] processing the driver database.

Error - 5/2/2009 12:20:24 AM | Computer Name = KILLA_CHUBS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 5/2/2009 12:20:28 AM | Computer Name = KILLA_CHUBS | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.


< End of report >
OTListIt logfile created on: 5/2/2009 12:34:56 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

447.48 Mb Total Physical Memory | 89.60 Mb Available Physical Memory | 20.02% Memory free
1.03 Gb Paging File | 0.76 Gb Available in Paging File | 74.01% Paging File free
Paging file location(s): C:\pagefile.sys 1344 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.22 Gb Total Space | 13.72 Gb Free Space | 7.53% Space Free | Partition Type: NTFS
Drive D: | 4.07 Gb Total Space | 0.69 Gb Free Space | 17.06% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 993.21 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KILLA_CHUBS
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2007/06/13 06:23:07 | 01,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2008/10/28 16:42:30 | 00,156,968 | —- | M] (Seagate Technology LLC) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
PRC - [2006/10/30 10:36:36 | 00,256,576 | —- | M] (Apple Computer, Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/02/10 14:21:40 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008/10/28 16:42:12 | 00,181,544 | —- | M] (Seagate LLC) – C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
PRC - [2007/08/03 12:51:06 | 00,202,024 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
PRC - [2007/08/08 09:25:08 | 00,836,904 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
PRC - [2004/09/29 12:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe
PRC - [2004/11/02 17:59:50 | 00,316,544 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
PRC - [2006/10/30 10:36:32 | 00,492,608 | —- | M] (Apple Computer, Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2007/08/03 12:51:18 | 00,382,248 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
PRC - [2007/08/03 12:51:18 | 01,422,632 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
PRC - [2004/11/04 19:36:46 | 00,425,984 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
PRC - [2009/05/02 00:39:29 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2005/11/01 23:26:44 | 00,068,096 | —- | M] () – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe – (Adobe LM Service [Disabled | Stopped])
SRV - [2005/09/23 07:28:32 | 00,029,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [Disabled | Stopped])
SRV - [2008/04/04 01:52:29 | 00,418,816 | —- | M] (GRISOFT, s.r.o.) – C:\Program Files\Grisoft\AVG7\avgamsvr.exe – (Avg7Alrt [Disabled | Stopped])
SRV - [2008/04/04 01:52:54 | 00,049,664 | —- | M] (GRISOFT, s.r.o.) – C:\Program Files\Grisoft\AVG7\avgupsvc.exe – (Avg7UpdSvc [Disabled | Stopped])
SRV - [2008/04/04 01:52:36 | 00,406,528 | —- | M] (GRISOFT, s.r.o.) – C:\Program Files\Grisoft\AVG7\avgemc.exe – (AVGEMS [Disabled | Stopped])
SRV - [2004/12/22 18:45:22 | 00,255,600 | —- | M] (Symantec Corporation) – c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe – (ccEvtMgr [Disabled | Stopped])
SRV - [2004/12/22 18:45:30 | 00,087,664 | —- | M] (Symantec Corporation) – c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe – (ccPwdSvc [Disabled | Stopped])
SRV - [2004/12/22 18:45:42 | 00,235,120 | —- | M] (Symantec Corporation) – c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe – (ccSetMgr [Disabled | Stopped])
SRV - [2005/09/23 07:28:56 | 00,066,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2006/10/20 21:21:24 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/10/28 16:42:30 | 00,156,968 | —- | M] (Seagate Technology LLC) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe – (FreeAgentGoNext Service [Auto | Running])
SRV - [2004/08/04 03:56:44 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2006/10/30 03:33:58 | 00,741,376 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2006/10/30 10:36:32 | 00,492,608 | —- | M] (Apple Computer, Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2009/02/10 14:21:40 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2004/08/06 04:50:00 | 00,102,463 | —- | M] (Network Associates, Inc.) – C:\Program Files\Network Associates\Common Framework\FrameworkService.exe – (McAfeeFramework [Disabled | Stopped])
SRV - [2004/09/22 21:00:00 | 00,221,191 | —- | M] (Network Associates, Inc.) – C:\Program Files\Network Associates\VirusScan\mcshield.exe – (McShield [Disabled | Stopped])
SRV - [2004/09/22 21:00:00 | 00,028,672 | —- | M] (Network Associates, Inc.) – C:\Program Files\Network Associates\VirusScan\vstskmgr.exe – (McTaskManager [Disabled | Stopped])
SRV - [2002/12/17 17:26:22 | 07,520,337 | —- | M] (Microsoft Corporation) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe – (MSSQL$SONY_MEDIAMGR [On_Demand | Stopped])
SRV - [2002/12/17 17:23:30 | 00,066,112 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe – (MSSQLServerADHelper [On_Demand | Stopped])
SRV - [2004/04/23 11:04:18 | 00,158,848 | —- | M] (Symantec Corporation) – c:\Program Files\Norton AntiVirus\navapsvc.exe – (navapsvc [Disabled | Stopped])
SRV - [2007/08/08 09:25:08 | 00,836,904 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe – (Nero BackItUp Scheduler 3 [Auto | Running])
SRV - File not found – – (Nero BackItUp Scheduler 4.0 [Auto | Stopped])
SRV - [2006/10/30 03:34:02 | 00,122,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/08/03 12:51:18 | 00,382,248 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe – (NMIndexingService [On_Demand | Running])
SRV - [2004/09/29 12:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12 [Auto | Running])
SRV - [2003/04/04 15:54:50 | 00,077,824 | —- | M] () – C:\Program Files\WinPcap\rpcapd.exe – (rpcapd [Disabled | Stopped])
SRV - [2003/12/04 18:22:30 | 00,193,816 | —- | M] (Symantec Corporation) – c:\Program Files\Norton AntiVirus\SAVScan.exe – (SAVScan [Disabled | Stopped])
SRV - [2005/01/21 23:32:12 | 00,206,552 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc [Disabled | Stopped])
SRV - [2002/12/17 17:23:30 | 00,311,872 | —- | M] (Microsoft Corporation) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE – (SQLAgent$SONY_MEDIAMGR [On_Demand | Stopped])
SRV - [2004/11/02 17:59:50 | 00,316,544 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe – (SymWSC [Auto | Running])
SRV - [2005/12/05 00:24:24 | 00,126,976 | —- | M] () – C:\WINDOWS\System32\UAService7.exe – (UserAccess7 [Disabled | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [Disabled | Stopped])
SRV - [2007/03/14 17:03:40 | 00,975,400 | —- | M] (Microsoft Corporation) – C:\Program Files\Zune\ZuneNss.exe – (ZuneNetworkSvc [Disabled | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2004/08/04 02:10:10 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\61883.sys – (61883 [On_Demand | Stopped])
DRV - [2004/06/29 10:07:18 | 01,268,204 | —- | M] (Agere Systems) – C:\WINDOWS\System32\DRIVERS\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2003/12/12 10:54:14 | 00,391,424 | —- | M] (Sensaura Ltd) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS – (ALCXSENS [On_Demand | Stopped])
DRV - [2004/10/01 11:24:02 | 02,279,424 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM [On_Demand | Running])
DRV - [2009/03/18 13:08:10 | 00,103,744 | —- | M] (SlySoft, Inc.) – C:\WINDOWS\System32\Drivers\AnyDVD.sys – (AnyDVD [On_Demand | Running])
DRV - [2004/08/04 02:10:10 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\avc.sys – (Avc [On_Demand | Stopped])
DRV - [2008/04/04 01:53:06 | 00,821,856 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\System32\Drivers\avg7core.sys – (Avg7Core [System | Running])
DRV - [2008/04/04 01:53:24 | 00,004,224 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\System32\Drivers\avg7rsw.sys – (Avg7RsW [System | Running])
DRV - [2008/04/04 01:53:27 | 00,027,776 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\System32\Drivers\avg7rsxp.sys – (Avg7RsXP [System | Running])
DRV - [2008/04/04 01:53:33 | 00,010,760 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\System32\Drivers\avgclean.sys – (AvgClean [System | Running])
DRV - [2008/04/04 01:53:31 | 00,004,960 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\System32\Drivers\avgtdi.sys – (AvgTdi [Auto | Running])
DRV - [2005/11/10 14:54:56 | 00,402,944 | R— | M] (Belkin Corporation) – C:\WINDOWS\System32\DRIVERS\BLKWGU.sys – (BLKWGU(Belkin) [On_Demand | Stopped])
DRV - [2003/02/28 17:13:58 | 00,042,624 | —- | M] (Accapella Ltd.) – C:\WINDOWS\System32\DRIVERS\CoachUsb.sys – (CoachUsb [On_Demand | Stopped])
DRV - [2003/01/25 00:12:20 | 00,046,048 | —- | M] (Accapella Ltd.) – C:\WINDOWS\System32\DRIVERS\CoachVc.sys – (CoachVc [On_Demand | Stopped])
DRV - [2003/05/01 13:26:34 | 00,005,220 | —- | M] (Cisco Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\CVirtA.sys – (CVirtA [On_Demand | Stopped])
DRV - [2004/08/22 16:31:10 | 00,155,136 | —- | M] ( ) – C:\WINDOWS\System32\DRIVERS\d347bus.sys – (d347bus [Boot | Running])
DRV - [2004/08/22 16:31:48 | 00,005,248 | —- | M] ( ) – C:\WINDOWS\System32\Drivers\d347prt.sys – (d347prt [Boot | Running])
DRV - [2009/02/17 13:11:30 | 00,024,232 | —- | M] (Elaborate Bytes AG) – C:\WINDOWS\System32\Drivers\ElbyCDIO.sys – (ElbyCDIO [System | Running])
DRV - [2004/09/22 21:00:00 | 00,008,320 | —- | M] (Network Associates, Inc) – C:\WINDOWS\system32\drivers\EntDrv51.sys – (EntDrv51 [On_Demand | Stopped])
DRV - [2009/02/25 20:22:12 | 00,008,704 | —- | M] () – C:\WINDOWS\system32\epmntdrv.sys – (epmntdrv [On_Demand | Stopped])
DRV - [2009/02/25 20:22:12 | 00,003,072 | —- | M] () – C:\WINDOWS\system32\EuGdiDrv.sys – (EuGdiDrv [On_Demand | Stopped])
DRV - [2003/12/02 22:23:20 | 00,142,336 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys – (fasttx2k [Boot | Running])
DRV - [2003/11/12 05:41:00 | 00,041,984 | —- | M] (VIA Technologies, Inc. ) – C:\WINDOWS\System32\DRIVERS\fetnd5b.sys – (FETNDISB [On_Demand | Running])
DRV - [2006/09/19 16:44:04 | 00,015,664 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2004/12/14 12:07:44 | 00,051,120 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys – (HPZid412 [On_Demand | Running])
DRV - [2004/12/14 12:07:44 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys – (HPZipr12 [On_Demand | Running])
DRV - [2004/12/14 12:07:44 | 00,021,744 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys – (HPZius12 [On_Demand | Running])
DRV - [2004/02/10 22:17:06 | 00,681,469 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys – (ialm [On_Demand | Stopped])
DRV - [2004/08/04 02:09:58 | 00,051,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\msdv.sys – (MSDV [On_Demand | Stopped])
DRV - [2004/09/22 21:00:00 | 00,108,256 | —- | M] (Network Associates, Inc.) – C:\WINDOWS\system32\drivers\naiavf5x.sys – (NaiAvFilter1 [On_Demand | Stopped])
DRV - [2004/09/22 21:00:00 | 00,058,048 | —- | M] (Network Associates, Inc.) – C:\WINDOWS\system32\drivers\mvstdi5x.sys – (NaiAvTdi1 [System | Running])
DRV - [2004/11/19 05:00:00 | 00,072,712 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20041119.003\NAVENG.SYS – (NAVENG [On_Demand | Running])
DRV - [2004/11/19 05:00:00 | 00,629,544 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20041119.003\NAVEX15.SYS – (NAVEX15 [On_Demand | Running])
DRV - [2003/04/04 16:07:20 | 00,030,336 | —- | M] (Politecnico di Torino) – C:\WINDOWS\system32\drivers\npf.sys – (NPF [On_Demand | Stopped])
DRV - [2005/01/04 05:43:08 | 00,004,682 | —- | M] (INCA Internet Co., Ltd.) – C:\WINDOWS\System32\npptNT2.sys – (NPPTNT2 [System | Running])
DRV - [2004/08/04 01:29:54 | 01,897,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Stopped])
DRV - [2009/03/23 17:15:25 | 00,047,360 | —- | M] (VSO Software) – C:\WINDOWS\System32\Drivers\Pcouffin.sys – (Pcouffin [On_Demand | Running])
DRV - [2003/09/19 04:47:00 | 00,010,368 | —- | M] (Padus, Inc.) – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc [On_Demand | Running])
DRV - [2002/07/30 01:43:50 | 00,023,808 | —- | M] (Hewlett-Packard Company) – C:\WINDOWS\System32\DRIVERS\PS2.sys – (Ps2 [On_Demand | Running])
DRV - [2003/08/15 22:10:32 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/03/07 19:51:00 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2002/10/04 21:04:10 | 00,046,976 | —- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS – (rtl8139 [On_Demand | Stopped])
DRV - [2003/12/04 18:22:30 | 00,308,416 | —- | M] (Symantec Corporation) – c:\Program Files\Norton AntiVirus\SAVRT.SYS – (SAVRT [System | Running])
DRV - [2003/12/04 18:22:30 | 00,037,056 | —- | M] (Symantec Corporation) – c:\Program Files\Norton AntiVirus\SAVRTPEL.SYS – (SAVRTPEL [System | Running])
DRV - [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [Auto | Running])
DRV - [2004/01/02 23:20:40 | 00,432,000 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys – (SiS315 [On_Demand | Stopped])
DRV - [2003/07/18 20:58:20 | 00,036,992 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys – (SISAGP [Boot | Running])
DRV - [2004/01/03 00:05:48 | 00,011,520 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\srvkp.sys – (SiSkp [System | Running])
DRV - [2004/12/20 19:58:18 | 00,110,352 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\SYMEVENT.SYS – (SymEvent [On_Demand | Running])
DRV - [2005/01/21 23:31:48 | 00,026,424 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV [On_Demand | Stopped])
DRV - [2005/01/21 23:31:50 | 00,267,384 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI [System | Running])
DRV - [2008/06/03 15:35:32 | 00,102,664 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\drivers\tmcomm.sys – (tmcomm [Auto | Running])
DRV - [2004/08/04 02:04:32 | 00,012,672 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\usb8023.sys – (USB_RNDIS_XP [On_Demand | Running])
DRV - [2003/07/02 15:42:00 | 00,027,904 | —- | M] (VIA Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys – (viaagp1 [Boot | Running])
DRV - [2004/12/07 20:08:58 | 00,172,672 | —- | M] (Copyright © VIA/S3 Graphics Co, Ltd.) – C:\WINDOWS\System32\DRIVERS\vtmini.sys – (viagfx [On_Demand | Running])
DRV - [2004/10/25 13:40:58 | 00,017,664 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) – C:\WINDOWS\System32\Drivers\ZDPSp50.sys – (ZDPSp50 [On_Demand | Stopped])
DRV - [2008/04/04 01:53:31 | 00,004,960 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\system32\drivers\avgtdi.sys – ({8applayrver [Disabled | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://broadband.zoomtown.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://broadband.zoomtown.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/02/10 14:21:56 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/28 21:56:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/28 21:56:43 | 00,000,000 | —D | M]

[2009/01/18 11:43:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2009/01/18 11:43:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/27 22:29:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\0wqhwt4c.a\extensions
[2008/09/18 14:20:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\0wqhwt4c.a\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2008/09/03 13:30:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\0wqhwt4c.a\extensions\[removed]
[2008/09/01 22:30:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions
[2006/01/24 19:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions\{7E77F5DF-8022-40e3-9122-F03DEBEFC43B}
[2007/04/15 21:09:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions\{9d1f059c-cada-4111-9696-41a62d64e3ba}
[2007/03/03 03:27:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions\{fd048119-78ee-487f-8fb1-1668d3a6859b}
[2008/05/18 23:33:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions\[removed]
[2008/05/28 14:53:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions\[removed]
[2008/08/28 08:15:28 | 00,001,412 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\6trvxeg1.default\searchplugins\bittorrent.xml
[2009/04/27 22:29:14 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/28 21:56:43 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/02/23 01:35:29 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
[2008/04/05 15:01:42 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/02/10 14:23:03 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/04/28 21:56:06 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/28 21:56:06 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/01/18 11:43:01 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/01/18 11:43:02 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/01/18 11:43:02 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/01/18 11:43:02 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/01/18 11:43:02 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/01/18 11:43:02 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/01/18 11:43:02 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe (HP)
O4 - HKLM..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Computer, Inc.)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KBD.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" (Seagate LLC)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto (Microsoft Corporation)
O4 - HKLM..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r (Sonic Solutions)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" (Nero AG)
O4 - HKCU..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" (www.BitComet.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add To Compaq Organize… - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://activation.rr.com/install/downloads/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} http://housecall-beta.trendmicro.com/housecall/xscan60.cab (HouseCall Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} http://www.webshots.com/samplers/WSDownloader.ocx (WSDownloader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1184020652671 (MUWebControl Class)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab (HouseCall Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} http://community.webshots.com/html/WSPhotoUploader.CAB (Webshots Photo Uploader)
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} http://gamedownload.ijjimax.com/gamedownlo…GPlugin7USA.cab (HGPlugin7USA Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} http://chat.msn.com/controls/msnchat45.cab (MSN Chat Control 4.5)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/02 15:55:20 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 14:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/10 11:02:32 | 00,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2007/08/09 11:10:22 | 00,001,868 | R— | M] () - G:\Autorun.inf – [ CDFS ]
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Info.exe – [2002/09/10 05:54:58 | 00,040,960 | -HS- | M] (XSS)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2 C:\WINDOWS\*.tmp files]
[2 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/05/02 00:39:26 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/04/22 23:50:47 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/04/22 23:43:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\DVDFab
[2009/04/22 23:43:07 | 00,000,000 | —D | C] – C:\Program Files\DVDFab 5
[2009/04/22 14:44:15 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Unused Desktop Shortcuts
[2009/04/22 14:42:01 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Performance
[2009/04/22 14:38:20 | 00,000,000 | —D | C] – C:\Program Files\Defraggler
[2009/04/22 12:12:24 | 00,257,865 | —- | C] () – C:\Documents and Settings\Owner\Desktop\cc_20090422_1212.reg
[2009/04/21 16:50:13 | 02,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2009/04/20 19:03:47 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/04/20 19:03:13 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/04/20 16:55:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\AnyDVDHD
[2009/04/20 13:55:01 | 00,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2009/04/20 13:55:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2009/04/20 13:54:25 | 00,000,000 | —D | C] – C:\Program Files\SlySoft
[2009/04/19 20:33:25 | 01,228,854 | —- | C] () – C:\Documents and Settings\All Users\Application Data\OrbError.bmp
[2009/04/19 19:48:39 | 00,001,132 | RH– | C] () – C:\WINDOWS\EPMBatch.ept
[2009/04/19 19:42:24 | 01,907,712 | —- | C] () – C:\WINDOWS\System32\BootMan.exe
[2009/04/19 19:42:24 | 00,014,848 | —- | C] () – C:\WINDOWS\System32\EuEpmGdi.dll
[2009/04/19 19:42:23 | 00,086,408 | —- | C] () – C:\WINDOWS\System32\setupempdrv03.exe
[2009/04/19 19:42:23 | 00,008,704 | —- | C] () – C:\WINDOWS\System32\epmntdrv.sys
[2009/04/19 19:42:23 | 00,003,072 | —- | C] () – C:\WINDOWS\System32\EuGdiDrv.sys
[2009/04/19 19:41:58 | 00,000,000 | —D | C] – C:\Program Files\EASEUS
[2009/04/19 17:23:33 | 00,088,064 | -HS- | C] () – C:\Documents and Settings\Owner\My Documents\Thumbs.db
[2009/04/19 13:09:53 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\External
[2009/04/15 21:06:00 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/15 21:05:59 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/04/15 21:05:56 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/15 21:05:55 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/15 21:05:53 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/15 21:05:52 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 21:05:49 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/15 21:05:43 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/15 21:05:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/15 20:58:48 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/03/23 16:09:03 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/03/22 23:43:47 | 00,000,014 | —- | C] () – C:\WINDOWS\System32\systeminfo3.dll
[2009/03/10 01:24:03 | 00,000,039 | —- | C] () – C:\WINDOWS\Irremote.ini
[2006/05/01 19:40:14 | 00,000,026 | —- | C] () – C:\WINDOWS\dvdSanta.INI
[2005/12/05 00:24:24 | 00,090,112 | —- | C] () – C:\WINDOWS\System32\CmdLineExt.dll
[2005/12/05 00:16:12 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/10/06 16:42:14 | 00,000,071 | —- | C] () – C:\WINDOWS\pex.INI
[2005/09/20 00:39:01 | 00,000,125 | —- | C] () – C:\WINDOWS\Ulead32.ini
[2005/09/13 20:18:09 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/07/12 14:44:42 | 00,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2005/03/27 18:16:16 | 00,001,009 | R-S- | C] () – C:\WINDOWS\System32\TBPS.ini
[2005/03/26 23:23:13 | 00,000,070 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/02/17 04:12:54 | 00,025,157 | —- | C] () – C:\WINDOWS\RMAgentOutput.dll
[2005/02/17 04:12:00 | 00,126,976 | —- | C] () – C:\WINDOWS\dllTSCLIBMT.dll
[2005/02/16 18:55:49 | 00,001,597 | —- | C] () – C:\WINDOWS\HattrickPoli.INI
[2005/02/02 19:40:51 | 00,001,271 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/01/27 22:59:48 | 00,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2005/01/27 22:56:37 | 00,000,306 | —- | C] () – C:\WINDOWS\QTW.INI
[2004/12/04 01:19:33 | 00,000,000 | —- | C] () – C:\WINDOWS\AutoRun.INI
[2004/10/01 18:33:46 | 00,000,809 | —- | C] () – C:\WINDOWS\TSC.ini
[2004/09/21 10:19:04 | 00,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004/09/21 10:18:46 | 00,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004/09/09 20:32:19 | 00,155,136 | —- | C] ( ) – C:\WINDOWS\System32\drivers\d347bus.sys
[2004/09/09 20:32:19 | 00,005,248 | —- | C] ( ) – C:\WINDOWS\System32\drivers\d347prt.sys
[2004/09/06 16:04:52 | 00,000,069 | —- | C] () – C:\WINDOWS\DVDXCopy.INI
[2004/09/02 13:23:06 | 00,001,110 | —- | C] () – C:\WINDOWS\winamp.ini
[2004/08/31 10:38:37 | 00,010,646 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2004/08/25 12:29:48 | 00,000,045 | —- | C] () – C:\WINDOWS\FEGHMMN.ini
[2004/08/22 20:23:06 | 00,053,760 | —- | C] () – C:\WINDOWS\System32\ZLIB.DLL
[2004/08/22 17:10:47 | 00,139,104 | —- | C] () – C:\WINDOWS\System32\CSGina.dll
[2004/08/22 17:04:56 | 00,069,120 | —- | C] () – C:\WINDOWS\daemon.dll
[2004/07/12 17:07:21 | 03,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/06/12 15:43:39 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2004/06/12 15:43:39 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2004/06/12 15:43:39 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2004/06/12 15:43:39 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2004/06/12 15:43:39 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2004/06/12 15:43:39 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2004/06/06 12:53:42 | 00,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/06/05 12:56:16 | 00,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2004/04/03 02:35:49 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\VGAunistlog.ini
[2004/04/03 02:35:48 | 00,000,451 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2004/04/02 22:57:39 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/04/02 19:08:49 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2004/04/02 19:08:20 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/04/02 19:08:20 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2004/04/02 19:03:06 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2004/04/02 18:47:59 | 00,027,754 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/04/02 18:47:19 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/04/02 18:31:02 | 00,000,453 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/04/02 18:22:10 | 00,000,907 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004/04/02 17:40:20 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/04/02 16:54:44 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/04/02 16:54:44 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/04/02 16:54:16 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/04/02 15:59:40 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/04/02 14:42:06 | 00,000,553 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/04/02 14:41:43 | 00,000,792 | —- | C] () – C:\WINDOWS\win.ini
[2004/04/02 14:41:40 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2004/03/23 16:38:00 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2004/01/24 03:33:14 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2002/11/01 16:17:50 | 00,000,256 | —- | C] () – C:\WINDOWS\aucfg.ini
[2002/07/04 15:05:34 | 00,000,269 | —- | C] () – C:\WINDOWS\tmupdate.ini
[2002/03/02 05:10:02 | 00,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2001/12/14 14:34:46 | 00,164,864 | —- | C] () – C:\WINDOWS\patchw32.dll
[1999/07/23 14:46:48 | 00,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 11:53:20 | 00,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll

========== Files - Modified Within 30 Days ==========

[6 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/05/02 12:34:19 | 00,000,186 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2009/05/02 12:18:55 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/02 12:18:26 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\desktop.ini
[2009/05/02 12:18:16 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/02 12:17:32 | 46,929,1008 | -HS- | M] () – C:\hiberfil.sys
[2009/05/02 00:39:29 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/05/01 23:58:16 | 00,000,530 | —- | M] () – C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
[2009/04/30 14:23:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/28 21:51:17 | 00,000,559 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Shortcut to Downloads.lnk
[2009/04/24 01:03:48 | 00,000,040 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2009/04/22 14:48:10 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/22 14:21:53 | 00,000,792 | —- | M] () – C:\WINDOWS\win.ini
[2009/04/22 14:21:53 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/04/22 14:21:53 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/04/22 12:12:46 | 00,257,865 | —- | M] () – C:\Documents and Settings\Owner\Desktop\cc_20090422_1212.reg
[2009/04/20 17:25:51 | 00,000,039 | —- | M] () – C:\WINDOWS\Irremote.ini
[2009/04/20 12:23:27 | 00,549,846 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/20 12:23:27 | 00,459,360 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/20 12:23:27 | 00,079,672 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/20 02:05:49 | 00,010,646 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/04/19 21:30:02 | 01,228,854 | —- | M] () – C:\Documents and Settings\All Users\Application Data\OrbError.bmp
[2009/04/19 20:13:31 | 00,001,132 | RH– | M] () – C:\WINDOWS\EPMBatch.ept
[2009/04/19 17:24:03 | 00,088,064 | -HS- | M] () – C:\Documents and Settings\Owner\My Documents\Thumbs.db
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 10:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe

========== LOP Check ==========

[2009/04/22 23:50:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/03 16:56:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/09/21 15:05:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/04/04 02:01:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg7
[2009/03/10 13:26:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/03/22 23:42:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVDXStudio
[2008/04/04 01:52:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2005/10/02 03:26:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2004/09/21 23:38:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Macrovision
[2008/07/17 21:45:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/15 14:34:43 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2004/04/02 19:06:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2009/04/21 16:56:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nero
[2005/02/25 11:37:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Network Associates
[2008/12/02 16:09:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OrbNetworks
[2008/08/08 13:16:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Outspark
[2006/05/09 14:06:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2005/10/10 15:44:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/04/02 16:00:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/03/29 15:07:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2009/04/20 13:55:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2005/10/11 16:37:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2009/04/22 14:26:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/03/07 21:37:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Support.com
[2004/04/02 22:43:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/05/25 21:59:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/04/24 12:57:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2005/09/20 14:46:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2004/09/26 16:57:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/04/22 23:50:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2007/07/09 18:44:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/03/23 17:16:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data
[2008/09/15 22:09:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Adobe
[2008/09/04 14:24:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeUM
[2006/04/10 00:31:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2007/02/18 05:17:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Apple Computer
[2009/04/22 10:55:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG7
[2005/03/08 00:21:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\drms
[2004/09/26 20:22:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Help
[2004/04/02 15:55:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Identities
[2004/09/06 16:08:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2004/09/12 17:39:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Jasc
[2004/09/27 02:18:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lavasoft
[2004/08/21 19:11:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2009/03/24 16:19:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\log
[2004/09/08 20:22:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Macromedia
[2008/07/17 21:46:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2008/09/04 14:44:08 | 00,000,000 | –SD | M] – C:\Documents and Settings\Owner\Application Data\Microsoft
[2005/03/27 17:23:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2008/05/22 14:01:03 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2009/01/18 11:43:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla
[2009/04/21 17:11:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nero
[2005/10/12 00:26:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\NetMedia Providers
[2006/07/26 00:28:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\NHN Corporation
[2006/05/09 14:19:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Propellerhead Software
[2004/08/28 00:59:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Publish Providers
[2008/04/04 15:50:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Real
[2004/04/02 19:24:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2005/12/05 00:24:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SecuROM
[2004/08/21 19:11:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sonic
[2005/10/12 00:26:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sony
[2004/04/02 17:11:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sun
[2004/04/02 22:42:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Symantec
[2005/04/08 21:47:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Talkback
[2005/10/06 16:41:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ulead Systems
[2009/04/29 02:40:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Vso
[2005/02/17 00:00:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2004/11/14 23:36:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Webshots
[2009/04/30 14:23:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2003/08/16 12:14:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/05/01 23:58:16 | 00,000,530 | —- | M] () – C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job
[2009/05/02 12:18:55 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2005/02/23 01:40:31 | 00,000,364 | —- | M] () – C:\WINDOWS\Tasks\Symantec NetDetect.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 24 bytes -> C:\WINDOWS:9F128BAA51D65A77
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:02C77207
< End of report >
mcfarljd,

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.


BitComet
You have BitComet, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm


I would recommend that you uninstall BitComet, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


You appear to have mulitple Anit-Virus programs running. Network Associates, Symantec, and AVG 7. Please uninstall two of them.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
sorry, let kapersky run yesterday and came home to find the "disk boot error" screen, it is running now though so hopefully i can get the log posted.
mcfarljd,

Lets look for rootkits.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.
  • Close Gmer.
  • Open Command Prompt by going to Start > Run and type in cmd. Press Enter.
  • In Command Prompt, type in net stop gmer. Press Enter.
  • Type in exit to close Command Prompt.

Note: Do not run any programs while Gmer is running.
Here's the Rooter, Kaspersky was close to finishing once, was 98% done and I know that the only things that it found up to that point were 18 objects in various quarantine folders, but again it failed at the end so no report to give. GMEr made the comp fail too, sad face, gonna give it another shot. Microsoft Windows XP Home Edition (5.1.2600) Service Pack 2 C:\ [Fixed] - NTFS - (Total:186593 Mo/Free:1882 Mo) D:\ [Fixed] - FAT32 - (Total:4170 Mo/Free:711 Mo) E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) G:\ [CD-Rom] (Total:992 Mo/Free:0 Mo) H:\ [Removable] (Total:0 Mo/Free:0 Mo) I:\ [Removable] (Total:0 Mo/Free:0 Mo) J:\ [Removable] (Total:0 Mo/Free:0 Mo) K:\ [Removable] (Total:0 Mo/Free:0 Mo) L:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) M:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) N:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) O:\ [Fixed] - FAT32 - (Total:476879 Mo/Free:666 Mo) P:\ [Removable] (Total:0 Mo/Free:0 Mo) Wed 05/06/2009|16:38 ———————-\\ Processes.. –Locked– [System Process] ———- System ———- \SystemRoot\System32\smss.exe ———- \??\C:\WINDOWS\system32\csrss.exe ———- \??\C:\WINDOWS\system32\winlogon.exe ———- C:\WINDOWS\system32\services.exe ———- C:\WINDOWS\system32\lsass.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\Explorer.EXE ———- C:\WINDOWS\system32\spoolsv.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\Program Files\Java\jre6\bin\jqs.exe ———- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe ———- C:\WINDOWS\system32\HPZipm12.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\windows\system\hpsysdrv.exe ———- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe ———- C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe ———- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe ———- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe ———- C:\WINDOWS\system32\wscntfy.exe ———- C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe ———- C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe ———- C:\WINDOWS\system32\wuauclt.exe ———- C:\Program Files\Internet Explorer\iexplore.exe ———- C:\WINDOWS\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! 1 - "C:\Rooter$\Rooter_3.txt" - Wed 05/06/2009|16:40 ———————-\\ Scan completed at 16:40
No thats what it came up with, I wasn't sure where it was saved since the comp obviously has a problem with error messages so i wasn't able to save the logs to the desktop. Gmer again caused a system error early so I've never been able to run that successfully.
mcfarljd,

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Hey who knew, my computer finally let a scan run :notworthy: DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 0:01:25.53 on Fri 05/08/2009 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_12 ============== Running Processes =============== ============== Pseudo HJT Report =============== uStart Page = hxxp://broadband.zoomtown.com uWindow Title = Road Runner High Speed Online mStart Page = hxxp://broadband.zoomtown.com uInternet Settings,ProxyOverride = localhost BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File EB: {BE8D0059-D24D-4919-B76F-99F4A2203647} - No File uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMBgMonitor.exe" uRun: [BitComet] "c:\program files\bitcomet\BitComet.exe" mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [MaxMenuMgr] "c:\program files\seagate\seagatemanager\freeagent status\StxMenuMgr.exe" mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe" dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE uExplorerRun: [mwkqw.exe] c:\windows\system\mwkqw.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe IE: Add To Compaq Organize… - c:\progra~1\hewlet~1\compaq~1\bin\core.hp.main\SendTo.html IE: E&xport; to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000 IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://activation.rr.com/install/downloads/tgctlcm.cab DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} - hxxp://housecall-beta.trendmicro.com/housecall/xscan60.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB DPF: {32505657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} - hxxp://www.webshots.com/samplers/WSDownloader.ocx DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184020652671 DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - hxxp://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} - hxxp://community.webshots.com/html/WSPhotoUploader.CAB DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin7USA.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} - hxxp://chat.msn.com/controls/msnchat45.cab Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\0wqhwt4c.a\ FF - prefs.js: browser.search.selectedEngine - Google FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\0wqhwt4c.a\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll ============= SERVICES / DRIVERS =============== ============== File Associations =============== regfile=regedit.exe "%1" %* scrfile="%1" %* =============== Created Last 30 ================ 2009-05-05 02:51 –d—– C:\Rooter$ 2009-04-22 23:50 –d—– c:\docume~1\alluse~1\applic~1\vsosdk 2009-04-22 23:43 –d—– c:\program files\DVDFab 5 2009-04-22 14:38 –d—– c:\program files\Defraggler 2009-04-20 13:54 –d—– c:\program files\SlySoft 2009-04-19 19:48 1,132 a—hr– c:\windows\EPMBatch.ept 2009-04-19 19:42 1,907,712 a——- c:\windows\system32\BootMan.exe 2009-04-19 19:42 14,848 a——- c:\windows\system32\EuEpmGdi.dll 2009-04-19 19:42 86,408 a——- c:\windows\system32\setupempdrv03.exe 2009-04-19 19:42 8,704 a——- c:\windows\system32\epmntdrv.sys 2009-04-19 19:42 3,072 a——- c:\windows\system32\EuGdiDrv.sys 2009-04-19 19:41 –d—– c:\program files\EASEUS 2009-04-15 21:06 283,648 -c—— c:\windows\system32\dllcache\pdh.dll 2009-04-15 21:05 60,416 -c—— c:\windows\system32\dllcache\colbact.dll 2009-04-15 21:05 399,360 -c—— c:\windows\system32\dllcache\rpcss.dll 2009-04-15 21:05 110,592 -c—— c:\windows\system32\dllcache\services.exe 2009-04-15 21:05 473,088 -c—— c:\windows\system32\dllcache\fastprox.dll 2009-04-15 21:05 227,840 -c—— c:\windows\system32\dllcache\wmiprvse.exe 2009-04-15 21:05 453,120 -c—— c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-15 21:05 616,960 -c—— c:\windows\system32\dllcache\advapi32.dll 2009-04-15 21:05 714,752 -c—— c:\windows\system32\dllcache\ntdll.dll 2009-04-15 20:58 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe ==================== Find3M ==================== 2009-04-20 02:05 10,646 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-04-06 15:32 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-06 15:32 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-03-23 17:15 87,608 a——- c:\docume~1\owner\applic~1\inst.exe 2009-03-23 17:15 47,360 a——- c:\windows\system32\drivers\pcouffin.sys 2009-03-23 17:15 47,360 a——- c:\docume~1\owner\applic~1\pcouffin.sys 2009-03-22 23:42 81,920 a——- c:\docume~1\owner\applic~1\ezpinst.exe 2009-03-18 13:08 103,744 a——- c:\windows\system32\drivers\AnyDVD.sys 2009-03-06 10:44 283,648 a——- c:\windows\system32\pdh.dll 2009-02-20 04:30 659,456 a——- c:\windows\system32\wininet.dll 2009-02-20 04:30 81,920 ——– c:\windows\system32\ieencode.dll 2009-02-17 09:33 89,256 a——- c:\windows\system32\ElbyCDIO.dll 2009-02-10 14:21 410,984 a——- c:\windows\system32\deploytk.dll 2009-02-09 06:20 723,456 a——- c:\windows\system32\lsasrv.dll 2009-02-09 06:20 399,360 a——- c:\windows\system32\rpcss.dll 2009-02-09 06:20 714,752 a——- c:\windows\system32\ntdll.dll 2009-02-09 06:20 616,960 a——- c:\windows\system32\advapi32.dll 2009-02-09 06:19 1,846,272 a——- c:\windows\system32\win32k.sys 2008-04-15 08:48 47,144 a——- c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT ============= FINISH: 0:03:18.32 ===============

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI