Here's the DDS logs below and a prescan log of GMER. 1st crash of GMER happened when a folder for Battlefield 1942 was open, so I moved the folder to the recycle bin and rescanned again. On the second scan, I forgot to turn off McAffee but the scan went a lot longer (hour or so) and then locked up (no reboot) after all the program files were scanned and it was in c:\tempEI4.
If you want, I will retry in safe mode
Thanks.
DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 10:39:59.23 on Sun 01/03/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3054.2385 [GMT -5:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Koller Family\My Documents\Downloads\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mURLSearchHooks: SrchHook Class: {d3f669eb-57ce-4f45-8fbd-e245cbb46366} - c:\program files\stopzilla!\toolbar\SZIESearchHook.dll
mURLSearchHooks: SrchHook Class: {d3f669eb-57ce-4f45-8fbd-e245cbb46366} - c:\program files\stopzilla!\toolbar\SZIESearchHook.dll
BHO: ZILLAbar Browser Helper Object: {1827766b-9f49-4854-8034-f6ee26fcb1ec} - c:\program files\stopzilla!\toolbar\SZSG.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: STOPzilla: {98828ded-a591-462f-83ba-d2f62a68b8b8} - c:\program files\stopzilla!\toolbar\SZSG.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: []
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244480103943
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\koller~1\applic~1\mozilla\firefox\profiles\trf53vvv.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\stopzilla!\toolbar\extension\components\SiteGuardFF.dll
FF - plugin: c:\documents and settings\koller family\application data\mozilla\firefox\profiles\trf53vvv.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\koller family\application data\mozilla\firefox\profiles\trf53vvv.default\extensions\[removed]\plugins\npImgCtl.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npRACtrl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-6-8 214664]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-6-8 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-6-8 144704]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-6-8 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-6-8 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-6-8 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-6-8 40552]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-7-9 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-12-20 38224]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-6-8 34248]
=============== Created Last 30 ================
2010-01-03 04:27:37 0 d—–w- c:\program files\Trend Micro
2009-12-30 09:15:54 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-26 16:37:19 1144 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-12-26 16:32:02 0 d—–w- c:\docume~1\alluse~1.win\applic~1\SITEguard
2009-12-26 16:31:10 0 d—–w- c:\program files\STOPzilla!
2009-12-26 16:31:07 0 d—–w- c:\program files\common files\iS3
2009-12-26 16:31:07 0 d—–w- c:\docume~1\alluse~1.win\applic~1\STOPzilla!
2009-12-24 04:12:52 0 d—–w- c:\program files\BCL Technologies
2009-12-20 13:41:04 0 d—–w- c:\docume~1\koller~1\applic~1\Malwarebytes
2009-12-20 13:40:59 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-20 13:40:57 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-20 13:40:57 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-20 13:40:57 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2009-12-14 19:15:14 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-09 21:01:15 139499 —-a-w- c:\windows\hpoins15.dat
2009-12-09 21:01:15 1039 ——w- c:\windows\hpomdl15.dat
2009-12-09 16:43:12 0 d—–w- c:\program files\common files\HP
2009-12-09 16:05:56 121329 ——w- c:\windows\hpoins15.dat.temp
2009-12-09 16:05:56 1037 ——w- c:\windows\hpomdl15.dat.temp
==================== Find3M ====================
2010-01-01 06:01:57 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2009-12-25 18:13:51 24892 —ha-w- c:\windows\system32\mlfcache.dat
2009-10-29 07:45:38 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-13 10:30:16 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-12 12:34:50 411368 —-a-w- c:\windows\system32\deploytk.dll
============= FINISH: 10:41:46.81 ===============
*************************************************************************Attach file**********************************************************************
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 6/8/2009 11:11:24 AM
System Uptime: 1/3/2010 2:25:03 AM (8 hours ago)
Motherboard: Intel Corporation | | DG965RY
Processor: Intel® Core™2 CPU 6300 @ 1.86GHz | | 1864/266mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 225 GiB total, 46.281 GiB free.
D: is FIXED (NTFS) - 466 GiB total, 189.509 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP143: 10/6/2009 1:23:04 AM - System Checkpoint
RP144: 10/7/2009 2:23:05 AM - System Checkpoint
RP145: 10/8/2009 3:18:08 PM - System Checkpoint
RP146: 10/9/2009 4:44:25 PM - System Checkpoint
RP147: 10/10/2009 5:20:06 PM - System Checkpoint
RP148: 10/11/2009 5:58:47 PM - System Checkpoint
RP149: 10/12/2009 8:34:45 AM - Installed Java™ 6 Update 16
RP150: 10/12/2009 2:46:56 PM - Software Distribution Service 3.0
RP151: 10/13/2009 3:46:11 PM - System Checkpoint
RP152: 10/14/2009 4:11:12 PM - System Checkpoint
RP153: 10/14/2009 10:34:11 PM - Software Distribution Service 3.0
RP154: 10/16/2009 7:40:22 AM - System Checkpoint
RP155: 10/17/2009 9:41:52 AM - System Checkpoint
RP156: 10/18/2009 9:44:47 AM - System Checkpoint
RP157: 10/19/2009 10:02:44 AM - System Checkpoint
RP158: 10/20/2009 11:43:11 AM - System Checkpoint
RP159: 10/21/2009 12:24:44 PM - System Checkpoint
RP160: 10/22/2009 12:29:53 PM - System Checkpoint
RP161: 10/23/2009 9:41:41 PM - System Checkpoint
RP162: 10/24/2009 10:35:38 PM - System Checkpoint
RP163: 10/26/2009 9:54:16 AM - System Checkpoint
RP164: 10/27/2009 10:12:45 AM - System Checkpoint
RP165: 10/28/2009 10:43:14 AM - System Checkpoint
RP166: 10/29/2009 11:21:50 AM - System Checkpoint
RP167: 10/29/2009 6:31:43 PM - Installed Compatibility Pack for the 2007 Office system
RP168: 10/30/2009 6:55:58 PM - System Checkpoint
RP169: 10/31/2009 7:23:12 PM - System Checkpoint
RP170: 11/1/2009 8:59:01 PM - System Checkpoint
RP171: 11/2/2009 9:00:28 PM - System Checkpoint
RP172: 11/3/2009 9:31:48 PM - System Checkpoint
RP173: 11/4/2009 10:41:57 PM - System Checkpoint
RP174: 11/5/2009 10:42:28 PM - System Checkpoint
RP175: 11/6/2009 1:19:46 AM - Software Distribution Service 3.0
RP176: 11/7/2009 1:24:57 AM - System Checkpoint
RP177: 11/8/2009 1:26:02 AM - System Checkpoint
RP178: 11/9/2009 7:40:49 AM - System Checkpoint
RP179: 11/10/2009 8:13:11 AM - System Checkpoint
RP180: 11/11/2009 1:18:37 AM - Software Distribution Service 3.0
RP181: 11/12/2009 8:12:24 AM - System Checkpoint
RP182: 11/13/2009 8:18:02 AM - System Checkpoint
RP183: 11/14/2009 9:37:13 AM - System Checkpoint
RP184: 11/15/2009 9:38:20 AM - System Checkpoint
RP185: 11/16/2009 10:30:09 AM - System Checkpoint
RP186: 11/17/2009 10:32:52 AM - System Checkpoint
RP187: 11/18/2009 11:47:41 AM - System Checkpoint
RP188: 11/19/2009 1:02:22 PM - System Checkpoint
RP189: 11/20/2009 4:15:26 PM - System Checkpoint
RP190: 11/21/2009 6:18:29 PM - System Checkpoint
RP191: 11/22/2009 11:28:09 PM - System Checkpoint
RP192: 11/24/2009 6:39:18 AM - System Checkpoint
RP193: 11/25/2009 6:39:41 AM - System Checkpoint
RP194: 11/26/2009 7:27:24 AM - System Checkpoint
RP195: 11/26/2009 9:19:47 AM - Software Distribution Service 3.0
RP196: 11/27/2009 3:50:33 PM - System Checkpoint
RP197: 11/28/2009 4:57:36 PM - System Checkpoint
RP198: 11/29/2009 5:34:20 PM - System Checkpoint
RP199: 11/30/2009 5:51:52 PM - System Checkpoint
RP200: 12/1/2009 6:48:47 PM - System Checkpoint
RP201: 12/2/2009 7:01:27 PM - System Checkpoint
RP202: 12/3/2009 7:28:04 PM - System Checkpoint
RP203: 12/4/2009 7:58:44 PM - System Checkpoint
RP204: 12/5/2009 8:46:26 PM - System Checkpoint
RP205: 12/6/2009 9:46:26 PM - System Checkpoint
RP206: 12/7/2009 9:51:46 PM - System Checkpoint
RP207: 12/8/2009 10:27:28 PM - System Checkpoint
RP208: 12/9/2009 11:44:47 AM - Installed HPSU306Stub
RP209: 12/9/2009 12:16:40 PM - Software Distribution Service 3.0
RP210: 12/10/2009 12:27:53 PM - System Checkpoint
RP211: 12/11/2009 12:59:00 PM - System Checkpoint
RP212: 12/12/2009 1:43:33 PM - System Checkpoint
RP213: 12/13/2009 5:15:35 PM - System Checkpoint
RP214: 12/14/2009 6:04:12 PM - System Checkpoint
RP215: 12/15/2009 6:54:15 PM - System Checkpoint
RP216: 12/16/2009 7:30:04 PM - System Checkpoint
RP217: 12/17/2009 8:15:44 PM - System Checkpoint
RP218: 12/18/2009 9:15:44 PM - System Checkpoint
RP219: 12/19/2009 9:17:55 PM - System Checkpoint
RP220: 12/20/2009 10:06:36 PM - System Checkpoint
RP221: 12/22/2009 8:11:03 AM - System Checkpoint
RP222: 12/23/2009 6:11:06 PM - System Checkpoint
RP223: 12/23/2009 11:08:46 PM - Configured Family Tree Maker 2009
RP224: 12/23/2009 11:09:13 PM - Configured Family Tree Maker 2009
RP225: 12/23/2009 11:12:17 PM - Installed Family Tree Maker 2009
RP226: 12/24/2009 11:46:53 PM - System Checkpoint
RP227: 12/26/2009 12:47:57 AM - System Checkpoint
RP228: 12/26/2009 11:31:00 AM - Installed STOPzilla. Available with Windows Installer version 1.2 and later.
RP229: 12/26/2009 11:48:17 AM - Removed STOPzilla. Available with Windows Installer version 1.2 and later.
RP230: 12/27/2009 1:53:21 PM - System Checkpoint
RP231: 12/28/2009 2:47:35 PM - System Checkpoint
RP232: 12/29/2009 3:03:01 PM - System Checkpoint
RP233: 12/30/2009 4:21:17 PM - System Checkpoint
RP234: 12/31/2009 5:06:31 PM - System Checkpoint
RP235: 12/31/2009 6:56:38 PM - Installed Nancy Drew: The Creature of Kapu Cave
RP236: 1/1/2010 6:57:39 PM - System Checkpoint
RP237: 1/3/2010 2:40:24 AM - System Checkpoint
==== Installed Programs ======================
32 Bit HP CIO Components Installer
Acrobat.com
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Reader 9.1.3
AIO_Scan
Amazon MP3 Downloader 1.0.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Audacity 1.3.7 (Unicode)
AVS Update Manager 1.0
AVS Video Converter 6
AVS4YOU Software Navigator 1.3
Bonjour
BufferChm
Compatibility Pack for the 2007 Office system
Copy
Critical Update for Windows Media Player 11 (KB959772)
CustomerResearchQFolder
Desktop Doctor
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DocProc
DocProcQFolder
E.M. PowerPoint Video Converter 2.50
ERUNT 1.1j
eSupportQFolder
Exact Audio Copy 0.99pb5
Family Tree Maker 2009
Far Out Field Trips
GIMP 2.6.6
Google Earth
Google SketchUp 7
Google Update Helper
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Customer Participation Program 9.0
HP Imaging Device Functions 9.0
HP OCR Software 9.0
HP Photosmart All-In-One Software 9.0
HP Photosmart Essential 2.01
HP Photosmart Essential2.01
HP Solution Center 9.0
HP Update
HPProductAssistant
HPSSupply
Intel Audio Studio 2.0
Intel® Active Client Manager 2.0 HECI Driver
Intel® PRO Network Connections
iS3 STOPzilla Toolbar
iTunes
Java™ 6 Update 16
LADSPA_plugins-win-0.4.15
LAME v3.98.2 for Audacity
LightScribe 1.4.89.1
Malwarebytes' Anti-Malware
MarketResearch
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Standard Edition 2003
Microsoft Primary Interoperability Assemblies 2005
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft WSE 3.0
Monopoly Junior
Mozilla Firefox (3.5.6)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Mystery Club Gadget Games
Nancy Drew: Danger by Design
Nancy Drew: Danger on Deception Island
Nancy Drew: Legend of the Crystal Skull
Nancy Drew: Secret of the Scarlet Hand
Nancy Drew: The Creature of Kapu Cave
Nero Suite
Nikon Scan
NVIDIA Drivers
Pdf995
Picasa 3
PowerVideoMaker Professional 5.0
PS_AIO_Software
PS_AIO_Software_min
PSSWCORE
QuickTime
Scan
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SigmaTel Audio
SolutionCenter
Sonic & Knuckles Collection Documentation
Sonic & Knuckles Killer !
Sony DVD Architect Studio 4.5
Sony Sound Forge Audio Studio 9.0
Spelling Dictionaries Support For Adobe Reader 9
Status
Toolbox
TrayApp
UnloadSupport
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Vegas Movie Studio Platinum 9.0
VideoToolkit01
VST Bridge 1.1
Wave Repair 4.9.2
WebFldrs XP
WebReg
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Zune Desktop Theme
==== Event Viewer Messages From Past Week ========
12/31/2009 7:00:00 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/31/2009 6:52:58 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
12/27/2009 7:12:55 AM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
12/27/2009 7:12:55 AM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
==== End Of File ===========================
******************************************GMER Prescan Info********************************
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit quick scan 2010-01-03 10:55:59
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\KOLLER~1\LOCALS~1\Temp\pwldipog.sys
—- System - GMER 1.0.15 —-
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xB111678A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xB1116821]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xB1116738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xB111674C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xB1116835]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB1116861]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xB11168CF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xB11168B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB11167CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xB11168FB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xB111680D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xB1116710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xB1116724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xB111679E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xB1116937]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xB11168A3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xB111688D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xB111684B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xB1116923]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xB111690F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xB1116776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xB1116762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xB1116877]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB11167F9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xB11168E5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB11167E0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xB11167B4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device -> \Driver\atapi \Device\Harddisk0\DR0 8A461618
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
—- EOF - GMER 1.0.15 —-