This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HJT Log Attached - McAfee No Longer Working

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HERE ARE THE RSIT logs. Now downloading and running GMER

Logfile of random's system information tool 1.06 (written by random/random)
Run by [removed] at 2009-05-17 12:04:54
Microsoft Windows XP Professional Service Pack 2
System drive C: has 695 GB (97%) free of 715 GB
Total RAM: 3326 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:04:55 PM, on 5/17/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Documents and Settings\Margaret McLeod\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Margaret McLeod.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Browser Helper Object - {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - C:\Program Files\Common\helper.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Google; Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [EPSON Stylus Photo 2200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus Photo 2200" /O6 "USB002" /M "Stylus Photo 2200"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AmazonGSDownloaderTray] C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: Epson printer Registration.lnk = D:\E_reg\EpsonReg.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafeeasap.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1218519555078
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_2/axofupld.cab
O18 - Filter hijack: text/html - {ab20a60c-58f9-48ab-9ac3-859e1337c0da} - C:\WINDOWS\system32\dsound3dd.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Amazon Download Agent - Amazon.com - C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

–
End of file - 9668 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 63128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-01-17 251504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-04-17 668656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}]
Browser Helper Object - C:\Program Files\Common\helper.dll [2009-05-17 294924]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [2009-01-17 522224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files\Dell\BAE\BAE.dll [2006-11-09 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google; Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-01-17 251504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe [2006-09-25 90112]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-07-22 16132608]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2007-07-22 69632]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-07-16 29744]
"PDVDDXSrv"=C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [2008-02-26 128296]
"EPSON Stylus Photo R200 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE [2003-07-08 99840]
"EPSON Stylus Photo 2200"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE [2002-07-01 74752]
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2004-10-08 221184]
"LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2005-01-18 458752]
"LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2005-01-18 217088]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-09-10 289576]
"AmazonGSDownloaderTray"=C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe [2009-02-02 246272]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-11 218032]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe [2005-01-18 196608]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-07-16 68856]
"Messenger (Yahoo!)"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2009-02-20 4363504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe [2008-08-26 20480]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
Nikon Monitor.lnk - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
TabUserW.exe.lnk - C:\WINDOWS\system32\WTablet\TabUserW.exe

C:\Documents and Settings\Margaret McLeod\Start Menu\Programs\Startup
Epson printer Registration.lnk - D:\E_reg\EpsonReg.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2008-08-22 10536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\GoToAssist]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe"="C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX"
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe"="C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe"="C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX"
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program"
"C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe"="C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe:*:Enabled:Managed Services Agent"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

======List of files/folders created in the last 1 months======

2009-05-17 12:04:54 —-D—- C:\rsit
2009-05-16 19:31:55 —-A—- C:\WINDOWS\zip.exe
2009-05-16 19:31:55 —-A—- C:\WINDOWS\vFind.exe
2009-05-16 19:31:55 —-A—- C:\WINDOWS\SWXCACLS.exe
2009-05-16 19:31:55 —-A—- C:\WINDOWS\SWSC.exe
2009-05-16 19:31:55 —-A—- C:\WINDOWS\SWREG.exe
2009-05-16 19:31:55 —-A—- C:\WINDOWS\sed.exe
2009-05-16 19:31:55 —-A—- C:\WINDOWS\NIRCMD.exe
2009-05-16 19:31:55 —-A—- C:\WINDOWS\grep.exe
2009-05-16 19:31:50 —-D—- C:\Combo-Fix
2009-05-16 19:31:48 —-A—- C:\WINDOWS\system32\CF6400.exe
2009-05-16 18:11:35 —-D—- C:\WINDOWS\ERDNT
2009-05-16 18:11:34 —-A—- C:\WINDOWS\system32\CF23448.exe
2009-05-16 17:20:22 —-D—- C:\Qoobox
2009-05-16 17:19:39 —-A—- C:\WINDOWS\myClean.bat
2009-05-15 23:50:44 —-D—- C:\Program Files\Trend Micro
2009-05-15 22:59:17 —-SHD—- C:\WINDOWS\CSC
2009-05-15 22:59:12 —-A—- C:\WINDOWS\ntbtlog.txt

======List of files/folders modified in the last 1 months======

2009-05-17 12:00:01 —-D—- C:\WINDOWS\Prefetch
2009-05-17 07:13:02 —-D—- C:\WINDOWS\Temp
2009-05-17 07:11:37 —-D—- C:\WINDOWS
2009-05-17 07:06:23 —-D—- C:\WINDOWS\system32
2009-05-17 07:06:20 —-D—- C:\Program Files\McAfee
2009-05-17 07:06:20 —-D—- C:\Program Files\Common Files
2009-05-17 07:06:20 —-D—- C:\Documents and Settings\All Users\Application Data\McAfee
2009-05-16 19:39:15 —-D—- C:\WINDOWS\system32\CatRoot2
2009-05-16 19:29:38 —-RD—- C:\Program Files
2009-05-16 19:28:30 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-05-16 18:06:45 —-D—- C:\Program Files\Mozilla Firefox
2009-05-16 17:18:55 —-D—- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2009-05-16 17:18:40 —-D—- C:\WINDOWS\system32\drivers
2009-05-15 23:34:18 —-D—- C:\WINDOWS\system32\CatRoot
2009-05-15 23:34:08 —-D—- C:\WINDOWS\system32\CatRoot_bak
2009-05-15 23:34:07 —-HD—- C:\WINDOWS\inf
2009-05-12 23:55:59 —-SHD—- C:\WINDOWS\Installer
2009-05-07 03:16:29 —-A—- C:\WINDOWS\system32\MRT.exe
2009-04-26 22:02:52 —-D—- C:\Program Files\EPSON Print CD
2009-04-19 22:58:03 —-D—- C:\Documents and Settings\Margaret McLeod\Application Data\Adobe
2009-04-18 10:44:17 —-D—- C:\Program Files\Common

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 DLARTL_M;DLARTL_M; C:\WINDOWS\System32\Drivers\DLARTL_M.SYS [2007-07-23 30064]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2009-03-03 213768]
R1 mfetdik;McAfee Inc. mfetdik; C:\WINDOWS\system32\drivers\mfetdik.sys [2009-03-03 55208]
R2 DLABMFSM;DLABMFSM; C:\WINDOWS\System32\Drivers\DLABMFSM.SYS [2007-07-23 37360]
R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\Drivers\DLABOIOM.SYS [2007-07-23 32848]
R2 DLADResM;DLADResM; C:\WINDOWS\System32\Drivers\DLADResM.SYS [2007-07-23 9104]
R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\Drivers\DLAIFS_M.SYS [2007-07-23 108752]
R2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\Drivers\DLAOPIOM.SYS [2007-07-23 27216]
R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\Drivers\DLAPoolM.SYS [2007-07-23 16304]
R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\Drivers\DLAUDF_M.SYS [2007-07-23 98448]
R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\Drivers\DLAUDFAM.SYS [2007-07-23 93552]
R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2007-07-23 52000]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-08-27 2371584]
R3 CamDrL;Logitech QuickCam Pro 3000(CamDrl); C:\WINDOWS\system32\DRIVERS\Camdrl.sys [2004-10-08 326656]
R3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-07-22 254872]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-08-12 137728]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-22 4424704]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2004-10-08 22016]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2005-10-25 27264]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
S3 catchme;catchme; \??\C:\Combo-Fix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 MfeAVFK;McAfee Inc. MfeAVFK; C:\WINDOWS\system32\drivers\MfeAVFK.sys [2009-03-03 79880]
S3 MfeBOPK;McAfee Inc. MfeBOPK; C:\WINDOWS\system32\drivers\MfeBOPK.sys [2009-03-03 35272]
S3 MfeRKDK;McAfee Inc. MfeRKDK; C:\WINDOWS\system32\drivers\MfeRKDK.sys [2009-03-03 34216]
S3 mr7910;Photo Viewer; C:\WINDOWS\system32\DRIVERS\mr7910.sys [2006-08-02 114560]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2004-08-04 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2004-08-04 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2004-08-04 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2004-08-04 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2004-08-03 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2004-08-04 41088]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-04 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Amazon Download Agent;Amazon Download Agent; C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2009-02-02 317440]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-09-10 116040]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-08-27 483328]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 EPSONStatusAgent2;EPSON Printer Status Agent2; C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe [2003-11-12 94208]
R2 IntuitUpdateService;Intuit Update Service; C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [2008-10-10 13088]
R2 TabletService;TabletService; C:\WINDOWS\system32\Tablet.exe [2005-12-06 753664]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-09-10 536872]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-04 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 GoogleDesktopManager-010708-104812;Google Desktop Manager 5.7.801.7324; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-07-16 29744]
S3 GoToAssist;GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [2008-08-22 16680]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-17 137200]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2007-07-11 69632]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

—————–EOF—————–

info.txt logfile of random's system information tool 1.06 2009-05-17 12:04:55

======Uninstall list======

–>C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
–>MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Photoshop 7.0.1–>C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Reader 7.0.8–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70800000002}
Amazon Games & Software Downloader–>"C:\Program Files\Amazon\Amazon Games & Software Downloader\uninst\unins000.exe"
AnswerWorks 5.0 English Runtime–>MsiExec.exe /I{9E5A03E3-6246-4920-9630-0527D5DA9B07}
Apple Mobile Device Support–>MsiExec.exe /I{AA9768AA-FF0B-4C66-A085-31E934F77841}
Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ArcSoft Panorama Maker 4–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D45E8C45-B601-4A80-AFD8-E16338744DE1}\Setup.exe" -l0x9
ATI Catalyst Control Center–>MsiExec.exe /I{87841AF8-C785-42FF-A76E-CC0F0C2816CC}
ATI Display Driver–>rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Bonjour–>MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
Browser Address Error Redirector–>MsiExec.exe /I{62230596-37E5-4618-A329-0D21F529A86F}
Compatibility Pack for the 2007 Office system–>MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Dell Driver Reset Tool–>MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
EPSON Print CD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}\Setup.exe" -l0x9 -SYSTEM
EPSON Printer Software–>C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /r
Google Desktop–>C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Toolbar for Internet Explorer–>"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
GoToAssist 8.0.0.514–>C:\Program Files\Citrix\GoToAssist\514\G2AUninstaller.exe /uninstall
High Definition Audio Driver Package - KB835221–>C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB915865)–>"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Intel® PRO Network Connections 12.1.12.0–>MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
iPod for Windows 2005-06-26–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{654F0312-CB3D-4FE2-962C-6BB9752E9146} /l1033
iTunes–>MsiExec.exe /I{41B9E2CF-0B3F-442A-B5B3-592A4A355634}
Java™ 6 Update 5–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
KODAK Gallery Upload Software–>MsiExec.exe /I{B7F98125-4955-41E3-8A71-4CE11CE9C198}
Logitech Desktop Messenger–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x9 UNINSTALL
Logitech Print Service–>C:\PROGRA~1\Logitech\PRINTS~1\UNWISE.EXE C:\PROGRA~1\Logitech\PRINTS~1\INSTALL.LOG
Logitech QuickCam Software–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x9
Logitech® Camera Driver–>"C:\Program Files\Common Files\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office XP Professional–>MsiExec.exe /I{91110409-6000-11D3-8CFE-0050048383C9}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0.10)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN–>C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6 Service Pack 2 (KB954459)–>MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
Nikon Message Center–>MsiExec.exe /X{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}
Nikon Transfer–>MsiExec.exe /X{E9757890-7EC5-46C8-99AB-B00F07B6525C}
Photo Viewer s2.5–>"C:\Program Files\Photo Viewer\unins000.exe"
Photo Viewer–>MsiExec.exe /I{67183F00-3DDC-497B-A090-4E2B79EAF1CD}
PowerDVD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -l0x9 -cluninstall
QuickTime–>MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
Realtek High Definition Audio Driver–>RtlUpd.exe -r -m
Roxio Activation Module–>MsiExec.exe /I{07159635-9DFE-4105-BFC0-2817DB540C68}
Roxio Creator Audio–>MsiExec.exe /I{83FFCFC7-88C6-41C6-8752-958A45325C82}
Roxio Creator BDAV Plugin–>MsiExec.exe /I{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}
Roxio Creator Copy–>MsiExec.exe /I{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}
Roxio Creator Data–>MsiExec.exe /I{0D397393-9B50-4C52-84D5-77E344289F87}
Roxio Creator DE–>MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
Roxio Creator Tools–>MsiExec.exe /I{0394CDC8-FABD-4ED8-B104-03393876DFDF}
Roxio Drag-to-Disc–>MsiExec.exe /I{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}
Roxio Express Labeler 3–>MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Roxio Update Manager–>MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
SearchAssist–>C:\DELL\SearchAssist\UninstSA.bat
Security Update for CAPICOM (KB931906)–>MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Step By Step Interactive Training (KB923723)–>"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)–>"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)–>"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)–>"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB963027)–>"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)–>"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)–>"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931784)–>"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944338-v2)–>"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950749)–>"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950759)–>"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)–>"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)–>"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)–>"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)–>"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)–>"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)–>"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)–>"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)–>"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)–>"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)–>"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Sonic CinePlayer Decoder Pack–>MsiExec.exe /I{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}
Tablet–>C:\Program Files\Tablet\Remove.exe /u
TurboTax 2008 WinPerFedFormset–>MsiExec.exe /I{7570F1CA-016D-46AC-B586-CD74645EFB52}
TurboTax 2008 WinPerProgramHelp–>MsiExec.exe /I{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}
TurboTax 2008 WinPerReleaseEngine–>MsiExec.exe /I{88214092-836F-4E22-A5AC-569AC9EE6A0F}
TurboTax 2008 WinPerTaxSupport–>MsiExec.exe /I{B23726CF-68BF-41A6-A4EB-72F12F87FE05}
TurboTax 2008 WinPerUserEducation–>MsiExec.exe /I{29521505-F489-4822-ADFA-32C6DEE4F114}
TurboTax 2008 wrapper–>MsiExec.exe /I{B1DB1AD8-C07E-4052-81A1-D2930232BA70}
TurboTax 2008–>C:\Program Files\TurboTax\Deluxe 2008\Installer\TurboTax 2008 Installer.exe /u /t /a
Update for Windows XP (KB896256)–>"C:\WINDOWS\$NtUninstallKB896256$\spuninst\spuninst.exe"
Update for Windows XP (KB898461)–>"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB932823-v3)–>"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
Update for Windows XP (KB942840)–>"C:\WINDOWS\$NtUninstallKB942840$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)–>"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Windows Driver Package - (mr7910) Image (08/08/2006 1.4.0.0)–>C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInstXP.exe /u C:\WINDOWS\system32\DRVSTORE\mr7910_1FFEF370F39864F3AAA62219D434AE06B02B70AB\mr7910.inf
Windows Internet Explorer 7–>"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Live installer–>MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger–>MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant–>MsiExec.exe /I{9422C8EA-B0C6-4197-B8FC-DC797658CA00}
Windows XP Hotfix - KB885884–>C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst.exe
Yahoo! Messenger–>C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG

=====HijackThis Backups=====

O18 - Filter hijack: text/html - {ab20a60c-58f9-48ab-9ac3-859e1337c0da} - C:\WINDOWS\system32\dsound3dd.dll [2009-05-17]

======System event log======

Computer Name: D8V5VTG1
Event Code: 17
Message: Time Provider NtpClient: An error occurred during DNS lookup of the manually
configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15
minutes.
The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Record Number: 13037
Source Name: W32Time
Time Written: 20090422003844.000000-240
Event Type: error
User:

Computer Name: D8V5VTG1
Event Code: 4226
Message: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Record Number: 12876
Source Name: Tcpip
Time Written: 20090419221810.000000-240
Event Type: warning
User:

Computer Name: D8V5VTG1
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 12866
Source Name: W32Time
Time Written: 20090418091302.000000-240
Event Type: warning
User:

Computer Name: D8V5VTG1
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 12455
Source Name: W32Time
Time Written: 20090411222236.000000-240
Event Type: warning
User:

Computer Name: D8V5VTG1
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 12118
Source Name: W32Time
Time Written: 20090405084511.000000-240
Event Type: warning
User:

=====Application event log=====

Computer Name: D8V5VTG1
Event Code: 1517
Message: Windows saved user D8V5VTG1\Margaret McLeod registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 1388
Source Name: Userenv
Time Written: 20081212023619.000000-300
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: D8V5VTG1
Event Code: 32068
Message: The outgoing routing rule is not valid because it cannot find a valid device. The outgoing faxes that use this rule will not be routed. Verify that the targeted device or devices (if routed to a group of devices) is connected and installed correctly, and turned on. If routed to a group, verify that the group is configured correctly.
Country/region code: '*'
Area code: '*'

Record Number: 1382
Source Name: Microsoft Fax
Time Written: 20081210184116.000000-300
Event Type: warning
User:

Computer Name: D8V5VTG1
Event Code: 32026
Message: Fax Service failed to initialize any assigned fax devices (virtual or TAPI).
No faxes can be sent or received until a fax device is installed.

Record Number: 1381
Source Name: Microsoft Fax
Time Written: 20081210184116.000000-300
Event Type: warning
User:

Computer Name: D8V5VTG1
Event Code: 2004
Message: Unable to open the Server service. Server performance data
will not be returned. Error code returned is in data DWORD 0.

Record Number: 1377
Source Name: PerfNet
Time Written: 20081210184033.000000-300
Event Type: error
User:

Computer Name: D8V5VTG1
Event Code: 1517
Message: Windows saved user D8V5VTG1\Margaret McLeod registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 1372
Source Name: Userenv
Time Written: 20081210003626.000000-300
Event Type: warning
User: NT AUTHORITY\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Intel\DMIX;C:\Program Files\ATI Technologies\ATI.ACE;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared;C:\Program Files\QuickTime\QTSystem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=1706
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip

—————–EOF—————–
This is the GMER log. I cannot report on how my PC is behaving because I have uninstalled my virus protection and that was the initial symptom. I could try to access a McAffee page, but I don't want to do too much until I know I am okay.

Let me know what else you need.

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-17 13:00:14
Windows 5.1.2600 Service Pack 2


—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\svchost.exe[516] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\svchost.exe[516] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\svchost.exe[516] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\svchost.exe[516] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\svchost.exe[516] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\svchost.exe[516] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\system32\Tablet.exe[604] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\Tablet.exe[604] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\Tablet.exe[604] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\Tablet.exe[604] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\Tablet.exe[604] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\Tablet.exe[604] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\system32\winlogon.exe[736] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\winlogon.exe[736] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\winlogon.exe[736] WS2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\winlogon.exe[736] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\winlogon.exe[736] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\winlogon.exe[736] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\system32\services.exe[780] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\services.exe[780] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\services.exe[780] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\services.exe[780] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\services.exe[780] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\services.exe[780] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\system32\lsass.exe[792] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\lsass.exe[792] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\lsass.exe[792] WS2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\lsass.exe[792] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\lsass.exe[792] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\lsass.exe[792] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\svchost.exe[1048] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\svchost.exe[1048] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\svchost.exe[1048] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\svchost.exe[1048] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\svchost.exe[1048] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\system32\svchost.exe[1124] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\svchost.exe[1124] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\svchost.exe[1124] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\svchost.exe[1124] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\svchost.exe[1124] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\svchost.exe[1124] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\System32\svchost.exe[1244] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\System32\svchost.exe[1244] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\System32\svchost.exe[1244] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\System32\svchost.exe[1244] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\System32\svchost.exe[1244] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\System32\svchost.exe[1244] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\svchost.exe[1356] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\svchost.exe[1356] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\svchost.exe[1356] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\svchost.exe[1356] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\svchost.exe[1356] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\svchost.exe[1456] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\svchost.exe[1456] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\svchost.exe[1456] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\svchost.exe[1456] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\svchost.exe[1456] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1596] KERNEL32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1596] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1596] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1596] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1596] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1596] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\system32\spoolsv.exe[1684] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\spoolsv.exe[1684] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\spoolsv.exe[1684] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\spoolsv.exe[1684] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\spoolsv.exe[1684] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\spoolsv.exe[1684] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\system32\svchost.exe[1808] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\svchost.exe[1808] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\svchost.exe[1808] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\svchost.exe[1808] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\svchost.exe[1808] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\svchost.exe[1808] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe[1860] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe[1860] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe[1860] WS2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe[1860] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe[1860] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\Program Files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe[1860] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[2012] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[2012] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[2012] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[2012] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[2012] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe[2012] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\System32\alg.exe[2096] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\System32\alg.exe[2096] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\System32\alg.exe[2096] WS2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\System32\alg.exe[2096] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\System32\alg.exe[2096] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\System32\alg.exe[2096] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\Program Files\Internet Explorer\iexplore.exe[2676] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\Program Files\Internet Explorer\iexplore.exe[2676] kernel32.dll!ExitProcess 7C81CDEA 5 Bytes JMP 030F1088 C:\WINDOWS\system32\dsound3dd.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2676] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\Program Files\Internet Explorer\iexplore.exe[2676] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\Program Files\Internet Explorer\iexplore.exe[2676] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\Program Files\Internet Explorer\iexplore.exe[2676] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\Program Files\Internet Explorer\iexplore.exe[2676] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\RTHDCPL.EXE[3384] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\RTHDCPL.EXE[3384] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\RTHDCPL.EXE[3384] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\RTHDCPL.EXE[3384] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\RTHDCPL.EXE[3384] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\RTHDCPL.EXE[3384] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE[3440] KERNEL32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE[3440] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE[3440] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE[3440] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE[3440] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE[3440] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3476] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3476] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3476] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3476] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3476] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3476] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\WINDOWS\system32\LVCOMSX.EXE[3516] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\LVCOMSX.EXE[3516] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\LVCOMSX.EXE[3516] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\LVCOMSX.EXE[3516] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\LVCOMSX.EXE[3516] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\LVCOMSX.EXE[3516] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14
.text C:\Program Files\Logitech\Video\LogiTray.exe[3532] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10084020
.text C:\Program Files\Logitech\Video\LogiTray.exe[3532] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10083F4C
.text C:\Program Files\Logitech\Video\LogiTray.exe[3532] ws2_32.dll!send 71AB428A 5 Bytes JMP 10083734
.text C:\Program Files\Logitech\Video\LogiTray.exe[3532] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10082D80
.text C:\Program Files\Logitech\Video\LogiTray.exe[3532] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10082CD0
.text C:\Program Files\Logitech\Video\LogiTray.exe[3532] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10083F14
.text C:\Program Files\iTunes\iTunesHelper.exe[3608] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\Program Files\iTunes\iTunesHelper.exe[3608] WS2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\Program Files\iTunes\iTunesHelper.exe[3608] WS2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\Program Files\iTunes\iTunesHelper.exe[3608] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\Program Files\iTunes\iTunesHelper.exe[3608] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\Program Files\iTunes\iTunesHelper.exe[3608] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[3692] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10014020
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[3692] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10013F4C
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[3692] ws2_32.dll!send 71AB428A 5 Bytes JMP 10013734
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[3692] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10012D80
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[3692] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10012CD0
.text C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe[3692] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10013F14
.text C:\WINDOWS\system32\ctfmon.exe[3704] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10004020
.text C:\WINDOWS\system32\ctfmon.exe[3704] ws2_32.dll!connect 71AB406A 5 Bytes JMP 10003F4C
.text C:\WINDOWS\system32\ctfmon.exe[3704] ws2_32.dll!send 71AB428A 5 Bytes JMP 10003734
.text C:\WINDOWS\system32\ctfmon.exe[3704] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 10002D80
.text C:\WINDOWS\system32\ctfmon.exe[3704] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002CD0
.text C:\WINDOWS\system32\ctfmon.exe[3704] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003F14

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6113A40D] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6113A33F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [61139C3F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6113A37F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!GetStockObject] [6113909F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6113A40D] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6113A33F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [61139C3F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6113A37F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!GetStockObject] [6113909F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6113A3BF] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6113A40D] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6113A37F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6113A33F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [61139C3F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [61139856] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [61139856] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [61138FE2] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [61138F66] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [61138FA4] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetStockObject] [6113909F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6113A33F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6113A37F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [61139C3F] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6113A40D] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6113A3BF] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AnimateWindow] [611390DD] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [61138FA4] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [61139856] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [61138FE2] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [61139856] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [611390A5] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[2332] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [61138F66] C:\Program Files\Yahoo!\Messenger\yui.dll

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

—- EOF - GMER 1.0.15 —-
Hi,

Did you have a failed installation attempt with SP3 before all this trouble began as the catroot folder may be corrupted.

One last attempt to get combofix to run.

Navigate to the ComboFix folder located at C:\ComboFix and delete it.

Delete the Combofix/Combo-fix icon from your desktop.

Download a fresh copy of ComboFix from one of these locations:


Link 1
Link 2
Link 3


rename it to MagCindy.exe before saving it to your desktop.

close all other open programs (including this one)

double click on the icon to run it. - Allow it to run uninterrupted for at least 30 minutes

Post the resulting log
I tried to install SP3 once, but aborted because I did not have a backup which it recommends prior to installation. I will delete and download a new copy of ComboFix, rename it, close all other programs and run it. Log will be posted afterward. I will delete ComboFix from my desktop as well.
:notworthy: It ran!

Here's the log file from combofix.

ComboFix 09-05-17.01 - Margaret McLeod 05/17/2009 13:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3326.2655 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\MagCindy.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common\helper.dll
c:\program files\Common\helper.sig
c:\windows\system32\mfc80.dll
c:\windows\system32\ntnet.drv
c:\windows\wiaservv.log

.
((((((((((((((((((((((((( Files Created from 2009-04-17 to 2009-05-17 )))))))))))))))))))))))))))))))
.

2009-05-17 16:04 . 2009-05-17 16:04 ——– d—–w C:\rsit
2009-05-17 11:15 . 2009-05-17 12:21 ——– d—–w c:\documents and settings\Margaret McLeod\DoctorWeb
2009-05-16 21:19 . 2006-12-05 22:17 240 —-a-w c:\windows\myClean.bat
2009-05-16 03:50 . 2009-05-16 03:50 ——– d—–w c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-17 17:58 . 2008-08-10 18:36 335 —-a-w c:\windows\system32\tablet.dat
2009-05-17 17:55 . 2009-04-09 04:05 ——– d—–w c:\program files\Common
2009-05-17 11:06 . 2008-07-16 22:49 ——– d—–w c:\program files\McAfee
2009-04-27 02:02 . 2008-11-04 00:10 ——– d—–w c:\program files\EPSON Print CD
2009-04-12 02:26 . 2008-12-24 18:43 20 —h–w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-04-05 22:29 . 2008-07-16 22:52 23576 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-05 22:29 . 2009-04-05 22:29 ——– d—–w c:\program files\Common Files\AnswerWorks 5.0
2009-04-05 22:28 . 2009-04-05 22:27 ——– d—–w c:\program files\Common Files\Intuit
2009-04-05 22:26 . 2009-04-05 22:26 ——– d—–w c:\program files\TurboTax
2009-03-15 16:05 . 2009-03-15 16:05 135 —-a-w c:\documents and settings\David McLeod\Local Settings\Application Data\fusioncache.dat
2009-03-14 23:10 . 2009-03-14 23:05 664 —-a-w c:\windows\system32\d3d9caps.dat
2009-03-06 14:00 . 2004-08-11 22:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 16:24 . 2008-07-16 22:49 55208 —-a-w c:\windows\system32\drivers\mfetdik.sys
2009-03-03 16:24 . 2008-07-16 22:49 34216 —-a-w c:\windows\system32\drivers\MfeRKDK.sys
2009-03-03 16:23 . 2008-07-16 22:49 213768 —-a-w c:\windows\system32\drivers\mfehidk.sys
2009-03-03 16:23 . 2008-07-16 22:49 35272 —-a-w c:\windows\system32\drivers\MfeBOPK.sys
2009-03-03 16:23 . 2008-07-16 22:49 79880 —-a-w c:\windows\system32\drivers\MfeAVFK.sys
2009-03-03 00:18 . 2004-08-11 22:00 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-21 12:25 . 2009-02-21 12:25 691592 —-a-w c:\windows\system32\OGACheckControl.DLL
2009-02-20 18:09 . 2004-08-11 22:00 78336 —-a-w c:\windows\system32\ieencode.dll
2009-01-01 15:01 . 2009-01-01 15:00 7518240 —-a-w c:\program files\Firefox Setup 3.0.5.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-16 68856]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-07-16 29744]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"EPSON Stylus Photo R200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE" [2003-07-08 99840]
"EPSON Stylus Photo 2200"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-07-01 74752]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-02-02 246272]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-07-22 16132608]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-8-10 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-8-26 450560]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2008-8-10 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-23 02:23 10536 —-a-w c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R2 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [3/16/2009 11:16 PM 317440]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45 AM 13088]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = localhost;*.local
Trusted Zone: mcafeeasap.com
FF - ProfilePath - c:\documents and settings\Margaret McLeod\Application Data\Mozilla\Firefox\Profiles\iy4uv9fs.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-17 14:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(740)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll

- - - - - - - > 'explorer.exe'(516)
c:\windows\system32\msi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\windows\system32\Tablet.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Completion time: 2009-05-17 14:39 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-17 18:39

Pre-Run: 729,013,805,056 bytes free
Post-Run: 728,995,950,592 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

144 — E O F — 2009-05-16 03:29
Hi,

It doesn't appear as though any infection remains on your system but we will run one more online antivirus scan just to be certain:

so the remaining issues to address now:

1. Re-install an AV
2. Update to SP3
3. Update your Java
4. Clean up our tools

Do you have a paidup subscription to McAfee or are you interested in a free alternative AV.

You can go ahead and re-install McAfee now. (unless you want to try something else - let me know.)

I would like you to run an on line virus scan with Kaspersky before you update to SP3.


While downloading the SP3 update McAfee will need to be disabled or it could interfere in the download.

Make sure you copy your documents, pictures, music etc. to a removable media before you do the SP3 update as MS advises.


Run an on-line scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.

We will address the Java update and tool clean up after your next post
Thank you so much. I have a paid subscription for McAfee through November, but I will need to re-install from disk (which is a trial) and then reactivate my subscription. I would hope they won't give me a hard time, but who knows? If you have a recommendation for a better virus protection, or a free alternative, I would love to hear about it. In the meantime, I will do the online scan wtih Kaspersky and post the log back to you. I'm not sure if I have enough cd's to back up all my data, so it may be a day or two before I can install SP3.
Hi,

You won't have a hard time re-activating - reinstalls occur all the time for various reasons so they are used to it.

Update your Java

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 13. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


I use Avira Antivir, but there are three really good free antivirus products that I would recommend - much lighter on resources too.

Avira AntiVir
Avast
AVG

set the one you choose to receive automatic updates so you are always as fully protected as possible from the newest virus threats.
NOTE: DO NOT install more than one anti-virus program as they will conflict, and provide less protection, not more.
I downloaded Java before you posted from your prior response so I could run Kaspersky. Should I now follow the above instructions before I run the Kaspersky scan? It is definitely a different install process than I just did.
No, not necessary, just delete the old java from your Add/Remove programs when you get the chance..the other instruction is to clear the java cache…you can do that anytime
I cannot get Kaspersky to run. I have downloaded Java, set all the appropriate flags and deleted files, rebooted, etc., per instructions on the JAVA download page. I even went back and followed your second set of instructions on installing (and deleting old copies) of Java. Still nothing. When I try to run the scan, I get the follwing message: From Windows IE Explorer Starting Java Applet has failed! Please go online to use this program. Then nothing. ADDED NOTE: I saw a reference to this message being indicative of some virus. Is that possible?
Hi,

Please try this

Go to Tools > Internet Options > Advanced tab. Click Reset then OK and exit IE 7.

Re-open IE 7 and ensure the Java add-ons are enabled.

[external image: Posted Image]





If Kaspersky still will not run do the following scan instead:

Please run the following online scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start.  The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button.  The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
I finally got Kapersky to run. Problem though (of course)…. The box for Viruses, Worms, Trojan Horses and Rootkits is greyed out and I cannot turn it on. I'm moving on to Eset…..
Log from Eset Online Scanner: # version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=4081 (20090517) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.066 (20070917) # EOSSerial=129bd2794baf434592f78c78966cea70 # end=finished # remove_checked=false # unwanted_checked=false # utc_time=2009-05-18 04:19:23 # local_time=2009-05-18 12:19:23 (-0500, Eastern Daylight Time) # country="United States" # osver=5.1.2600 NT Service Pack 2 # scanned=188609 # found=1 # scan_time=745 C:\Documents and Settings\Margaret McLeod\DoctorWeb\Quarantine\Av-test.txt Eicar test file 1195B64D237F57E6289D3CD105228D93 I am off to bed now. Thank you again for all your assistance. I will check in tomorrow for next steps. I still have to reinstall some anti-virus software but I will wait for your next instructions.
Hi, Well that is good news, all ESET found were the items in quarantine. I suggest you try installing one of the free antivirus products for now, see if there are any issues or conflicts. You can always go back to McAfee if you prefer it. Some of your issues may have been caused by a failed install of SP3. Getting a successful install of SP3 may resolve a lot of your issues. Check with MS, I know they distributed many SP3 disks to the Major Computer Retailers, you may find a disk somewhere, or they may send you one - if you would prefer to install it via disk rather than download. In the meantime - post a fresh HJT log as there were a couple of minor items that needed attention in the last one, I want to see if they are still there. Open HJT >>- run a system scan and save a log file >> post the resulting log. Then after that, we can clean up our tools.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI